Courseiva

CCNA Prisma Access Services Questions

55 questions · Prisma Access Services · All types, answers revealed

1
MCQhard

An administrator notices that certain mobile users connecting via Prisma Access are experiencing intermittent authentication timeouts when authenticating via SAML 2.0. Where should the administrator check to verify the Identity Provider (IdP) connectivity status and SAML assertion errors within Panorama?

A.Monitor -> Traffic -> Session End
B.Objects -> Authentication -> SAML Test
C.Monitor -> Logs -> Authentication
D.Panorama -> Cloud Services -> Health -> Infrastructure
AnswerC

The Authentication log in Panorama provides detailed records of user login attempts, SAML response parsing, and IdP communication status.

Why this answer

Prisma Access status and operational logs related to user authentication and SAML can be monitored via Panorama operational commands and SaaS / User-ID status dashboards.

2
MCQeasy

Which Prisma Access feature enables enterprises to inspect and secure traffic between different virtual networks or cloud environments connected to the cloud service?

A.CASB API scanning
B.Prisma Access Insights
C.GlobalProtect Portal
D.Firewall as a Service (FWaaS)
AnswerD

FWaaS provides cloud-delivered network security and stateful inspection for all traffic flows across Prisma Access.

Why this answer

Firewall as a Service (FWaaS) provides comprehensive Layer 7 inspection for all traffic traversing Prisma Access.

3
MCQeasy

An organization is migrating their branch offices to Prisma Access Firewall as a Service (FWaaS). What is the primary method used to connect a physical branch office location to the Prisma Access cloud infrastructure securely?

A.Direct peering via AWS Direct Connect without any encapsulation
B.GlobalProtect client software installed on every desktop in the branch
C.IPsec VPN tunnels from the branch office router or firewall to Prisma Access Remote Networks
D.Explicit HTTP proxy configuration pushed via browser group policy
AnswerC

Branch offices use standard IPsec VPN connections terminating at the nearest Prisma Access Remote Networks node to secure traffic to and from the cloud.

Why this answer

Remote Networks (RN) in Prisma Access connect physical branch offices and headquarters to the cloud service using standard IPsec VPN tunnels terminated on Prisma Access service nodes.

4
MCQeasy

When configuring Prisma Access via Panorama, which administrative role or permission is required to push configuration changes to the cloud infrastructure?

A.Panorama Administrator role with Cloud Services plugin permissions
B.Network Administrator without Cloud Services access
C.Prisma Cloud Administrator
D.GlobalProtect Read-Only Operator
AnswerA

Managing Prisma Access requires specific administrator privileges covering Panorama Cloud Services plugins and configuration push capabilities.

Why this answer

Administrators require appropriate Panorama roles with permissions to commit and push changes to Cloud Services templates and device groups.

5
MCQmedium

An administrator configuring Prisma Access ZTNA wants to view real-time metrics regarding active mobile user connections, bandwidth consumption per region, and tunnel status. Which tool provides this specific operational dashboard?

A.Prisma Access Insights
B.Panorama Traffic Logs
C.Command Line Interface (CLI) via SSH to Prisma Access nodes
D.Prisma Cloud Compute console
AnswerA

Prisma Access Insights offers visibility into active users, bandwidth usage, service uptime, and tenant metrics.

Why this answer

Prisma Access Insights provides operational dashboards for bandwidth, active users, and tenant health.

6
Multi-Selecthard

An administrator is designing a Prisma Access Secure Web Gateway (SWG) and CASB architecture. Which THREE capabilities can be enforced natively through Prisma Access SWG and inline CASB policies? (Choose three)

Select 3 answers
A.Granular action control such as allowing read-only access while blocking file uploads to sanctioned or unsanctioned SaaS tenants
B.Direct peer-to-peer BGP routing exchanges with external public web servers
C.URL filtering based on threat risk categories and web categories
D.Local BIOS firmware flashing and motherboard diagnostics for remote client laptops
E.Data Filtering to detect and block the exfiltration of sensitive data such as credit card numbers or PII
AnswersA, C, E

Inline CASB capabilities in Prisma Access allow precise activity control over SaaS applications (upload, download, share).

Why this answer

Prisma Access SWG and inline CASB allow administrators to control specific application actions (e.g., block uploads), inspect traffic using URL filtering categories, and enforce data loss prevention via Data Filtering profiles.

7
MCQeasy

Which Prisma Access service capability provides secure, least-privilege remote access for third-party contractors who cannot install the GlobalProtect agent on their managed or unmanaged devices?

A.Prisma Access Remote Network IPsec
B.Prisma Access Browser
C.Explicit Proxy Forwarding
D.GlobalProtect Client-less VPN
AnswerD

Client-less VPN allows users to securely access internal web applications directly from a standard web browser.

Why this answer

GlobalProtect Client-less VPN provides browser-based access to internal web applications without requiring an endpoint client.

