Courseiva
Prisma Access TroubleshootingmediumMultiple ChoiceObjective-mapped

SSE-Engineer Prisma Access Troubleshooting Practice Question

An administrator notices that users connecting via Prisma Access Remote Networks are unable to reach a specific internal application hosted in the corporate datacenter. The traffic is dropped by Prisma Access. Which tool in Panorama should the administrator use first to verify if the security policy is matching and blocking the traffic in real-time?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Traffic Logs with a filter for the source user and destination IP, checking the 'Drop Reason' field.

ACC (App-Command Center) and Traffic Logs are used to inspect sessions, but the ACC does not provide real-time session debugging for specific policy rule matches. The Panorama Traffic log with the correct filter or the CLI command 'test security-policy-match' is used to troubleshoot policy matches, but for real-time monitoring of dropped packets on Prisma Access nodes, Traffic Logs filtered by drop cause or using the Real-Time Log Viewer is the most appropriate native UI troubleshooting mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • GlobalProtect app diagnostics tab on the endpoint.

    Why it's wrong here

    GlobalProtect diagnostics are for client-side connection issues, not backend datacenter routing or security policy drops.

  • Prisma Access Insight path quality monitoring.

    Why it's wrong here

    Path Quality Monitoring is used for QoS and latency metrics, not security policy drops.

  • Traffic Logs with a filter for the source user and destination IP, checking the 'Drop Reason' field.

    Why this is correct

    Traffic Logs record the drop reason and allow administrators to immediately see if a security policy rule denied the traffic.

  • Panorama Dynamic Updates status page.

    Why it's wrong here

    Dynamic updates check for antivirus and threat signatures, not policy matches.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 203 original SSE-Engineer practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This SSE-Engineer practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSE-Engineer exam.