Courseiva

CCNA Prisma Access Administration And Operation Questions

49 questions · Prisma Access Administration And Operation · All types, answers revealed

1
Multi-Selectmedium

An administrator wants to ensure that mobile users comply with security posture policies before accessing corporate applications. Which TWO elements are required to enforce HIP (Host Information Profile) checking? (Choose two)

Select 2 answers
A.Enable HIP data collection on the GlobalProtect agent settings.
B.Configure static ARP entries on the GlobalProtect gateway.
C.Reference the created HIP Object or Profile within Security policy rules.
D.Deploy WildFire appliance hardware at every branch location.
E.Install a local proxy server on every mobile device.
AnswersA, C

The GlobalProtect agent must be configured to gather endpoint security posture data (patches, antivirus, disk encryption).

Why this answer

HIP enforcement requires collecting profiles via the GlobalProtect agent and enforcing them in Security rules.

2
Multi-Selectmedium

Which TWO of the following are prerequisites for setting up Cloud Identity Engine (CIE) with Prisma Access?

Select 2 answers
A.Active Directory Domain Controller installation on Prisma Access.
B.Configuring DNS on the local workstation.
C.An identity provider (IdP) integration, such as Azure AD or Okta.
D.Deploying a hardware firewall at every branch.
E.Enabling the Cloud Identity Engine service in the Prisma Access tenant.
AnswersC, E

This is the core identity source for CIE.

Why this answer

CIE requires an identity source integration and the enablement of the CIE service on the tenant.

3
MCQhard

You are troubleshooting a Mobile User connectivity issue where users cannot access internal resources. The Cloud Identity Engine (CIE) shows the user as authenticated, but the Security Policy log shows the traffic is dropped with 'policy-deny'. What is the most likely cause?

A.The Security Policy rule source zone or user-group mapping does not match the incoming traffic flow.
B.The GlobalProtect portal is down.
C.The CIE directory sync is failing.
D.The Prisma Access license has expired.
AnswerA

This is a common cause for 'policy-deny' when identity is confirmed but access is blocked.

Why this answer

When the user is authenticated but traffic is dropped by policy, it usually indicates that the source user or group mapping is not being correctly identified in the Security Policy, or the specific traffic rule is missing.

4
MCQeasy

An administrator needs to configure remote networks in Prisma Access to connect branch locations. Where is this configuration primarily managed within the Prisma Access architecture?

A.Prisma Access App > Traffic Steering > Remote Networks
B.Panorama > Cloud Services > Configuration > Remote Networks
C.Policies > Security > Remote Networks
D.Device > Setup > Operations > Remote Networks
AnswerB

This is the correct navigation path in Panorama to configure remote network locations, bandwidth allocations, and IPsec tunnels.

Why this answer

Prisma Access remote networks and mobile user configurations are managed centrally through Panorama using the Cloud Services plugin.

5
MCQmedium

An organization requires that specific SaaS applications are accessed only by corporate-managed devices that pass a specific HIP check. Which policy type should the administrator configure?

A.Security Policy Rule referencing the HIP Profile
B.Decryption Policy applying inbound SSL decryption
C.QoS Policy referencing the HIP Object
D.Authentication Policy enforcing GlobalProtect gateway authentication
AnswerA

Security rules allow administrators to enforce access restrictions based on whether a device matches a specific HIP Profile.

Why this answer

HIP checks are enforced within Security Policy rules by referencing the desired HIP Object or HIP Profile in the rule's criteria.

6
MCQmedium

An administrator needs to ensure that mobile users connecting via Prisma Access resolve internal domain names using the corporate DNS servers rather than public resolvers. Where is this configured?

A.Objects > GlobalProtect > DNS Profile
B.Panorama > Cloud Services > Configuration > Mobile Users > Client Settings
C.Device > Setup > Services > DNS
D.Network > GlobalProtect > Gateway > DNS
AnswerB

Client settings allow administrators to push network parameters, such as internal DNS and IP addresses, to the GlobalProtect app.

Why this answer

GlobalProtect client settings, including primary and secondary DNS servers assigned to mobile users, are configured within the GlobalProtect Client Settings in Panorama.