8
MCQmedium

An organization requires that Prisma Access Secure Web Gateway inspects all inbound and outbound TLS traffic for employees browsing external websites. However, HR and healthcare applications must be bypassed due to privacy regulations. Where in Panorama must the administrator configure the exception for these categories?

A.Policies -> Decryption
B.Panorama -> Cloud Services -> User Access
C.Network Services -> Prisma Access -> Decryption Bypass
D.Objects -> Custom URL Category
AnswerA

Decryption policies contain rules that define which traffic to decrypt, block, or no-decrypt based on URL categories.

Why this answer

Decryption policy rules in Panorama allow administrators to bypass decryption based on URL categories such as healthcare and financial services.

9
Multi-Selectmedium

An administrator is configuring authentication for Prisma Access mobile users. Which TWO authentication methods are natively supported for GlobalProtect mobile users in Prisma Access? (Choose two)

Select 2 answers
A.Local plaintext password files stored on user endpoint hard drives
B.RADIUS and LDAP authentication servers
C.Peer-to-peer certificate exchange without an authentication authority
D.Hardcoded pre-shared keys without user credentials
E.SAML 2.0 Identity Provider integration (e.g., Okta, Microsoft Entra ID, Ping Identity)
AnswersB, E

RADIUS and LDAP profiles allow direct integration with directory services and MFA radius servers.

Why this answer

Prisma Access supports SAML 2.0 and RADIUS/LDAP authentication methods for mobile users.

10
Multi-Selecthard

An enterprise is deploying Prisma Access Service Connections to connect corporate data centers to the cloud security platform. Which THREE configuration parameters must be correctly specified on Panorama for a Service Connection? (Choose three)

Select 3 answers
A.GlobalProtect client software download URLs for mobile endpoints.
B.BGP peer AS number and peering IP addresses for dynamic route exchange.
C.WMI probing schedules for Active Directory domain discovery.
D.IPsec Crypto Profile and IKE Crypto Profile settings.
E.Peer IP address of the enterprise data center VPN gateway.
AnswersB, D, E

BGP configuration is necessary to exchange routing prefixes between the data center and Prisma Access.

Why this answer

Service Connections require defining the remote peer IP address, IPsec crypto settings, and BGP peering parameters for routing.

11
MCQhard

An administrator is troubleshooting a Prisma Access deployment where mobile users are intermittently disconnected when moving between trusted Wi-Fi networks and cellular connections. Which GlobalProtect client setting in Prisma Access helps maintain session persistence and fast reconnection during network roaming?

A.Explicit Proxy PAC file fallback mode
B.GlobalProtect App configuration with seamless tunnel reconnection and 'Always On' mode
C.BGP route dampening on the Service Connection
D.IPsec Dead Peer Detection (DPD) timer set to zero
AnswerB

Seamless tunnel reconnection allows the GlobalProtect client to re-establish secure sessions automatically when network interfaces change.

Why this answer

GlobalProtect app settings such as 'Connect Method' set to 'Always On' or 'Pre-Logon' along with seamless tunnel reconnection settings ensure persistent connections.

12
Multi-Selectmedium

An administrator is configuring Prisma Access Remote Networks to connect branch offices to the cloud security backbone. Which TWO configuration steps are required on Panorama to establish a functional Remote Network connection? (Choose two)

Select 2 answers
A.Upload customer SAML metadata files to the GlobalProtect Portal.
B.Configure IPsec Crypto Profiles and Tunnel settings for the Remote Network connection.
C.Configure the Remote Network general settings including region, bandwidth, and public IP address of the CPE device.
D.Configure WMI probing credentials for Active Directory domain controllers.
E.Install the GlobalProtect agent software on all CPE branch routers.
AnswersB, C

IPsec crypto and tunnel settings define the cryptographic parameters used to secure the tunnel to Prisma Access.

Why this answer

Configuring Remote Networks requires defining the remote network location with public IP/bandwidth and creating IPsec tunnel parameters to establish the secure connection.

13
MCQhard

An administrator is setting up Prisma Access and needs to ensure that mobile users connecting from managed corporate laptops can access internal resources, while unmanaged contractor laptops are restricted to web-based applications only. Which Prisma Access mechanism distinguishes between managed and unmanaged endpoints during connection?

A.SAML Identity Provider group claims
B.Active Directory Security Group membership only
C.GlobalProtect HIP (Host Information Profile) checks
D.Prisma Access Explicit Proxy PAC file routing
AnswerC

HIP checks inspect the endpoint for specific software, certificates, or registry keys to determine if it is a managed corporate device.

Why this answer

GlobalProtect HIP (Host Information Profile) checks evaluate the endpoint state upon connection to verify if it meets corporate security requirements.

14
Multi-Selectmedium

An administrator is configuring Prisma Access Secure Web Gateway and wants to restrict access to high-risk web categories. Which TWO options represent configurable actions within a Prisma Access URL Filtering profile? (Choose two)

Select 2 answers
A.Decrypt
B.Continue
C.Sandbox
D.Block
E.Quarantine
AnswersB, D

Continue displays a warning page allowing the user to proceed by clicking through.

