Courseiva

Certified Security Service Edge Engineer (SSE-Engineer) (SSE-Engineer) — Questions 151203

203 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
MCQeasy

Which log type in Prisma Access should an administrator examine to review details about blocked URLs, category ratings, and user web-browsing attempts?

A.Threat log
B.Data Filtering log
C.HIP Match log
D.URL Filtering log
AnswerD

URL Filtering logs capture every web transaction, matched category, and allow/block action.

Why this answer

URL Filtering logs record all web traffic processed by SWG URL filtering rules.

152
MCQhard

An administrator is configuring QoS in Prisma Access for a Remote Network connection. Where must the QoS profile be applied to ensure priority handling for VoIP traffic coming from the branch?

A.Inside the GlobalProtect Gateway agent configuration profile
B.On the Remote Network configuration in Panorama under Bandwidth Allocation and QoS
C.Globally inside the Palo Alto Networks WildFire configuration
D.Directly on the customer branch router CLI via MQC
AnswerB

QoS for remote networks is configured directly within the Prisma Access Remote Network setup in Panorama.

Why this answer

QoS profiles in Prisma Access for remote networks are applied on the Remote Network configuration settings in Panorama under Cloud Services.

153
MCQhard

An enterprise using Prisma Access Mobile Users needs to enforce Host Information Profile (HIP) checks to ensure that endpoints have an active and updated corporate antimalware solution before granting access to internal applications. Which workflow must an administrator complete to successfully enforce this requirement?

A.Deploy a Prisma Access Service Connection to proxy endpoint security telemetry to Panorama.
B.Configure the Cloud Identity Engine to query local endpoint registries directly for antimalware signatures.
C.Enable User-ID syslog mapping to ingest antimalware status logs from third-party endpoint protection servers.
D.Create HIP Objects and HIP Profiles in Panorama, then reference those profiles in Security Policy rules.
AnswerD

Administrators must define HIP Objects to match criteria (like antimalware status), group them into HIP Profiles, and enforce them within Security Policy rules.

Why this answer

HIP data is gathered by the GlobalProtect agent, forwarded to Prisma Access, and then evaluated in Security Policy rules via HIP Objects and HIP Profiles.

154
MCQeasy

When designing a Prisma Access deployment for remote workers, which component authenticates the user and assigns the appropriate GlobalProtect gateway connection based on geographic location?

A.Service Connection
B.GlobalProtect Portal
C.GlobalProtect Gateway
D.Remote Network
AnswerB

The Portal provides configuration updates and directs the client to the closest or best performing Gateway.

Why this answer

The GlobalProtect Portal handles user authentication, client software updates, and assigns the optimal GlobalProtect Gateway.

155
MCQmedium

An administrator notices that certain SaaS applications are not being accurately identified or controlled by Prisma Access CASB inline policies due to domain fronting and complex URL structures. Which feature should the administrator configure in Prisma Access to ensure deep application identification and decryption of this traffic?

A.Quality of Service (QoS) profile for SaaS acceleration
B.User-ID agent mapping via LDAP integration
C.DNS Security with external recursive resolver redirection
D.SSL Decryption policy with a Forward Trust certificate
AnswerD

SSL Decryption is required for Prisma Access to inspect HTTPS traffic, identify specific SaaS applications, and enforce inline CASB controls.

Why this answer

Inbound and outbound SSL/TLS Decryption is critical for Prisma Access SWG and CASB to inspect application payloads, read SNI, and apply granular control over cloud applications.

156
MCQmedium

An organization is integrating Prisma Access with their existing Panorama deployment. Which plugin must be installed on Panorama to enable the Prisma Access configuration workflows?

A.Prisma Access plugin
B.SD-WAN plugin
C.VM-Series plugin
D.Cortex Data Lake plugin
AnswerA

The Prisma Access plugin adds the Cloud Services tab and configuration workflows to Panorama.

Why this answer

The Prisma Access plugin is required on Panorama to configure and manage Prisma Access infrastructure.

157
MCQhard

An enterprise is deploying Prisma Access and wants to ensure that user identity mapping is gathered efficiently from Microsoft Entra ID (formerly Azure AD) without deploying physical User-ID agents inside the cloud network. Which integration method should be used?

A.WMI probing from Prisma Access nodes
B.GlobalProtect client registry polling
C.Cloud Identity Engine (CIE)
D.Syslog server parsing via Service Connection
AnswerC

The Cloud Identity Engine securely synchronizes identity and group information from cloud directories like Microsoft Entra ID to Prisma Access.

Why this answer

Prisma Access supports User-ID integration with Azure AD via the Cloud Identity Engine (CIE) or direct cloud-based User-ID agentless polling.