7
MCQmedium

An administrator is configuring Remote Networks in Prisma Access for a branch office using Internet Key Exchange Version 2 (IKEv2). During the configuration in Panorama, which component must be deployed on the branch office router to ensure proper IPsec tunnel establishment with the Prisma Access Service Connections and Remote Networks nodes?

A.The GlobalProtect app configured in manual gateway connection mode.
B.An active Prisma Access Insights API token for dynamic routing updates.
C.The Cloud Identity Engine agent installed locally on the branch router's operating system.
D.A valid public IP address and a pre-shared key matching the IKE gateway configuration defined in Panorama.
AnswerD

Prisma Access requires the branch router to have a static public IP and matching authentication credentials (such as a pre-shared key) to authenticate the IKEv2 gateway.

Why this answer

To establish a secure IPsec tunnel between a branch office and Prisma Access, the branch office router must be configured with a public IP address, support IKEv2, and use a pre-shared key or certificate matching the Panorama Remote Networks configuration.

8
MCQmedium

An administrator wants to inspect outbound web traffic from mobile users for malware and spyware using Prisma Access. Which security profile type must be attached to the Security policy rule?

A.Antivirus and Anti-Spyware profiles
B.Decryption profile and URL filtering profile only
C.QoS Profile and Zone Protection profile
D.HIP Profile and WildFire analysis profile
AnswerA

Antivirus profiles protect against file-based malware, and anti-spyware profiles protect against malicious callbacks.

Why this answer

Antivirus and Anti-Spyware profiles inspect traffic passing through security rules for known malware and command-and-control signatures.

9
Multi-Selecthard

Which THREE factors influence the selection of a Compute Location in a Prisma Access deployment?

Select 3 answers
A.The number of users in the local branch.
B.Local ISP latency and bandwidth.
C.Geographic proximity to the mobile user.
D.Available capacity in the compute location.
E.The color of the hardware appliance.
AnswersB, C, D

Network performance is a key factor.

Why this answer

Compute locations are chosen based on proximity to users, licensing availability, and the specific traffic type.

10
MCQeasy

An administrator wants to view real-time metrics, node status, and active connection counts for Prisma Access Mobile Users and Remote Networks directly from Panorama. Which tool within Panorama should the administrator access?

A.GlobalProtect Portal Diagnostics Tool
B.Command Center CLI
C.Prisma Access Insights
D.Cloud Identity Engine Console
AnswerC

Prisma Access Insights is the native dashboard and monitoring tool built into Panorama for operational visibility.

Why this answer

Prisma Access Insights provides a centralized dashboard in Panorama for monitoring service health, bandwidth utilization, and active connections.

11
Multi-Selecthard

An administrator is troubleshooting connectivity issues for a remote network connected to Prisma Access via IPsec VPN. Which TWO checks should be performed to verify tunnel health and status? (Choose two)

Select 2 answers
A.Inspect the GlobalProtect client runtime logs on the mobile user's laptop.
B.Check the IPsec tunnel status under Panorama > Cloud Services > Status > Remote Networks.
C.Check the DNS resolver settings in the local device setup tab.
D.Run a physical cable test from the Prisma Access cloud node to the carrier router.
E.Verify IKE and IPsec cryptographic and phase settings match on both the Prisma Access side and the customer edge router.
AnswersB, E

This status view displays real-time IPsec tunnel establishment and connection health for remote networks.

Why this answer

IPsec tunnel status can be validated via cloud status monitors and standard tunnel monitoring logs.

12
MCQhard

You are deploying Prisma Access and need to ensure that traffic from mobile users accessing the internet is inspected by a specific set of security profiles. Where should these profiles be applied?

A.In the GlobalProtect Gateway settings.
B.In the Service Connection configuration.
C.In the Cloud Identity Engine configuration.
D.In the Panorama Security Policy rule matching the traffic.
AnswerD

Security Policies are where you link Security Profiles to traffic.

Why this answer

Security Profiles must be attached to the Security Policy rules that govern the specific traffic flow.

13
MCQmedium

An organization is migrating its identity provider integration to the Cloud Identity Engine (CIE) to support Prisma Access authentication and User-ID. When configuring the connection between CIE and the enterprise Active Directory, which component is required on-premises to sync directory objects securely without opening inbound firewall ports?