Why this answer

URL Filtering profiles support multiple actions per category, including Allow, Block, Alert, Continue, and Override.

15
Multi-Selecthard

A security architect is designing a Prisma Access FWaaS deployment and needs to ensure robust security posture across all zones (Mobile Users, Remote Networks, Service Connections, and Internet). Which THREE security profile types should be attached to Security Policy rules to ensure comprehensive threat prevention? (Choose three)

Select 3 answers
A.GlobalProtect Portal Configuration Profile
B.Vulnerability Protection Security Profile
C.Antivirus Security Profile
D.Cloud Services Dynamic Template
E.WildFire Analysis Security Profile
AnswersB, C, E

Vulnerability Protection blocks known exploit attempts and protocol anomalies.

Why this answer

Comprehensive threat prevention in PAN-OS / Prisma Access relies on Antivirus, Vulnerability Protection, and WildFire Analysis profiles.

16
MCQmedium

An administrator is configuring Prisma Access Firewall as a Service (FWaaS) to protect outbound internet traffic from remote networks. They want to ensure that known command-and-control (C2) traffic and vulnerability exploits are blocked dynamically in real time. Which security profile should be applied to the security policy rules?

A.URL Filtering and Decryption profiles only
B.Data Filtering and File Blocking profiles only
C.User-ID and Device-ID mapping policies
D.Anti-Spyware and Vulnerability Protection profiles
AnswerD

Anti-Spyware profiles detect C2 traffic, and Vulnerability Protection profiles block known exploits, providing core FWaaS threat prevention.

Why this answer

Anti-Spyware and Vulnerability Protection profiles inspect traffic passing through Prisma Access FWaaS to detect and block C2 callbacks, malware downloads, and exploit attempts.

17
MCQhard

A security architect is designing a CASB inline policy in Prisma Access. The requirement is to restrict corporate users from logging into personal instances of sanctioned SaaS applications (e.g., personal Microsoft 365 or Google Workspace) while allowing access to corporate-owned tenants. Which feature enables this control?

A.Prisma Access DNS Security sinking
B.HTTP Header Insertion / Restricted Tenant Access
C.GlobalProtect Client-less VPN rewriting rules
D.SaaS Security API inline scanning
AnswerB

Prisma Access can insert specific HTTP headers (such as Restricted-Access-Current-Tenant) into outbound requests to cloud services, forcing corporate tenants only.

Why this answer

App-ID SaaS Security controls and HTTP header insertion (specifically restricted domains/tenant restriction headers) allow Prisma Access to enforce access only to approved enterprise tenants.

18
MCQmedium

An organization wants to restrict access to a sensitive internal financial database so that only users belonging to the 'Finance-Dept' Active Directory group and connecting from compliant corporate laptops can access it. Which Prisma Access security feature combines user identity, device posture, and application access control?

A.URL Filtering Custom Categories
B.Zone Protection profiles
C.HIP (Host Information Profile) matching in Security Policies
D.CASB Inline Policy Rules
AnswerC

HIP profiles collect endpoint security state (antivirus, disk encryption, OS patch level) and are referenced in Security policy rules to grant or deny access.

Why this answer

Prisma Access ZTNA policy enforcement leverages User-ID, HIP (Host Information Profile) checks, and App-ID to enforce least-privilege access.

19
MCQmedium

A security engineer is configuring a Prisma Access Remote Network location with redundant IPsec tunnels to ensure high availability. What configuration requirement must be met on the customer premise equipment (CPE) router to support dynamic routing over these redundant tunnels?

A.Static floating routes with identical metrics must be used.
B.BGP peering must be established across both tunnels with the Prisma Access service node.
C.OSPF area 0 must be configured on the CPE interface.
D.GRE encapsulation must wrap the IPsec packets.
AnswerB

Dynamic routing with BGP over IPsec enables automatic failover between redundant tunnels.

Why this answer

BGP peering must be configured over both IPsec tunnels, with appropriate path metrics or AS path prepending to manage active/backup or active/active flow.

20
MCQeasy

Which log category in Prisma Access records events when a user's host information profile (HIP) changes or fails a compliance check?

A.System log
B.HIP Match log
C.Configuration log
D.User-ID log
AnswerB

HIP Match logs store records of endpoint evaluations against defined Host Information Profiles.

Why this answer

HIP Match logs record endpoint compliance evaluation results.

21
MCQeasy

An enterprise wants to implement Firewall as a Service (FWaaS) using Prisma Access to protect inter-branch traffic and internet traffic. Which Panorama template type is primarily used to push network and device configurations to Prisma Access nodes?

A.Stack templates
B.Prisma Access Global templates
C.Cloud Services templates
D.Mobile User dynamic templates
AnswerC

Cloud Services templates are specifically designed to configure Prisma Access Remote Networks, Mobile Users, and Service Connections.

Why this answer

Panorama uses Cloud Services templates to manage network, interface, and routing settings for Prisma Access locations.