158
Multi-Selectmedium

An administrator is troubleshooting a Prisma Access Remote Networks deployment where branch office users cannot reach external websites. Which TWO configuration areas or logs should the administrator check to resolve this issue? (Choose two)

Select 2 answers
A.Prisma Access Insight mobile user license allocation
B.Panorama > Policy > Security rules allowing trust-to-untrust traffic
C.GlobalProtect Portal client certificate store
D.Remote Networks routing configuration and static/BGP routes
E.WildFire analysis report queue
AnswersB, D

Security policy rules must explicitly permit traffic from the internal branch zone to the external untrust zone.

Why this answer

To troubleshoot remote network traffic failing to reach the internet, administrators should verify the Security Policy rules permitting outbound traffic and the Service Connections / Remote Networks routing tables to ensure default routes are properly advertised and handled.

159
Multi-Selectmedium

An administrator is reviewing the status of a Prisma Access deployment using Prisma Access Insights. Which THREE key metrics or insights can be viewed through this tool? (Choose three)

Select 3 answers
A.Individual endpoint user Windows registry configurations
B.Service health and status of cloud infrastructure and tunnels
C.License consumption and active mobile user counts
D.Bandwidth utilization and allocation across remote locations
E.Local branch switch port VLAN configurations
AnswersB, C, D

Insights displays real-time health and status of nodes and connections.

Why this answer

Prisma Access Insights provides visibility into service health, license utilization, active user counts, and bandwidth consumption across locations.

160
MCQhard

A company requires that Prisma Access FWaaS inspects all inter-zone traffic between two different remote branch offices connected via Prisma Access. By default, how does Prisma Access handle traffic between two Remote Networks attached to the same service region?

A.Traffic must be backhauled to the corporate data center via a Service Connection before reaching another branch.
B.Traffic between Remote Networks is dropped by default unless explicitly allowed by security policy and inter-branch routing is enabled.
C.Remote Networks cannot communicate with each other under any circumstance.
D.Traffic is automatically bypassed and sent directly over public internet.
AnswerB

Inter-branch traffic requires explicit configuration in the Remote Networks settings and matching security policies to allow communication.

Why this answer

Prisma Access supports inter-branch routing, allowing traffic between remote networks to be inspected by security policies when inter-branch traffic is enabled.

161
MCQhard

An administrator configures a Service Connection in Prisma Access to reach an on-premises Active Directory domain controller for authentication. Users are able to log in, but User-ID is failing to map IP addresses to usernames for users behind the Remote Network. What is the most likely reason for this User-ID failure?

A.User-ID agent or Panorama redistribution is not configured to poll the internal Domain Controller across the Service Connection, or security rules block User-ID traffic.
B.The GlobalProtect client certificate has expired.
C.BGP routing is disabled on the GlobalProtect gateway.
D.WildFire subscription is expired.
AnswerA

Panorama or User-ID agents must actively poll or receive syslog/WMI traffic from domain controllers to build IP-to-username mappings.

Why this answer

User-ID collection from internal sources requires either User-ID agents, syslog listening, or Panorama polling configured correctly to reach the AD server across the Service Connection.

162
MCQhard

Users in a specific region are experiencing intermittent latency and packet loss when accessing SaaS applications through Prisma Access. The administrator wants to analyze the quality of the path between the remote network location and the Prisma Access cloud node. Which Prisma Access feature should be utilized?

A.Panorama ACC Threat Map
B.Traffic log bandwidth utilization graphs
C.Prisma Access Insight path quality monitoring
D.GlobalProtect internal adapter diagnostics
AnswerC

Prisma Access Insight provides continuous monitoring of network paths, latency, jitter, and packet loss.

Why this answer

Prisma Access Insight provides visibility into end-to-end performance, including path quality, latency, and packet loss between remote locations and Prisma Access nodes.

163
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site tunnel failure between a customer CPE and a Prisma Access Remote Network. The IKE phase 1 negotiations fail. Which log should the engineer examine to determine the exact reason for the IKE negotiation failure?

A.Monitor > Logs > Threat.
B.Panorama > Cloud Services > Audit Log.
C.Monitor > Logs > System (filtering for IKE or IPsec events) or viewing tunnel status.
D.Monitor > Logs > URL Filtering.
AnswerC

System logs record IPsec and IKE negotiation details, encryption/hash mismatches, and phase failures.

Why this answer

System logs and IKE/IPsec operational debugging logs record Phase 1 and Phase 2 negotiation mismatches.

164
MCQhard

A user is experiencing 'Gateway not found' errors. Which troubleshooting step is most effective for verifying if the GlobalProtect Gateway is reachable?

A.Performing an nslookup on the portal-provided gateway FQDN.
B.Verifying the IPSec tunnel status in Panorama.
C.Checking the User-ID Agent logs on-premises.
D.Restarting the Cloud Identity Engine service.
AnswerA

Verifying DNS resolution of the gateway FQDN is the first step in connectivity troubleshooting.