A.Prisma Access User-ID Syslog Listener
B.GlobalProtect Gateway Proxy
C.Cloud Identity Engine Agent
D.Panorama Log Collector
AnswerC

The CIE Agent initiates an outbound connection to the cloud service, allowing secure directory synchronization without inbound firewall rules.

Why this answer

The Cloud Identity Engine Agent runs on-premises and establishes an outbound secure connection to CIE, synchronizing directory data without requiring inbound firewall changes.

14
MCQhard

A security engineer needs to configure a Security policy rule in Prisma Access that targets users belonging to a specific Active Directory group synced via the Cloud Identity Engine. How should the source user be specified in the Security rule?

A.In the Source Device field, select the Cloud Identity Engine connector object.
B.In the IP/Netmask field, enter the subnet assigned by the CIE connector.
C.In the Destination field, specify the LDAP server IP address.
D.In the Source User field, add the fully qualified group name provided by CIE.
AnswerD

Security rules evaluate user and group identity directly when placed in the Source User/Group field of the rule.

Why this answer

When using CIE or User-ID, security rules reference group objects directly using the format domain\group or the discovered group name.

15
MCQmedium

Which object type should be used to restrict access to a specific internal application for Remote Network users while ensuring the policy is scalable?

A.URL filtering category.
B.Address objects or Address Groups.
C.Service objects based on port numbers only.
D.Interface-based rules.
AnswerB

Objects allow for scalable and manageable policy definitions.

Why this answer

Address objects or Address Groups allow for efficient grouping and reuse in security policies.

16
Multi-Selectmedium

An administrator is reviewing the status of Remote Networks in Prisma Access and notices that an IPsec tunnel has failed to establish. Which THREE diagnostic steps or verifications should the administrator perform in Panorama or Prisma Access Insights? (Choose three)

Select 3 answers
A.Modify the GlobalProtect client configuration to force internal DNS resolution.
B.Reboot the Cloud Identity Engine container to clear stale routing cache entries.
C.Verify that the peer public IP address configured in Panorama matches the public IP of the branch office router.
D.Check that IKE Phase 1 and Phase 2 cryptographic proposals (encryption, authentication, DH group) match on both the Prisma Access side and the branch router.
E.Review Prisma Access Insights to check tunnel status, error logs, and event details.
AnswersC, D, E

An incorrect peer IP address will prevent the IKE security association from initiating successfully.

Why this answer

Troubleshooting IPsec tunnels in Prisma Access involves verifying pre-shared keys or certificates, checking public IP settings, confirming correct Phase 1/Phase 2 proposal settings, and examining system logs via Prisma Access Insights.

17
MCQmedium

When configuring a Remote Network (RN) connection to an on-premises data center, which parameter is required to ensure proper routing of internal traffic via the IPSec tunnel?

A.Primary and Secondary IKE gateways.
B.The User-ID agent IP address.
C.The BGP peer IP address or static routes defining the internal subnets.
D.The GlobalProtect Gateway IP.
AnswerC

Static or dynamic routing is essential for traffic to reach internal resources.

Why this answer

The BGP peer configuration or static routes within the Remote Network settings ensure the Prisma Access cloud knows which subnets to route through the tunnel.

18
Multi-Selectmedium

An administrator is configuring security policies in Prisma Access and wants to ensure comprehensive protection against unknown threats and malware. Which TWO security profile types should be applied to outbound and internet-bound rules? (Choose two)

Select 2 answers
A.Vulnerability Protection profile
B.WildFire Analysis profile
C.Decryption profile assigned directly to the threat engine
D.Zone Protection profile
E.QoS profile for traffic shaping
AnswersA, B

Vulnerability protection blocks network-based exploits targeting known software bugs and vulnerabilities.

Why this answer

WildFire and Vulnerability Protection profiles defend against zero-day exploits and known vulnerabilities.

19
Multi-Selectmedium

When configuring Security policy rules in Prisma Access, which THREE types of criteria can be used to control traffic traversing the cloud infrastructure? (Choose three)

Select 3 answers
A.Source and destination security zones
B.Local physical switch port numbers on the cloud node
C.Applications identified via App-ID
D.Hardware motherboard serial numbers of client machines
E.User and Group identities via User-ID or CIE
AnswersA, C, E

Security zones (such as remote-network, mobile-user, or trust zones) are fundamental match criteria.