22
Multi-Selectmedium

An administrator needs to configure Prisma Access ZTNA to verify endpoint hygiene before granting access to internal applications. Which TWO posture checks can be evaluated using GlobalProtect Host Information Profiles (HIP)? (Choose two)

Select 2 answers
A.Active Directory group membership hierarchy
B.BGP route advertisement metrics
C.Antivirus presence and definition update status
D.SAML Identity Provider multi-factor authentication token validity
E.Disk encryption status (e.g., FileVault or BitLocker enabled)
AnswersC, E

HIP profiles verify that antivirus software is installed, running, and up to date.

Why this answer

HIP profiles evaluate endpoint security parameters including disk encryption status, antivirus installation, OS patch levels, and software inventory.

23
MCQhard

A deployment of Prisma Access requires ZTNA 2.0 posture check enforcement for remote users. The administrator must ensure that mobile devices attempting to connect to internal corporate apps are evaluated for disk encryption and active endpoint protection agents prior to tunnel establishment. Which component performs this real-time device posture assessment?

A.Remote Networks (RN) node
B.GlobalProtect app using Host Information Profile (HIP) reporting
C.Cloud Secure Web Gateway (SWG) explicit proxy listener
D.Cloud Managed Services (CMS) collector
AnswerB

The GlobalProtect app gathers host information (HIP data) such as disk encryption and antivirus status, reporting it to Prisma Access to dynamically enforce access controls.

Why this answer

Prisma Access integrates with Cortex XDR and Prisma Access Browser/GlobalProtect app to perform device posture checks via Host Information Profile (HIP) matching. HIP checks evaluate the security posture of the endpoint and feed directly into Security Policy rules enforcing ZTNA.

24
MCQeasy

Which component of Prisma Access is responsible for providing centralized management, monitoring, and reporting for all SWG, ZTNA, CASB, and FWaaS features?

A.Panorama
B.Prisma Access Insights
C.GlobalProtect App
D.Prisma Cloud
AnswerA

Panorama provides a single pane of glass to configure, manage, and view logs for all Prisma Access components.

Why this answer

Panorama is the centralized management and logging platform for Prisma Access.

25
Multi-Selecthard

An organization is deploying Prisma Access CASB and Secure Web Gateway features. Which THREE capabilities are provided by Prisma Access Inline CASB compared to out-of-band SaaS Security API? (Choose three)

Select 3 answers
A.Deep historical scanning of files at rest stored within cloud SaaS storage repositories.
B.Out-of-band remediation of externally shared links via API webhooks.
C.Real-time blocking of unauthorized data uploads to sanctioned and unsanctioned cloud applications.
D.Enforcement of tenant restriction headers (HTTP header insertion) for enterprise cloud apps.
E.Immediate prevention of malware downloads from cloud storage platforms during user browsing.
AnswersC, D, E

Inline CASB blocks traffic as it passes through the proxy/firewall engine in real time.

Why this answer

Inline CASB inspects traffic in real time, blocks unauthorized uploads/downloads immediately, and enforces tenant restriction headers.

26
MCQhard

A Prisma Access administrator needs to implement ZTNA 2.0 continuous trust verification for mobile users accessing internal private applications. Which feature ensures that continuous validation of both user identity and device posture occurs throughout the session, rather than only at initial authentication?

A.Continuous Trust Verification via periodic Host Information Profile (HIP) re-evaluation and app-connector telemetry
B.Pre-logon GlobalProtect connection mode
C.Explicit proxy PAC file auto-discovery
D.RADIUS single sign-on (SSO) integration with Multi-Factor Authentication
AnswerA

ZTNA 2.0 continuously verifies trust by periodically re-evaluating HIP reports and monitoring application behavior to revoke access immediately if risk increases.

Why this answer

ZTNA 2.0 in Prisma Access enforces continuous trust verification by re-evaluating device posture (HIP checks) and user context periodically during active sessions, cutting off access if conditions change.

27
MCQhard

A security engineer is troubleshooting a ZTNA connection issue where remote users running GlobalProtect are unable to reach internal applications hosted behind a Prisma Access Remote Network. The mobile users and remote networks are in the same region, but direct branch-to-branch routing is failing. Which Prisma Access feature must be verified to ensure direct traffic flow between mobile users and remote networks without backhauling to the cloud service nodes?

A.Explicit Proxy PAC file redirect
B.Prisma Access Insights Regional Peering
C.Mobile User to Remote Network direct routing
D.Clean Pipe architecture
AnswerC

This feature allows sessions between mobile users and remote networks to bypass unnecessary cloud node processing when co-located in the same region.

Why this answer

Prisma Access supports Mobile User to Remote Network (MU-to-RN) direct traffic routing, which allows traffic to flow between mobile users and remote networks directly when both are connected to the same service node location.

28
MCQmedium

A security analyst is investigating a Prisma Access FWaaS alert indicating a brute-force attack against an internal server published via a Service Connection. Which security profile should be tuned to detect and block this network-layer attack signature?