Why this answer

The 'nslookup' or 'ping' of the FQDN assigned to the gateway is the standard way to verify resolution and connectivity.

165
MCQhard

An enterprise using Prisma Access has configured a Service Connection to their primary data center. Users at remote branches report that they cannot reach internal applications hosted in the data center. Upon checking Panorama, the Service Connection status shows 'Connected', but routing is failing. What configuration step is required on Prisma Access to advertise the remote network subnets to the data center?

A.Configure BGP peer settings and export rules on the Service Connection in Panorama.
B.Enable SSL Decryption on the Service Connection interface.
C.Create a GlobalProtect Portal authentication profile for the data center.
D.Configure Zone Protection profiles on the tunnel interface.
AnswerA

BGP must be properly configured on the Service Connection so Prisma Access and the data center exchange routes dynamically.

Why this answer

Service Connections require BGP peering configuration to exchange routing information between Prisma Access and the enterprise data center router.

166
MCQmedium

An administrator is troubleshooting a HIP (Host Information Profile) check failure for mobile users. Where can the administrator view the collected HIP reports and check compliance status in real-time?

A.Monitor > Logs > HIP Matches
B.Device > Certificate Management > HIP
C.Panorama > Cloud Services > Status > HIP
D.GlobalProtect > Gateway > Agent > HIP Objects
AnswerA

The HIP Matches log displays detailed information about host information profiles reported by GlobalProtect clients.

Why this answer

HIP check data and reports for connected mobile users can be inspected via the Panorama operational commands or ACC/Monitor tabs.

167
Multi-Selecthard

An enterprise has deployed Prisma Access with multiple remote networks and mobile users. An administrator notices that threat intelligence feeds (such as malicious IP lists and dynamic address groups) are not updating. Which THREE components should be inspected to resolve this update failure? (Choose three)

Select 3 answers
A.Verify the BGP ASN configured on the Service Connection.
B.Check External Dynamic List (EDL) URLs and ensure that Prisma Access nodes can successfully reach the external EDL hosting servers.
C.Verify that Panorama has outbound internet access to download threat feeds and dynamic updates from Palo Alto Networks servers.
D.Inspect the Dynamic Update schedule and status in Panorama under Device Deployment to ensure updates are actively scheduled and applied.
E.Check the GlobalProtect portal certificate expiration date.
AnswersB, C, D

If EDLs point to external URLs that are blocked or unreachable, dynamic lists fail to populate.

Why this answer

Threat intelligence and dynamic updates require verifying Panorama internet connectivity, dynamic update schedules, and external dynamic list (EDL) reachability.

168
MCQeasy

When troubleshooting a Prisma Access issue, an engineer needs to generate a Tech Support File (TSF) specifically for the Prisma Access cloud infrastructure. Where is this option located in Panorama?

A.Device > Support > Tech Support File.
B.Panorama > Cloud Services > Setup > Support.
C.Monitor > Logs > System.
D.Policies > Security.
AnswerB

The Support section in Cloud Services allows administrators to generate and download tech support files for Prisma Access.

Why this answer

TSFs for Prisma Access can be generated under Panorama > Cloud Services > Setup > Support.

169
MCQhard

An organization requires that all DNS queries from Prisma Access mobile users be inspected and filtered for malicious domains before resolving. Where in Panorama is Prisma Access DNS Security configured?

A.Objects -> Security Profiles -> DNS Security
B.Policies -> NAT
C.Panorama -> Cloud Services -> GlobalProtect -> DNS
D.Network Services -> DNS Proxy
AnswerA

DNS Security profiles are created under Objects -> Security Profiles and enforced via Security policy rules.

Why this answer

DNS Security profiles are attached to Security Policy rules in Panorama to inspect and take action on DNS requests.

170
Multi-Selectmedium

When configuring Prisma Access for ZTNA 2.0 to control access to private applications, which TWO components or configurations are mandatory for establishing least-privileged application access? (Choose two)

Select 2 answers
A.Legacy PPTP VPN dial-in server integration
B.Explicit PAC files distributed to all internal users
C.Public IP addresses assigned to every internal workstation
D.App-ID based security policies that explicitly name specific internal applications rather than subnets
E.Prisma Access App Connectors deployed in the internal network hosting private applications
AnswersD, E

ZTNA 2.0 replaces implicit trust with precise application control using App-ID, ensuring users access only authorized apps rather than entire network segments.

Why this answer

ZTNA 2.0 requires app-level segmentation instead of network-level access, meaning App-ID based security policies and Prisma Access App Connectors deployed in the private data center are mandatory.

171
Multi-Selecthard

When designing a multi-region Prisma Access architecture, an architect must consider compute locations and routing preferences. Which THREE factors influence the selection and placement of compute locations? (Choose three)

Select 3 answers
A.The physical desk layout of employee cubicles in branch offices
B.Geographic distribution of remote users and branch offices
C.Data residency and regulatory compliance requirements
D.The local power grid provider utilized by the cloud data center
E.Proximity to primary SaaS applications and enterprise datacenters
AnswersB, C, E

Deploying compute locations close to users minimizes latency.