Why this answer

Prisma Access security policies support standard PAN-OS match criteria including applications, users, zones, and regions.

20
MCQmedium

An administrator is troubleshooting a scenario where remote users connected via Prisma Access Mobile Users cannot access a specific newly added subnet behind a Remote Network location. Which configuration check should the administrator perform first in Panorama?

A.Restart the Cloud Identity Engine agent on the domain controller to refresh IP-to-user mappings.
B.Verify that Security Policy rules permit traffic from the Mobile Users zone to the Remote Networks zone, and that the remote subnet is included in the Remote Network configuration.
C.Reinstall the GlobalProtect agent on all remote user machines to update the gateway list.
D.Generate a new API key in Prisma Access Insights to force a routing table recalculation.
AnswerB

Inter-zone traffic must be explicitly allowed by Security Policy rules, and Remote Networks must advertise the correct subnets so Prisma Access routing knows how to forward the packets.

Why this answer

To allow communication between different Prisma Access access types (such as Mobile Users to Remote Networks), the administrator must ensure that inter-zone traffic is permitted and that routing/address spaces are properly advertised in Panorama.

21
MCQeasy

What is the benefit of using Prisma Access for Remote Networks instead of traditional site-to-site VPNs?

A.It allows local traffic to bypass security inspection entirely.
B.It provides centralized, unified security policy management and inspection.
C.It eliminates the need for internet connectivity at the branch.
D.It removes the need for any internal firewalls.
AnswerB

The main benefit is centralizing security and inspection.

Why this answer

Prisma Access simplifies management and provides consistent security policy enforcement across all locations.

22
Multi-Selectmedium

An administrator is configuring Mobile Users in Prisma Access and needs to set up user authentication. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)

Select 2 answers
A.Local database accounts stored on the individual Prisma Access cloud nodes
B.WPA3 Enterprise 802.1X enterprise tunneling
C.IPsec Pre-Shared Key user authentication
D.LDAP directory authentication
E.SAML 2.0 identity provider integration
AnswersD, E

LDAP server profiles allow direct authentication against Active Directory or LDAP directories.

Why this answer

Prisma Access supports multiple authentication mechanisms including SAML 2.0 and LDAP/RADIUS via authentication profiles.

23
MCQeasy

Which tool provides end-to-end visibility into Prisma Access performance, user experience metrics, and digital experience monitoring (DEM)?

A.WildFire Portal reporting
B.Panorama Packet Capture utility
C.Prisma Access ADEM (Autonomous Digital Experience Management)
D.GlobalProtect Syslog Analyzer
AnswerC

ADEM provides telemetry and troubleshooting data regarding endpoint, Wi-Fi, and cloud path performance for Prisma Access users.

Why this answer

Autonomous DEM (ADEM) for Prisma Access provides visibility into end-user experience, endpoint health, and path performance.

24
MCQhard

An administrator configures Decryption Policies in Prisma Access to inspect inbound traffic destined for internal applications published via Service Connections. Users report that certain internal web applications using custom internal Certificate Authorities (CAs) are failing TLS handshakes. Where should the administrator check and install the enterprise internal CA certificate to resolve this inspection issue?

A.GlobalProtect Portal > Client Settings > Authentication, and push the CA via client configuration.
B.Panorama > Certificate Management > Certificates, and ensure the internal CA is imported and trusted for SSL decryption.
C.Cloud Identity Engine > Settings > Trusted Roots, and sync the certificate via LDAP.
D.Prisma Access Insights > Policies > Decryption, and toggle the 'Bypass Internal CA' switch.
AnswerB

Importing the internal CA into Panorama and setting the trust flags allows Prisma Access nodes to validate and decrypt traffic destined for internal resources securely.

Why this answer

For Prisma Access to successfully issue forward proxy certificates or trust internal servers during SSL decryption, the internal enterprise CA certificate must be imported into the Certificate Management store in Panorama and marked as a trusted root CA.

25
MCQeasy

A network administrator wants to enable User-ID for mobile users connecting via GlobalProtect in Prisma Access. Which component should be configured to map users to IP addresses when using the Cloud Identity Engine?