A.Vulnerability Protection Profile
B.Antivirus Profile
C.Data Filtering Profile
D.URL Filtering Profile
AnswerA

Vulnerability Protection profiles detect and prevent network exploitation attempts, including brute-force attacks and buffer overflows.

Why this answer

Vulnerability Protection profiles inspect network traffic for known exploit signatures, including brute-force attempts and protocol anomalies.

29
MCQmedium

An administrator is configuring Prisma Access Secure Web Gateway and wants to ensure that newly registered malicious domains are blocked automatically without waiting for manual signature updates. Which Palo Alto Networks security service provides real-time IP and domain threat intelligence to Prisma Access?

A.Prisma Access Insights
B.DNS Security
C.SaaS Security API
D.GlobalProtect Cloud Service Agent
AnswerB

DNS Security uses machine learning and predictive analytics to block newly registered domains (NRDs) and command-and-control (C2) domains in real time.

Why this answer

WildFire and DNS Security provide real-time threat intelligence and automated threat prevention across Prisma Access.

30
Multi-Selectmedium

An administrator is troubleshooting ZTNA connectivity issues for mobile users connecting via Prisma Access. Which TWO tools or log types in Panorama should the administrator check to diagnose user authentication and tunnel establishment problems? (Choose two)

Select 2 answers
A.WildFire submission log
B.System log
C.HIP Match log
D.Data Filtering log
E.Authentication log
AnswersB, E

System logs record daemon events, GlobalProtect gateway connection statuses, and service health messages.

Why this answer

System logs and Authentication logs provide visibility into mobile user login events, GlobalProtect connection handshakes, and SAML/LDAP authentication results.

31
MCQeasy

An enterprise requires their mobile users to use a Secure Web Gateway (SWG) service that intercepts all web traffic without requiring explicit browser proxy configurations on each client machine. Which Prisma Access deployment method meets this requirement transparently?

A.GlobalProtect client in transparent tunnel mode forwarding traffic to Prisma Access SWG
B.GRE tunnel forwarding from local ISP routers
C.Static NAT configuration on the branch office gateway
D.GlobalProtect client in explicit proxy mode
AnswerA

Transparent forwarding via the GlobalProtect client routes all traffic securely to Prisma Access SWG without requiring client-side proxy settings.

Why this answer

Prisma Access transparently intercepts web traffic from mobile users via the GlobalProtect app operating in layer-3 tunnel mode, eliminating the need for PAC files or manual proxy settings.

32
Multi-Selecthard

An enterprise is integrating Prisma Access with their corporate infrastructure. Which THREE components can be connected to Prisma Access to provide centralized cloud security inspection? (Choose three)

Select 3 answers
A.Service Connections (corporate data centers or headquarters)
B.Local standalone firewalls operating in hardware bypass mode without cloud connection
C.Public cloud VPCs directly via automated cloud connectors without IPsec or BGP
D.Remote Networks (branch offices via IPsec VPN)
E.Mobile Users running the GlobalProtect app
AnswersA, D, E

Service Connections link Prisma Access back to corporate data centers and internal resources.

Why this answer

Prisma Access connects Mobile Users, Remote Networks (branch offices), and Service Connections (data centers/HQ).

33
MCQhard

A network administrator needs to verify that the QoS (Quality of Service) settings applied to Prisma Access mobile users are prioritizing real-time voice and video traffic correctly. Where are QoS profiles applied in the Prisma Access configuration hierarchy in Panorama?

A.Objects -> QoS Profiles -> Global
B.Panorama -> Cloud Services -> Configuration -> QoS Policy
C.GlobalProtect Portal -> Client Settings -> QoS
D.Network -> Interfaces -> Tunnel -> QoS
AnswerB

QoS policies and profiles for Prisma Access are managed under the Cloud Services configuration workflow in Panorama.

Why this answer

QoS profiles in Prisma Access are applied within the QoS policy rules and associated with the Cloud Services mobile user or remote network configuration to prioritize traffic classes.

34
Multi-Selectmedium

An administrator is configuring Prisma Access SWG and needs to implement granular control over file sharing and collaboration tools. Which TWO SaaS Security features can be configured in Prisma Access to achieve this? (Choose two)

Select 2 answers
A.IPsec crypto profile selection for branch offices
B.Shadow IT discovery and risk scoring of unapproved cloud applications
C.GlobalProtect client software version deployment rules
D.SaaS application activity controls to restrict specific actions like sharing files externally
E.WMI-based user mapping polling intervals
AnswersB, D

Prisma Access discovers unauthorized cloud apps and rates their risk based on security criteria.

Why this answer

Prisma Access CASB allows administrators to discover shadow IT, control tenant access, and inspect file activities.