Why this answer

Compute location selection is driven by user geographic distribution, regulatory compliance requirements, and proximity to enterprise SaaS or data center locations.

172
MCQhard

An organization notices that mobile users connecting to Prisma Access from a specific country are experiencing high latency and frequent disconnections. The administrator wants to check the regional Prisma Access node performance and status. Which feature in Panorama provides regional status and cloud infrastructure metrics?

A.Panorama > Cloud Services > Status > Locations / Remote Networks / Mobile Users.
B.Policies > QoS > Bandwidth Management.
C.Device > High Availability.
D.Monitor > Traffic > GlobalProtect Analytics.
AnswerA

This section provides operational status, public IP details, and health metrics for Prisma Access nodes across different global regions.

Why this answer

Panorama > Cloud Services > Status provides regional deployment metrics and node health.

173
MCQeasy

Which security feature in Prisma Access SWG inspects downloaded executable files and documents against a cloud-based behavioral sandbox to identify zero-day malware?

A.Data Filtering
B.URL Filtering
C.Antivirus Profile
D.WildFire
AnswerD

WildFire automatically analyzes unknown files in a sandbox environment to detect zero-day threats.

Why this answer

WildFire is Palo Alto Networks cloud-based malware analysis and sandbox engine.

174
MCQeasy

An architect is designing a Prisma Access deployment for a global enterprise that requires low-latency connectivity for remote workers across North America, Europe, and Asia. Which component should the architect deploy to ensure traffic processing occurs closest to the user's geographical location?

A.A dedicated hardware Panorama appliance in each branch office
B.Prisma SD-WAN appliances at every remote user laptop
C.A single centralized Prisma Access parent node in the headquarters region
D.Multiple Security Processing Nodes (SPNs) distributed across multiple geographic regions
AnswerD

Deploying SPNs across multiple cloud regions ensures users connect to the nearest compute location.

Why this answer

Remote Networks and Mobile Users require Security Processing Nodes (SPNs) deployed across multiple compute locations globally to ensure traffic is processed closest to the user, minimizing latency.

175
MCQhard

An enterprise deployment of Prisma Access uses explicit proxy. Users report that specific SaaS applications are failing because the proxy is stripping required HTTP headers. Where should the administrator check and modify proxy header insertion rules in Prisma Access?

A.Panorama > Cloud Services > Service Setup > Proxy Settings / Decryption Profiles.
B.Objects > Custom Objects > URL Filtering.
C.Network > GlobalProtect > Gateways > Agent > Client Settings.
D.Policies > NAT.
AnswerA

Explicit proxy settings and HTTP header insertion/stripping behaviors are configured within proxy profiles and decryption settings.

Why this answer

HTTP header insertion and modification rules are configured in decryption or proxy profiles within Prisma Access.

176
MCQeasy

A network engineer is configuring Prisma Access and needs to verify the status of deployed Mobile User nodes across different regions. Which Panorama workspace is dedicated to displaying the overall health and status of Prisma Access infrastructure?

A.Panorama > Cloud Services > Status.
B.Objects > Certificates.
C.Policies > QoS.
D.Monitor > Managed Devices.
AnswerA

The Status tab in Cloud Services shows the operational health of Mobile Users, Remote Networks, and Service Connections.

Why this answer

Panorama > Cloud Services > Status provides a comprehensive dashboard for Prisma Access infrastructure health.

177
MCQmedium

An administrator needs to configure secure access for remote networks using dynamic routing (BGP). Where are the BGP peer parameters, local AS number, and peer AS configured in Prisma Access?

A.Panorama > Cloud Services > Configuration > Remote Networks > [Select Network] > BGP
B.Objects > Remote Networks > BGP Profile
C.Network > Virtual Routers > BGP
D.Device > Setup > Routing > BGP
AnswerA

BGP peer IP, AS numbers, and routing preferences are configured directly inside each remote network's settings in the Cloud Services plugin.

Why this answer

BGP settings for remote networks are configured within the Remote Network definition in the Panorama Cloud Services plugin.

178
MCQhard

An organization uses SAML authentication with Prisma Access for mobile users. Users report an intermittent 'Authentication Failed' error when trying to establish a GlobalProtect connection. The Identity Provider (IdP) logs show successful authentication, but Prisma Access logs indicate a failure. What is the most likely cause of this discrepancy?

A.The GlobalProtect client software license has expired on Panorama.
B.Clock skew between the SAML Identity Provider and the Prisma Access service nodes exceeding the allowed tolerance window.
C.The User-ID agent service on the Panorama management server is stopped.
D.WildFire cloud subscription has lapsed.
AnswerB

SAML assertions have strict validity timestamps (NotBefore and NotOnOrAfter); significant clock skew causes the firewall to reject the assertion.