A.Configure a User-ID agent on every branch router.
B.Install the GlobalProtect agent with local syslog forwarding.
C.Enable captive portal authentication on all remote network firewalls.
D.Configure Cloud Identity Engine (CIE) settings in Panorama to sync directory services.
AnswerD

CIE integrates with enterprise directory services to provide seamless user and group mapping for Prisma Access.

Why this answer

The Cloud Identity Engine (CIE) acts as the directory sync mechanism to gather user and group mapping information for Prisma Access.

26
MCQeasy

Which pane in the Prisma Access monitoring interface provides an overview of active mobile users, connection status, and geographical distribution?

A.Policies > Security > Status
B.Network > GlobalProtect > Runtime
C.Monitor > ACC or the Prisma Access App dashboard
D.Device > Status > Active Users
AnswerC

The ACC and Prisma Access App dashboards display graphical summaries of active mobile users, locations, and traffic.

Why this answer

The Prisma Access monitoring app and Panorama's ACC provide real-time dashboards for mobile user connectivity.

27
Multi-Selecthard

When designing high availability and redundancy for Prisma Access Remote Networks, which THREE considerations or practices are essential? (Choose three)

Select 3 answers
A.Cluster physical firewalls in an Active-Active HA pair inside the Prisma Access cloud infrastructure.
B.Implement dynamic routing protocols (BGP) over the IPsec tunnels to facilitate automatic failover.
C.Deploy dual customer edge routers at the branch location connecting to Prisma Access.
D.Configure redundant IPsec tunnels from customer premises equipment (CPE) to diverse Prisma Access gateways.
E.Manually update static routes on employee laptops whenever a remote network link fails.
AnswersB, C, D

BGP allows routers to dynamically adjust paths and switch traffic to secondary tunnels upon link failure.

Why this answer

Remote network redundancy relies on redundant IPsec tunnels, BGP multipath/failover, and dual edge routers.

28
MCQeasy

Which component in Prisma Access is responsible for performing decryption, content inspection, and threat prevention for mobile users?

A.Compute Location
B.GlobalProtect Portal
C.Service Connection
D.Panorama
E.Cloud Identity Engine
AnswerA

Compute locations perform the actual traffic processing for mobile users.

Why this answer

The Service Connection is for branch-to-datacenter traffic, while the Compute Location handles the actual inspection for mobile users.

29
Multi-Selecthard

When designing Security and Inspection Policies for Prisma Access, an administrator needs to ensure optimal performance and security coverage. Which THREE best practices should the administrator follow when implementing Security Policy rules in Panorama for Prisma Access? (Choose three)

Select 3 answers
A.Disable SSL Decryption globally to maximize Prisma Access processing throughput across all mobile user nodes.
B.Configure all Security Policy rules to use 'Any' application to simplify rule maintenance and reduce rule count.
C.Attach appropriate Security Profiles (such as Antivirus, Anti-Spyware, and Vulnerability Protection) to all active Security Policy allow rules.
D.Use App-ID and User-ID in security rules instead of relying solely on IP addresses and port numbers.
E.Place specific application allow rules above broad general rules, and maintain explicit deny rules for known malicious traffic where appropriate.
AnswersC, D, E

Security profiles inspect allowed application traffic for threats, which is a core best practice in Prisma Access.

Why this answer

Prisma Access security best practices include placing explicit block rules at the top, leveraging application-layer filtering rather than relying solely on ports/IPs, and utilizing Security Profiles (antivirus, anti-spyware, URL filtering) across rules.

30
MCQmedium

An administrator wants to configure authentication for mobile users using SAML 2.0 with Prisma Access. Where is the identity provider (IdP) metadata imported and configured?

A.Network > GlobalProtect > Portal > Authentication
B.Panorama > Cloud Services > Authentication > SAML
C.Device > Server Profiles > SAML Identity Provider
D.Objects > Cloud Identity Engine > SAML
AnswerC

SAML IdP server profiles are where metadata is imported and sign-on properties are established.

Why this answer

SAML identity provider server profiles are configured in Panorama under Device or Server Profiles before being assigned to GlobalProtect authentication profiles.