35
Multi-Selecthard

A security engineer is troubleshooting traffic inspection issues in Prisma Access FWaaS. Traffic between two mobile users is bypassing security policy inspection. Which THREE factors could cause intra-zone or inter-user traffic to bypass security inspection in Prisma Access? (Choose three)

Select 3 answers
A.Security policy rules configured with the 'App-Override' or custom bypass settings for specific applications.
B.GlobalProtect portal banner message customization.
C.An explicit Decryption rule configured with 'No Decrypt' action for sensitive categories.
D.Client split-tunneling configured to send specific traffic directly to the local internet rather than through Prisma Access.
E.Panorama template commit pending status on Remote Networks.
AnswersA, C, D

App-Override rules bypass deep packet inspection and signature analysis for matching traffic.

Why this answer

Traffic bypassing inspection can be caused by explicit decryption bypass rules, clientless or split-tunnel configurations, or specific application bypass features.

36
MCQmedium

An enterprise wants to ensure that all internet-bound traffic from mobile users is decrypted and inspected for malware and sensitive data using Prisma Access SWG. Which GlobalProtect client traffic forwarding configuration ensures that all traffic is sent to Prisma Access?

A.Explicit Proxy local bypass mode
B.Split Tunnel mode based on destination subnets
C.Client-less Portal mode
D.Tunnel All Traffic mode
AnswerD

Tunnel All Traffic mode routes all client internet and corporate traffic through Prisma Access for complete SWG inspection.

Why this answer

Tunnel all traffic mode routes all client traffic through the secure GlobalProtect tunnel to Prisma Access.

37
MCQeasy

Which log type in Prisma Access should an administrator examine to review details about blocked URLs, category ratings, and user web-browsing attempts?

A.Threat log
B.Data Filtering log
C.HIP Match log
D.URL Filtering log
AnswerD

URL Filtering logs capture every web transaction, matched category, and allow/block action.

Why this answer

URL Filtering logs record all web traffic processed by SWG URL filtering rules.

38
MCQeasy

When designing a Prisma Access deployment for remote workers, which component authenticates the user and assigns the appropriate GlobalProtect gateway connection based on geographic location?

A.Service Connection
B.GlobalProtect Portal
C.GlobalProtect Gateway
D.Remote Network
AnswerB

The Portal provides configuration updates and directs the client to the closest or best performing Gateway.

Why this answer

The GlobalProtect Portal handles user authentication, client software updates, and assigns the optimal GlobalProtect Gateway.

39
MCQmedium

An administrator notices that certain SaaS applications are not being accurately identified or controlled by Prisma Access CASB inline policies due to domain fronting and complex URL structures. Which feature should the administrator configure in Prisma Access to ensure deep application identification and decryption of this traffic?

A.Quality of Service (QoS) profile for SaaS acceleration
B.User-ID agent mapping via LDAP integration
C.DNS Security with external recursive resolver redirection
D.SSL Decryption policy with a Forward Trust certificate
AnswerD

SSL Decryption is required for Prisma Access to inspect HTTPS traffic, identify specific SaaS applications, and enforce inline CASB controls.

Why this answer

Inbound and outbound SSL/TLS Decryption is critical for Prisma Access SWG and CASB to inspect application payloads, read SNI, and apply granular control over cloud applications.

40
MCQhard

An enterprise is deploying Prisma Access and wants to ensure that user identity mapping is gathered efficiently from Microsoft Entra ID (formerly Azure AD) without deploying physical User-ID agents inside the cloud network. Which integration method should be used?

A.WMI probing from Prisma Access nodes
B.GlobalProtect client registry polling
C.Cloud Identity Engine (CIE)
D.Syslog server parsing via Service Connection
AnswerC

The Cloud Identity Engine securely synchronizes identity and group information from cloud directories like Microsoft Entra ID to Prisma Access.

Why this answer

Prisma Access supports User-ID integration with Azure AD via the Cloud Identity Engine (CIE) or direct cloud-based User-ID agentless polling.

41
MCQhard

A company requires that Prisma Access FWaaS inspects all inter-zone traffic between two different remote branch offices connected via Prisma Access. By default, how does Prisma Access handle traffic between two Remote Networks attached to the same service region?

A.Traffic must be backhauled to the corporate data center via a Service Connection before reaching another branch.
B.Traffic between Remote Networks is dropped by default unless explicitly allowed by security policy and inter-branch routing is enabled.
C.Remote Networks cannot communicate with each other under any circumstance.
D.Traffic is automatically bypassed and sent directly over public internet.
AnswerB

Inter-branch traffic requires explicit configuration in the Remote Networks settings and matching security policies to allow communication.

Why this answer

Prisma Access supports inter-branch routing, allowing traffic between remote networks to be inspected by security policies when inter-branch traffic is enabled.

42
MCQhard

An enterprise using Prisma Access has configured a Service Connection to their primary data center. Users at remote branches report that they cannot reach internal applications hosted in the data center. Upon checking Panorama, the Service Connection status shows 'Connected', but routing is failing. What configuration step is required on Prisma Access to advertise the remote network subnets to the data center?