Why this answer

SAML assertion validation failures often occur due to clock skew between the IdP and the Prisma Access authentication profile settings.

179
MCQmedium

An administrator configures a new Service Connection in Prisma Access to allow mobile users to access resources in the corporate data center. However, traffic from mobile users cannot reach the data center. The administrator confirms that the IPsec tunnel is up. What is the most likely cause of this issue in Panorama?

A.Panorama requires a reboot to activate Service Connections.
B.The internal subnet routes associated with the Service Connection have not been added to the Mobile Users Explicit Proxy or Split Tunnel configuration.
C.The GlobalProtect client version is outdated on all endpoints.
D.The WildFire public cloud subscription has expired.
AnswerB

Mobile users will not route traffic destined for the corporate data center into Prisma Access unless the corresponding internal subnets are defined in their split tunnel / routing configuration.

Why this answer

When setting up Service Connections, administrators must update the Mobile Users explicit proxy or explicit routing settings (specifically pushing internal routes via the GlobalProtect agent config) so that clients know to send data center traffic through the Prisma Access tunnel.

180
MCQmedium

When using Cloud Identity Engine (CIE) for authentication, which method allows for the most seamless user experience for mobile users?

A.RADIUS authentication.
B.SAML integration with a cloud identity provider.
C.LDAP without SSL.
D.Local database on the firewall.
AnswerB

SAML allows for modern auth like MFA and SSO.

Why this answer

SAML with a Cloud Identity Provider is the standard for modern identity integration in Prisma Access.

181
MCQmedium

A network engineer is configuring a Service Connection in Prisma Access to connect the cloud security infrastructure back to the corporate data center. Which routing protocol is supported natively by Prisma Access to dynamically exchange routes over the IPsec VPN tunnel?

A.BGP
B.EIGRP
C.RIPv2
D.OSPF
AnswerA

BGP is the industry standard dynamic routing protocol supported across Prisma Access IPsec connections.

Why this answer

Prisma Access supports BGP (Border Gateway Protocol) over IPsec for dynamic routing on Service Connections and Remote Networks.

182
MCQmedium

An administrator troubleshooting a Prisma Access environment notices that specific traffic is bypassing security inspection. Upon checking the Security Policy, the administrator sees that a security rule has the profile setting set to 'None'. What does this configuration mean for traffic matching that rule?

A.Traffic matching the rule is dropped automatically.
B.SSL decryption is automatically enabled.
C.Traffic is forced through the explicit proxy.
D.Traffic allowed by the rule will not be inspected by Antivirus, Anti-Spyware, Vulnerability Protection, or WildFire security profiles.
AnswerD

A 'None' profile setting disables content-ID security inspection for sessions matching that specific security rule.

Why this answer

Setting security profiles to 'None' means that while App-ID and basic layer-4 security rules apply (allow/deny), advanced threat prevention, antivirus, and anti-spyware inspection are not performed on those sessions.

183
MCQmedium

An organization is deploying Prisma Access for mobile users and needs to ensure that users in Europe connect to European cloud nodes while users in North America connect to North American nodes. How does Prisma Access automatically achieve this geographic routing?

A.Active Directory site-to-site replication
B.Explicit Proxy PAC file geographic strings
C.Manual IP routing configuration on each user laptop
D.GlobalProtect cloud DNS resolution and regional gateway priority settings
AnswerD

GlobalProtect resolves connection requests to the nearest regional cloud service location automatically.

Why this answer

GlobalProtect cloud service uses a worldwide DNS infrastructure and cloud routing mechanism to direct client connection requests to the nearest geographic node.

184
Multi-Selectmedium

An administrator wants to ensure high availability and resilient connectivity for mobile users connecting to Prisma Access. Which TWO features or mechanisms are utilized by Prisma Access to ensure reliable mobile user access? (Choose two)

Select 2 answers
A.Static routing tables configured locally on Windows and macOS registry settings
B.Cloud-scale redundant gateway architecture across multiple geographic locations
C.Manual IPsec tunnel failover scripting executed on each endpoint device
D.On-premise physical hardware load balancers deployed in front of mobile user tunnels
E.Automatic gateway selection directing clients to the best performing regional service node
AnswersB, E

Prisma Access runs redundant nodes in every deployed region to ensure service uptime.

Why this answer

Prisma Access provides mobile user high availability via automated gateway selection, regional redundancy, and client reconnect capabilities.

185
MCQmedium

An administrator needs to configure Prisma Access Remote Networks to route specific corporate traffic to a local data center while sending internet-bound traffic directly through Prisma Access. Which configuration component in Panorama is used to define this split-tunneling behavior?

