SSE-Engineer Prisma Access Administration And Operation Practice Question
When designing Security and Inspection Policies for Prisma Access, an administrator needs to ensure optimal performance and security coverage. Which THREE best practices should the administrator follow when implementing Security Policy rules in Panorama for Prisma Access? (Choose three)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach appropriate Security Profiles (such as Antivirus, Anti-Spyware, and Vulnerability Protection) to all active Security Policy allow rules.
Prisma Access security best practices include placing explicit block rules at the top, leveraging application-layer filtering rather than relying solely on ports/IPs, and utilizing Security Profiles (antivirus, anti-spyware, URL filtering) across rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable SSL Decryption globally to maximize Prisma Access processing throughput across all mobile user nodes.
Why it's wrong here
Disabling SSL decryption blinds the security services to threats hidden inside TLS traffic, which violates security best practices.
- ✗
Configure all Security Policy rules to use 'Any' application to simplify rule maintenance and reduce rule count.
Why it's wrong here
Using 'Any' for applications reduces visibility and control, defeating the purpose of App-ID inspection.
- ✓
Attach appropriate Security Profiles (such as Antivirus, Anti-Spyware, and Vulnerability Protection) to all active Security Policy allow rules.
Why this is correct
Security profiles inspect allowed application traffic for threats, which is a core best practice in Prisma Access.
- ✓
Use App-ID and User-ID in security rules instead of relying solely on IP addresses and port numbers.
Why this is correct
Prisma Access is a next-generation security service; using App-ID and User-ID provides granular, context-aware security policies.
- ✓
Place specific application allow rules above broad general rules, and maintain explicit deny rules for known malicious traffic where appropriate.
Why this is correct
Firewall policy evaluation is top-down; rule ordering ensures intended granular matches occur before general catch-all rules.
About these practice questions
Courseiva writes every SSE-Engineer question from scratch — 203 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This SSE-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSE-Engineer exam.