A.Configure BGP peer settings and export rules on the Service Connection in Panorama.
B.Enable SSL Decryption on the Service Connection interface.
C.Create a GlobalProtect Portal authentication profile for the data center.
D.Configure Zone Protection profiles on the tunnel interface.
AnswerA

BGP must be properly configured on the Service Connection so Prisma Access and the data center exchange routes dynamically.

Why this answer

Service Connections require BGP peering configuration to exchange routing information between Prisma Access and the enterprise data center router.

43
MCQhard

An organization requires that all DNS queries from Prisma Access mobile users be inspected and filtered for malicious domains before resolving. Where in Panorama is Prisma Access DNS Security configured?

A.Objects -> Security Profiles -> DNS Security
B.Policies -> NAT
C.Panorama -> Cloud Services -> GlobalProtect -> DNS
D.Network Services -> DNS Proxy
AnswerA

DNS Security profiles are created under Objects -> Security Profiles and enforced via Security policy rules.

Why this answer

DNS Security profiles are attached to Security Policy rules in Panorama to inspect and take action on DNS requests.

44
Multi-Selectmedium

When configuring Prisma Access for ZTNA 2.0 to control access to private applications, which TWO components or configurations are mandatory for establishing least-privileged application access? (Choose two)

Select 2 answers
A.Legacy PPTP VPN dial-in server integration
B.Explicit PAC files distributed to all internal users
C.Public IP addresses assigned to every internal workstation
D.App-ID based security policies that explicitly name specific internal applications rather than subnets
E.Prisma Access App Connectors deployed in the internal network hosting private applications
AnswersD, E

ZTNA 2.0 replaces implicit trust with precise application control using App-ID, ensuring users access only authorized apps rather than entire network segments.

Why this answer

ZTNA 2.0 requires app-level segmentation instead of network-level access, meaning App-ID based security policies and Prisma Access App Connectors deployed in the private data center are mandatory.

45
MCQeasy

Which security feature in Prisma Access SWG inspects downloaded executable files and documents against a cloud-based behavioral sandbox to identify zero-day malware?

A.Data Filtering
B.URL Filtering
C.Antivirus Profile
D.WildFire
AnswerD

WildFire automatically analyzes unknown files in a sandbox environment to detect zero-day threats.

Why this answer

WildFire is Palo Alto Networks cloud-based malware analysis and sandbox engine.

46
MCQmedium

A network engineer is configuring a Service Connection in Prisma Access to connect the cloud security infrastructure back to the corporate data center. Which routing protocol is supported natively by Prisma Access to dynamically exchange routes over the IPsec VPN tunnel?

A.BGP
B.EIGRP
C.RIPv2
D.OSPF
AnswerA

BGP is the industry standard dynamic routing protocol supported across Prisma Access IPsec connections.

Why this answer

Prisma Access supports BGP (Border Gateway Protocol) over IPsec for dynamic routing on Service Connections and Remote Networks.

47
MCQmedium

An organization is deploying Prisma Access for mobile users and needs to ensure that users in Europe connect to European cloud nodes while users in North America connect to North American nodes. How does Prisma Access automatically achieve this geographic routing?

A.Active Directory site-to-site replication
B.Explicit Proxy PAC file geographic strings
C.Manual IP routing configuration on each user laptop
D.GlobalProtect cloud DNS resolution and regional gateway priority settings
AnswerD

GlobalProtect resolves connection requests to the nearest regional cloud service location automatically.

Why this answer

GlobalProtect cloud service uses a worldwide DNS infrastructure and cloud routing mechanism to direct client connection requests to the nearest geographic node.

48
Multi-Selectmedium

An administrator wants to ensure high availability and resilient connectivity for mobile users connecting to Prisma Access. Which TWO features or mechanisms are utilized by Prisma Access to ensure reliable mobile user access? (Choose two)

Select 2 answers
A.Static routing tables configured locally on Windows and macOS registry settings
B.Cloud-scale redundant gateway architecture across multiple geographic locations
C.Manual IPsec tunnel failover scripting executed on each endpoint device
D.On-premise physical hardware load balancers deployed in front of mobile user tunnels
E.Automatic gateway selection directing clients to the best performing regional service node
AnswersB, E

Prisma Access runs redundant nodes in every deployed region to ensure service uptime.

Why this answer

Prisma Access provides mobile user high availability via automated gateway selection, regional redundancy, and client reconnect capabilities.

49
MCQmedium

An administrator needs to configure Prisma Access Remote Networks to route specific corporate traffic to a local data center while sending internet-bound traffic directly through Prisma Access. Which configuration component in Panorama is used to define this split-tunneling behavior?

A.Traffic Distribution profile
B.GlobalProtect Client-less VPN portal settings
C.Decryption Policy rules
D.Subnets included in the Remote Network definition
AnswerD

Administrators define exact subnets that should be routed via Prisma Access in the Remote Network configuration, effectively enabling split tunneling.