A.Traffic Distribution profile
B.GlobalProtect Client-less VPN portal settings
C.Decryption Policy rules
D.Subnets included in the Remote Network definition
AnswerD

Administrators define exact subnets that should be routed via Prisma Access in the Remote Network configuration, effectively enabling split tunneling.

Why this answer

In Prisma Access Remote Networks, split tunneling is controlled via the Traffic Distribution profile or explicit static routes configured under Network Services -> Prisma Access -> Remote Networks.

186
Multi-Selecthard

When troubleshooting a Prisma Access deployment where traffic from remote users is failing Threat Prevention inspection, which TWO components or configurations must be verified? (Choose two)

Select 2 answers
A.Decryption policy configuration ensuring traffic is not bypassing inspection
B.Cloud Access Security Broker (CASB) API connector tokens
C.GlobalProtect user username-to-IP mapping agent status
D.Security Policy rules having appropriate Threat Prevention profiles (Antivirus, Vulnerability, Anti-Spyware) attached
E.Service Connection BGP peer keepalive intervals
AnswersA, D

Encrypted traffic cannot be inspected for threats unless a Decryption policy is actively decrypting the session.

Why this answer

For Threat Prevention to inspect traffic in Prisma Access, Decryption policies must be active (since most traffic is SSL/TLS encrypted) and Anti-Spyware/Antivirus security profiles must be attached to the respective Security Policy rules.

187
Multi-Selecthard

When troubleshooting SSL Decryption issues in a Prisma Access environment where users report certificate warnings, which THREE areas should an administrator inspect? (Choose three)

Select 3 answers
A.Check the Decryption Policy rules to ensure the correct traffic zones, URLs, and actions (Decrypt/No Decrypt) are configured.
B.Verify the BGP routing table for Service Connection prefixes.
C.Inspect Inbound Decryption rule server certificates and private keys to ensure proper binding.
D.Check the GlobalProtect client version installed on mobile workstations.
E.Verify that the Forward Trust and Forward Untrust certificates installed in Prisma Access are signed by the organization's internal Enterprise CA and trusted by endpoints.
AnswersA, C, E

Incorrectly matched decryption rules can cause improper interception or un-trusted certificate presentation.

Why this answer

Decryption troubleshooting requires verifying certificate trust chains, forwarding/inbound profile settings, and explicit proxy/decryption policy bindings.

188
Multi-Selecthard

An enterprise is planning a Prisma Access deployment and wants to optimize performance and redundancy for Remote Networks. Which THREE best practices should the network architect follow when designing IPsec connections to Prisma Access? (Choose three)

Select 3 answers
A.Disable Dead Peer Detection (DPD) to keep tunnels permanently active.
B.Configure redundant IPsec tunnels from separate CPE devices or diverse ISP connections to Prisma Access.
C.Configure MSS clamping on the CPE routers to prevent fragmentation over IPsec tunnels.
D.Use OSPF area 0 across all IPsec tunnels to establish fast convergence.
E.Implement BGP dynamic routing over the IPsec tunnels for automated failover.
AnswersB, C, E

Redundant tunnels ensure high availability in case of ISP or CPE failure.

Why this answer

Best practices for Remote Networks include configuring redundant tunnels, enabling BGP for dynamic routing, and selecting appropriate MTU/MSS settings.

189
Multi-Selecthard

An administrator is troubleshooting a Prisma Access explicit proxy deployment where users report that specific web applications are failing with connection timeout errors. Which THREE areas should the administrator check? (Choose three)

Select 3 answers
A.Inspect Proxy Authentication and Decryption profiles to ensure authentication challenges are correctly processed.
B.Verify the BGP AS number on the Service Connection.
C.Check Security Policy rules to ensure traffic destined for the explicit proxy listener ports is allowed.
D.Verify that explicit proxy port settings and proxy profiles match what is configured on the client browser or PAC file.
E.Check the GlobalProtect client pre-logon timeout value.
AnswersA, C, D

Misconfigured proxy authentication can cause connection stalls and timeouts.

Why this answer

Explicit proxy troubleshooting involves verifying proxy profile configurations, security rules allowing proxy traffic, PAC file distribution, and decryption settings.

190
MCQeasy

An administrator needs to troubleshoot a Security Policy rule that is expected to block access to unauthorized cloud storage applications in a Prisma Access environment. Where can the administrator view real-time data regarding which specific applications are being utilized by remote users?

A.Panorama > Setup > Operations
B.Panorama > ACC (App-Command Center)
C.Panorama > Managed Devices > Summary
D.Prisma Access > Cloud Services > Dashboard > Status
AnswerB

The ACC provides graphical dashboards detailing application traffic, user activity, and risk factors.

Why this answer

The ACC (App-Command Center) provides visual summaries of application usage, threats, and web activity in real time.