31
Multi-Selectmedium

When managing Security Policies in Prisma Access, which TWO components are essential to ensure that policies are correctly applied to traffic?

Select 2 answers
A.Using source/destination address objects or tags.
B.Enabling SSL inspection on all traffic.
C.Defining the physical port number.
D.Configuring the GlobalProtect client version.
E.Defining source and destination zones.
AnswersA, E

Objects allow for granularity in policy matching.

Why this answer

Security policies require zones and address objects (or user groups) to identify traffic uniquely.

32
Multi-Selecthard

An administrator is setting up the Cloud Identity Engine (CIE) to support user mapping and authentication for Prisma Access. Which THREE components or steps are required for a successful CIE deployment? (Choose three)

Select 3 answers
A.Configure a Directory Service connector to sync users and groups from Active Directory.
B.Configure authentication settings and map user attributes within CIE.
C.Install physical Domain Controllers inside each Prisma Access cloud node.
D.Link the Cloud Identity Engine tenant to the Prisma Access / Panorama instance.
E.Configure BGP peering between CIE and the enterprise DNS servers.
AnswersA, B, D

The directory service connector synchronizes organizational units, users, and groups into CIE.

Why this answer

CIE requires directory service integration, cloud tenant setup, and agent or sync configuration.

33
Multi-Selecthard

Which THREE items must be configured to successfully enforce HIP-based security policies for mobile users?

Select 3 answers
A.Add the HIP Profile to the Security Policy rule.
B.Enable HIP data collection on the GlobalProtect portal.
C.Create a separate GlobalProtect gateway for each security level.
D.Create HIP Objects and Profiles in the Panorama object library.
E.Install an on-premises User-ID agent.
AnswersA, B, D

The policy must be linked to the profile.

Why this answer

HIP requires the agent to be enabled, the objects to be defined, and the security policy to reference them.

34
Multi-Selecthard

An administrator needs to optimize mobile user traffic performance and reduce latency in Prisma Access. Which THREE features or configurations can be utilized to achieve this? (Choose three)

Select 3 answers
A.Configure split tunneling to route non-corporate or high-bandwidth web traffic (e.g., video streaming) directly to the internet.
B.Disable all threat inspection profiles for mobile users to bypass security processing.
C.Enable 'Closest Gateway' selection so users automatically connect to the nearest Prisma Access location.
D.Implement Quality of Service (QoS) policies to prioritize business-critical applications.
E.Route all mobile user traffic through a single centralized headquarters datacenter firewall.
AnswersA, C, D

Split tunneling prevents unnecessary backhauling of non-corporate traffic through Prisma Access nodes.

Why this answer

Traffic optimization for mobile users involves split tunneling, optimal gateway selection, and QoS.

35
MCQeasy

Which action should an administrator take to update the Prisma Access software and plugin versions across the deployment?

A.Device > Software > Prisma Access
B.Policies > Management > Updates
C.Monitor > Software Updates > Cloud
D.Panorama > Plugin > Cloud Services > Updates
AnswerD

Prisma Access plugin and cloud component updates are managed directly from the Panorama Plugin interface.

Why this answer

Panorama manages Prisma Access updates through the Software and Cloud Services plugin update mechanisms.

36
MCQmedium

A network administrator needs to restrict access for remote users to a specific SaaS application based on their device's security posture. Which configuration sequence allows this in Prisma Access?

A.Configure an App-ID override rule and assign the device certificate to the User-ID agent.
B.Enable SSL Forward Proxy and add the device serial number to the GlobalProtect portal whitelist.
C.Assign a dynamic address group to the user and create a custom URL filtering category for the SaaS app.
D.Create a HIP Object, add it to a HIP Profile, and apply it to a Security Policy rule source criteria.
AnswerD

This is the standard workflow to enforce endpoint posture in Security Policies.

Why this answer

Host Information Profile (HIP) objects must be defined, added to a HIP Object Profile, and then referenced in a Security Policy rule.

37
MCQeasy

What is the primary function of the GlobalProtect Portal in a Prisma Access deployment?

A.Terminating the IPSec tunnel from branch sites.
B.Managing Cloud Identity Engine sync.
C.Hosting the GlobalProtect agent software and gateway lists.
D.Performing deep packet inspection.
AnswerC

This is the primary function of the portal.