Why this answer

In Prisma Access Remote Networks, split tunneling is controlled via the Traffic Distribution profile or explicit static routes configured under Network Services -> Prisma Access -> Remote Networks.

50
Multi-Selecthard

An enterprise is planning a Prisma Access deployment and wants to optimize performance and redundancy for Remote Networks. Which THREE best practices should the network architect follow when designing IPsec connections to Prisma Access? (Choose three)

Select 3 answers
A.Disable Dead Peer Detection (DPD) to keep tunnels permanently active.
B.Configure redundant IPsec tunnels from separate CPE devices or diverse ISP connections to Prisma Access.
C.Configure MSS clamping on the CPE routers to prevent fragmentation over IPsec tunnels.
D.Use OSPF area 0 across all IPsec tunnels to establish fast convergence.
E.Implement BGP dynamic routing over the IPsec tunnels for automated failover.
AnswersB, C, E

Redundant tunnels ensure high availability in case of ISP or CPE failure.

Why this answer

Best practices for Remote Networks include configuring redundant tunnels, enabling BGP for dynamic routing, and selecting appropriate MTU/MSS settings.

51
Multi-Selecthard

An administrator is troubleshooting a connectivity issue where remote mobile users cannot reach internal private applications via Prisma Access ZTNA. Which THREE diagnostic steps or verification checks should the administrator perform? (Choose three)

Select 3 answers
A.Verify that the GlobalProtect app on the user endpoint has successfully established a secure tunnel and updated its Host Information Profile (HIP)
B.Check the status of the Prisma Access App Connectors in the management plane to ensure they are connected and healthy
C.Reboot the physical public cloud provider datacenter hypervisor hosting the tenant
D.Review the Prisma Access Traffic and Threat logs to confirm whether security policy rules are dropping or allowing the application traffic
E.Reconfigure the local ISP router's BGP autonomous system number to match the Prisma Access gateway
AnswersA, B, D

If the GlobalProtect tunnel is down or HIP checks fail, the user will be blocked from accessing ZTNA private applications.

Why this answer

Troubleshooting Prisma Access ZTNA connectivity involves verifying the GlobalProtect connection status and HIP report, ensuring the Prisma Access App Connector is online and reachable, and checking the Security Policy rules for App-ID blocks.

52
MCQmedium

An administrator is troubleshooting a CASB inline policy where a specific file upload to an unapproved SaaS application was not blocked. Upon checking the Security policy, the rule has the correct application identified. What is the most likely reason the inline action failed to trigger?

A.The GlobalProtect agent version is outdated.
B.The User-ID agent is offline.
C.SSL Decryption is disabled for the traffic flow.
D.SaaS Security API sync interval needs to be refreshed.
AnswerC

Without SSL Decryption, Prisma Access cannot inspect HTTP headers or payload contents to enforce inline CASB restrictions.

Why this answer

Inline CASB controls in Prisma Access require SSL Decryption to be enabled because SaaS traffic is encrypted via HTTPS.

53
Multi-Selecthard

An administrator is setting up Prisma Access logging and monitoring. Which THREE logs or reporting features in Panorama provide insights into SWG, ZTNA, and CASB activities? (Choose three)

Select 3 answers
A.Threat logs for malware, spyware, and vulnerability exploit detections.
B.Hardware environmental temperature and power supply status logs.
C.Data Filtering logs for sensitive data exfiltration attempts.
D.URL Filtering logs for web category access and SWG policy enforcement.
E.CLI debug logs from physical core router interfaces.
AnswersA, C, D

Threat logs record security violations detected by FWaaS and SWG security profiles.

Why this answer

Panorama provides specialized logs for URLs, threats, traffic, and SaaS activities to monitor SSE domains.

54
MCQeasy

An administrator wants to deploy Secure Web Gateway (SWG) capabilities in Prisma Access to prevent users from uploading company proprietary data to unauthorized cloud storage applications. Which Prisma Access profile type should be applied to the Security Policy rules to achieve this?

A.Zone Protection profile
B.Antivirus profile
C.Data Filtering profile
D.URL Filtering profile
AnswerC

Data Filtering profiles inspect content for patterns such as credit cards, SSNs, or custom data patterns to block unauthorized uploads.

Why this answer

Data Filtering profiles inspect outgoing traffic for specific patterns, file types, and sensitive data to prevent data exfiltration in SWG deployments.

55
MCQmedium

An administrator wants to configure Prisma Access Secure Web Gateway to block access to sites categorized as 'Gambling' during working hours, but allow them during lunch breaks. Which Panorama feature enables time-based policy enforcement?

A.Prisma Access Insights time-window filters
B.URL Filtering custom time-out profiles
C.Schedule Objects applied to Security Policy rules
D.GlobalProtect Portal connection timers
AnswerC

Schedule objects allow administrators to define specific time windows when a security policy rule is active.

Why this answer

Schedule objects in Panorama can be applied to Security Policy rules to enforce rules only during specified days and times.

Ready to test yourself?

Try a timed practice session using only Prisma Access Services questions.