191
Multi-Selecthard

An administrator is configuring User-ID and authentication for Prisma Access using the Cloud Identity Engine (CIE). Which TWO actions must be performed to ensure successful authentication and group-based policy enforcement? (Choose two)

Select 2 answers
A.Disable all multi-factor authentication (MFA) requirements on Prisma Access portals.
B.Configure Group Mapping Settings in Panorama to retrieve user group memberships from the Cloud Identity Engine.
C.Install the GlobalProtect agent directly on all domain controller servers acting as CIE proxies.
D.Configure an Authentication Profile in Panorama that references the Cloud Identity Engine container.
E.Manually export user CSV files daily and upload them to Panorama using the CLI.
AnswersB, D

Group mapping is essential so that Security Policy rules can evaluate and enforce access based on Active Directory group membership.

Why this answer

To use CIE with Prisma Access, you must connect the directory service via the CIE agent or integration, configure the Authentication Profile in Panorama to point to CIE, and apply group mapping.

192
MCQmedium

An administrator notices that the Panorama management server is failing to push configuration updates to Prisma Access nodes. Where should the administrator check for configuration push failure details and error logs in Panorama?

A.Panorama > Job Status or Monitor > Logs > Config / System.
B.Cloud Services > Status > Remote Networks.
C.Device > High Availability.
D.Policies > Security > Audit.
AnswerA

The Job Status window displays active and failed push jobs with detailed error codes for troubleshooting configuration sync issues.

Why this answer

Job status and config push logs in Panorama record failures and specific error messages when pushing configurations to Prisma Access.

193
MCQhard

A Prisma Access administrator notices that remote network traffic destined for another remote network (branch-to-branch traffic) is being dropped or failing to establish. What is the required configuration to allow branch-to-branch traffic?

A.Configure static routes pointing to the loopback interface on every remote network gateway.
B.Enable 'Branch-to-Branch' routing under Panorama > Cloud Services > Configuration > Remote Networks and create matching security rules.
C.Enable GlobalProtect Clientless VPN on all remote network gateways.
D.Deploy dedicated external hardware firewalls at each branch location.
AnswerB

Branch-to-branch traffic requires both the routing enablement within the remote network configuration and permissive security policies.

Why this answer

By default, branch-to-branch traffic in Prisma Access must be explicitly allowed in the Prisma Access traffic steering and security policy configurations.

194
Multi-Selecthard

An administrator is troubleshooting a connectivity issue where remote mobile users cannot reach internal private applications via Prisma Access ZTNA. Which THREE diagnostic steps or verification checks should the administrator perform? (Choose three)

Select 3 answers
A.Verify that the GlobalProtect app on the user endpoint has successfully established a secure tunnel and updated its Host Information Profile (HIP)
B.Check the status of the Prisma Access App Connectors in the management plane to ensure they are connected and healthy
C.Reboot the physical public cloud provider datacenter hypervisor hosting the tenant
D.Review the Prisma Access Traffic and Threat logs to confirm whether security policy rules are dropping or allowing the application traffic
E.Reconfigure the local ISP router's BGP autonomous system number to match the Prisma Access gateway
AnswersA, B, D

If the GlobalProtect tunnel is down or HIP checks fail, the user will be blocked from accessing ZTNA private applications.

Why this answer

Troubleshooting Prisma Access ZTNA connectivity involves verifying the GlobalProtect connection status and HIP report, ensuring the Prisma Access App Connector is online and reachable, and checking the Security Policy rules for App-ID blocks.

195
MCQmedium

An administrator is troubleshooting a CASB inline policy where a specific file upload to an unapproved SaaS application was not blocked. Upon checking the Security policy, the rule has the correct application identified. What is the most likely reason the inline action failed to trigger?

A.The GlobalProtect agent version is outdated.
B.The User-ID agent is offline.
C.SSL Decryption is disabled for the traffic flow.
D.SaaS Security API sync interval needs to be refreshed.
AnswerC

Without SSL Decryption, Prisma Access cannot inspect HTTP headers or payload contents to enforce inline CASB restrictions.

Why this answer

Inline CASB controls in Prisma Access require SSL Decryption to be enabled because SaaS traffic is encrypted via HTTPS.

196
MCQhard

A Prisma Access mobile user reports that they cannot access internal resources, and the GlobalProtect app status shows 'Connected' but with an internal IP address assigned from the reserve pool. What is the most likely cause of routing failure?

A.The internal subnets are not included in the GlobalProtect Agent Split Tunneling 'Include Access Route' list.
B.The user's Active Directory password has expired in the Cloud Identity Engine.
C.The WildFire file size limit was exceeded.
D.The HIP check failed due to an outdated operating system patch.
AnswerA

If internal subnets are omitted from the include routes, the client will not tunnel traffic destined for those internal networks.

Why this answer

Split tunneling configurations or missing network includes in the GlobalProtect agent configuration prevent traffic from routing correctly to internal networks.