Why this answer

The Portal provides authentication and the configuration/software updates to the GlobalProtect agent.

38
Multi-Selectmedium

An administrator is reviewing the operational health and logs of Prisma Access. Which TWO monitoring tools or log types are available within Panorama for troubleshooting security events and traffic flows? (Choose two)

Select 2 answers
A.Traffic and Threat logs
B.Active Directory replication event logs
C.Local hypervisor resource utilization logs
D.Switch spanning-tree topology tables
E.HIP Match logs
AnswersA, E

Traffic and Threat logs record all session establishment details and security inspection verdicts.

Why this answer

Panorama provides traffic, threat, and HIP match logs alongside ACC dashboards for visibility.

39
MCQeasy

Where do administrators configure service connections in Prisma Access to connect the cloud security infrastructure to the organization's data center or headquarters?

A.Network > Interfaces > Tunnel
B.Policies > QoS > Service Connections
C.Panorama > Cloud Services > Configuration > Service Connections
D.Device > Cloud Services > GlobalProtect
AnswerC

This menu path is used to define service connections, including peer IP addresses, BGP settings, and bandwidth.

Why this answer

Service connections are configured in the Panorama Cloud Services plugin to establish secure tunnels back to corporate datacenters.

40
MCQhard

An enterprise using Prisma Access Mobile Users needs to enforce Host Information Profile (HIP) checks to ensure that endpoints have an active and updated corporate antimalware solution before granting access to internal applications. Which workflow must an administrator complete to successfully enforce this requirement?

A.Deploy a Prisma Access Service Connection to proxy endpoint security telemetry to Panorama.
B.Configure the Cloud Identity Engine to query local endpoint registries directly for antimalware signatures.
C.Enable User-ID syslog mapping to ingest antimalware status logs from third-party endpoint protection servers.
D.Create HIP Objects and HIP Profiles in Panorama, then reference those profiles in Security Policy rules.
AnswerD

Administrators must define HIP Objects to match criteria (like antimalware status), group them into HIP Profiles, and enforce them within Security Policy rules.

Why this answer

HIP data is gathered by the GlobalProtect agent, forwarded to Prisma Access, and then evaluated in Security Policy rules via HIP Objects and HIP Profiles.

41
MCQhard

A user is experiencing 'Gateway not found' errors. Which troubleshooting step is most effective for verifying if the GlobalProtect Gateway is reachable?

A.Performing an nslookup on the portal-provided gateway FQDN.
B.Verifying the IPSec tunnel status in Panorama.
C.Checking the User-ID Agent logs on-premises.
D.Restarting the Cloud Identity Engine service.
AnswerA

Verifying DNS resolution of the gateway FQDN is the first step in connectivity troubleshooting.

Why this answer

The 'nslookup' or 'ping' of the FQDN assigned to the gateway is the standard way to verify resolution and connectivity.

42
MCQmedium

An administrator is troubleshooting a HIP (Host Information Profile) check failure for mobile users. Where can the administrator view the collected HIP reports and check compliance status in real-time?

A.Monitor > Logs > HIP Matches
B.Device > Certificate Management > HIP
C.Panorama > Cloud Services > Status > HIP
D.GlobalProtect > Gateway > Agent > HIP Objects
AnswerA

The HIP Matches log displays detailed information about host information profiles reported by GlobalProtect clients.

Why this answer

HIP check data and reports for connected mobile users can be inspected via the Panorama operational commands or ACC/Monitor tabs.

43
MCQmedium

An administrator needs to configure secure access for remote networks using dynamic routing (BGP). Where are the BGP peer parameters, local AS number, and peer AS configured in Prisma Access?

A.Panorama > Cloud Services > Configuration > Remote Networks > [Select Network] > BGP
B.Objects > Remote Networks > BGP Profile
C.Network > Virtual Routers > BGP
D.Device > Setup > Routing > BGP
AnswerA

BGP peer IP, AS numbers, and routing preferences are configured directly inside each remote network's settings in the Cloud Services plugin.

Why this answer

BGP settings for remote networks are configured within the Remote Network definition in the Panorama Cloud Services plugin.