197
MCQhard

An administrator notices that specific applications identified via App-ID are failing decryption inspection in Prisma Access because the server uses an unsupported cipher suite. Where can the administrator adjust the SSL decryption profile to resolve handshake failures?

A.Panorama > Cloud Services > Global Settings > Decryption
B.Device > Certificate Management > SSL Policy
C.Policies > Decryption > Settings
D.Objects > Decryption > SSL Decryption Profile
AnswerD

SSL Decryption profiles define which TLS versions, cipher suites, and handling methods are applied during traffic inspection.

Why this answer

SSL Decryption profiles govern cipher suites, minimum TLS versions, and handling of unsupported options.

198
Multi-Selecthard

An administrator is setting up Prisma Access logging and monitoring. Which THREE logs or reporting features in Panorama provide insights into SWG, ZTNA, and CASB activities? (Choose three)

Select 3 answers
A.Threat logs for malware, spyware, and vulnerability exploit detections.
B.Hardware environmental temperature and power supply status logs.
C.Data Filtering logs for sensitive data exfiltration attempts.
D.URL Filtering logs for web category access and SWG policy enforcement.
E.CLI debug logs from physical core router interfaces.
AnswersA, C, D

Threat logs record security violations detected by FWaaS and SWG security profiles.

Why this answer

Panorama provides specialized logs for URLs, threats, traffic, and SaaS activities to monitor SSE domains.

199
MCQeasy

An administrator wants to deploy Secure Web Gateway (SWG) capabilities in Prisma Access to prevent users from uploading company proprietary data to unauthorized cloud storage applications. Which Prisma Access profile type should be applied to the Security Policy rules to achieve this?

A.Zone Protection profile
B.Antivirus profile
C.Data Filtering profile
D.URL Filtering profile
AnswerC

Data Filtering profiles inspect content for patterns such as credit cards, SSNs, or custom data patterns to block unauthorized uploads.

Why this answer

Data Filtering profiles inspect outgoing traffic for specific patterns, file types, and sensitive data to prevent data exfiltration in SWG deployments.

200
Multi-Selecthard

An administrator is troubleshooting a Prisma Access mobile user deployment where GlobalProtect clients are unable to connect. Which THREE components or settings should the administrator inspect to resolve the connection failure? (Choose three)

Select 3 answers
A.Inspect the GlobalProtect Client Settings in Panorama to ensure gateways and agent configurations are correctly assigned.
B.Verify that the SSL/TLS certificates assigned to the GlobalProtect Portal and Gateways are valid and trusted by client devices.
C.Check the WildFire file size upload limit for malicious attachments.
D.Verify the BGP AS number configured on the customer data center router.
E.Check the Authentication Profile to ensure RADIUS, LDAP, or SAML servers are reachable and responding.
AnswersA, B, E

Incorrectly configured client settings prevent the agent from locating gateways or receiving necessary parameters.

Why this answer

GlobalProtect connection failures for mobile users typically involve portal/gateway certificates, authentication profiles, and client configuration profiles.

201
Multi-Selecteasy

Which TWO configuration steps are required to allow internet access for Remote Network users?

Select 2 answers
A.Enable Internet Access in the Remote Network configuration.
B.Install a local proxy server.
C.Assign a static IP address to every mobile device.
D.Configure an IPSec tunnel to a third-party ISP.
E.Create a Security Policy allowing the Remote Network zone to the Internet zone.
AnswersA, E

This setting is required to enable internet egress.

Why this answer

To allow internet access, the remote network needs to be configured and a security policy must permit the traffic from the remote network zone to the internet zone.

202
MCQeasy

An administrator is troubleshooting a policy where applications are being identified incorrectly in Prisma Access. Which tool should be used to inspect how Prisma Access performs App-ID identification on a live stream of packets?

A.Verify the SSL decryption certificate chain.
B.Check the GlobalProtect client configuration profile.
C.Examine the Traffic log session details to view the detected App-ID, or use packet captures if necessary.
D.Review the Panorama Audit log.
AnswerC

Traffic log entries show the final App-ID determined by Prisma Access for each session.

Why this answer

Packet capture (pcap) or policy evaluation tools are used to inspect traffic; flow basic diagnostics are done via traffic logs and session info.

203
MCQmedium

An administrator wants to configure Prisma Access Secure Web Gateway to block access to sites categorized as 'Gambling' during working hours, but allow them during lunch breaks. Which Panorama feature enables time-based policy enforcement?

A.Prisma Access Insights time-window filters
B.URL Filtering custom time-out profiles
C.Schedule Objects applied to Security Policy rules
D.GlobalProtect Portal connection timers
AnswerC

Schedule objects allow administrators to define specific time windows when a security policy rule is active.

Why this answer

Schedule objects in Panorama can be applied to Security Policy rules to enforce rules only during specified days and times.

Page 2

Page 3 of 3

All pages