44
MCQmedium

When using Cloud Identity Engine (CIE) for authentication, which method allows for the most seamless user experience for mobile users?

A.RADIUS authentication.
B.SAML integration with a cloud identity provider.
C.LDAP without SSL.
D.Local database on the firewall.
AnswerB

SAML allows for modern auth like MFA and SSO.

Why this answer

SAML with a Cloud Identity Provider is the standard for modern identity integration in Prisma Access.

45
Multi-Selecthard

An administrator is configuring User-ID and authentication for Prisma Access using the Cloud Identity Engine (CIE). Which TWO actions must be performed to ensure successful authentication and group-based policy enforcement? (Choose two)

Select 2 answers
A.Disable all multi-factor authentication (MFA) requirements on Prisma Access portals.
B.Configure Group Mapping Settings in Panorama to retrieve user group memberships from the Cloud Identity Engine.
C.Install the GlobalProtect agent directly on all domain controller servers acting as CIE proxies.
D.Configure an Authentication Profile in Panorama that references the Cloud Identity Engine container.
E.Manually export user CSV files daily and upload them to Panorama using the CLI.
AnswersB, D

Group mapping is essential so that Security Policy rules can evaluate and enforce access based on Active Directory group membership.

Why this answer

To use CIE with Prisma Access, you must connect the directory service via the CIE agent or integration, configure the Authentication Profile in Panorama to point to CIE, and apply group mapping.

46
MCQhard

A Prisma Access administrator notices that remote network traffic destined for another remote network (branch-to-branch traffic) is being dropped or failing to establish. What is the required configuration to allow branch-to-branch traffic?

A.Configure static routes pointing to the loopback interface on every remote network gateway.
B.Enable 'Branch-to-Branch' routing under Panorama > Cloud Services > Configuration > Remote Networks and create matching security rules.
C.Enable GlobalProtect Clientless VPN on all remote network gateways.
D.Deploy dedicated external hardware firewalls at each branch location.
AnswerB

Branch-to-branch traffic requires both the routing enablement within the remote network configuration and permissive security policies.

Why this answer

By default, branch-to-branch traffic in Prisma Access must be explicitly allowed in the Prisma Access traffic steering and security policy configurations.

47
MCQhard

A Prisma Access mobile user reports that they cannot access internal resources, and the GlobalProtect app status shows 'Connected' but with an internal IP address assigned from the reserve pool. What is the most likely cause of routing failure?

A.The internal subnets are not included in the GlobalProtect Agent Split Tunneling 'Include Access Route' list.
B.The user's Active Directory password has expired in the Cloud Identity Engine.
C.The WildFire file size limit was exceeded.
D.The HIP check failed due to an outdated operating system patch.
AnswerA

If internal subnets are omitted from the include routes, the client will not tunnel traffic destined for those internal networks.

Why this answer

Split tunneling configurations or missing network includes in the GlobalProtect agent configuration prevent traffic from routing correctly to internal networks.

48
MCQhard

An administrator notices that specific applications identified via App-ID are failing decryption inspection in Prisma Access because the server uses an unsupported cipher suite. Where can the administrator adjust the SSL decryption profile to resolve handshake failures?

A.Panorama > Cloud Services > Global Settings > Decryption
B.Device > Certificate Management > SSL Policy
C.Policies > Decryption > Settings
D.Objects > Decryption > SSL Decryption Profile
AnswerD

SSL Decryption profiles define which TLS versions, cipher suites, and handling methods are applied during traffic inspection.

Why this answer

SSL Decryption profiles govern cipher suites, minimum TLS versions, and handling of unsupported options.

49
Multi-Selecteasy

Which TWO configuration steps are required to allow internet access for Remote Network users?

Select 2 answers
A.Enable Internet Access in the Remote Network configuration.
B.Install a local proxy server.
C.Assign a static IP address to every mobile device.
D.Configure an IPSec tunnel to a third-party ISP.
E.Create a Security Policy allowing the Remote Network zone to the Internet zone.
AnswersA, E

This setting is required to enable internet egress.

Why this answer

To allow internet access, the remote network needs to be configured and a security policy must permit the traffic from the remote network zone to the internet zone.

Ready to test yourself?

Try a timed practice session using only Prisma Access Administration And Operation questions.