Courseiva

CCNA Prisma Access Planning And Deployment Questions

23 questions · Prisma Access Planning And Deployment topic · All types, answers revealed

1
MCQeasy

Which administrative role or tool is primarily used to monitor the status, health, and aggregate traffic statistics of a Prisma Access deployment across all regions?

A.Prisma Cloud Compute Console
B.Prisma Access Insights
C.WildFire portal
D.Cortex XDR incident management console
AnswerB

Prisma Access Insights provides visibility into service health, bandwidth usage, and deployment status.

Why this answer

Prisma Access Insights is the cloud-managed dashboard used to monitor health, status, and analytics of the Prisma Access deployment.

2
MCQmedium

An enterprise requires mobile users connecting via Prisma Access to authenticate using an external SAML 2.0 Identity Provider (IdP) such as Okta or Azure AD. Where is this authentication profile referenced in Panorama for mobile users?

A.In the Panorama Log Forwarding profile
B.In the Prisma Access Remote Network BGP peer settings
C.In the Service Connection QoS profile
D.In the GlobalProtect Portal configuration under Authentication
AnswerD

GlobalProtect Portal handles user authentication via SAML authentication profiles.

Why this answer

SAML authentication for mobile users is configured and referenced within the GlobalProtect Portal external authentication settings.

3
Multi-Selecthard

An enterprise is implementing Prisma Access and wants to ensure strict security governance. Which THREE capabilities are provided natively by Prisma Access security processing nodes (SPNs)? (Choose three)

Select 3 answers
A.URL Filtering with real-time category lookups
B.WildFire cloud-based malware analysis
C.Local enterprise data center physical power failover management
D.Threat Prevention (IPS, Anti-Spyware, and Antivirus)
E.Physical rack-and-stack server hardware maintenance by the customer
AnswersA, B, D

URL Filtering inspects web traffic across all mobile users and remote networks.

Why this answer

Prisma Access provides comprehensive cloud-delivered security services including Threat Prevention, URL Filtering, and WildFire malware analysis natively on SPNs.

4
Multi-Selecthard

An architect is designing a high-availability Remote Network location for Prisma Access. Which TWO methods can be used to ensure redundancy for branch office traffic connecting to Prisma Access? (Choose two)

Select 2 answers
A.Deploy dual branch routers establishing independent IPSec tunnels to Prisma Access
B.Enable VRRP directly across the Prisma Access cloud gateway public IP addresses
C.Configure redundant IPSec tunnels terminating on separate Prisma Access SPNs with BGP path selection
D.Configure Spanning Tree Protocol (STP) across the IPSec tunnel interfaces
E.Use L2TPv3 link aggregation across the cloud service edge
AnswersA, C

Dual branch routers provide hardware-level redundancy at the branch site.

Why this answer

Branch office redundancy in Prisma Access can be achieved by deploying redundant IPSec tunnels from the branch router to Prisma Access and utilizing BGP path selection, or by deploying redundant branch hardware devices.

5
MCQeasy

When planning a Prisma Access deployment for Mobile Users, which IP address allocation method is recommended and most commonly used for assigning virtual IP addresses to GlobalProtect clients?

A.Static IP assignment per user via Active Directory attributes
B.Static IP assignment via local DHCP server in each branch office
C.Manual entry by users upon connection
D.Automatic IP address allocation managed by Prisma Access
AnswerD

Prisma Access automatically assigns IP addresses from its managed pool to GlobalProtect clients.

Why this answer

Prisma Access automatically manages and allocates dynamic IP pools for mobile users via Panorama.

6
Multi-Selectmedium

An administrator is configuring Source NAT (SNAT) for Prisma Access Remote Networks. Which TWO reasons explain why SNAT is necessary in certain network designs? (Choose two)

Select 2 answers
A.To authenticate GlobalProtect users against Active Directory
B.To resolve overlapping IP address spaces between multiple branch offices
C.To replace the requirement for BGP routing over Service Connections
D.To present a consistent source IP address when branch traffic exits to external SaaS applications
E.To assign dynamic IPv6 addresses to individual remote worker laptops
AnswersB, D

SNAT translates overlapping private subnets to unique allocated IP pools.

Why this answer

SNAT is used to prevent IP address overlapping between branch sites and to hide internal network structures when accessing external destinations.

7
Multi-Selectmedium

When configuring GlobalProtect mobile users in Prisma Access, which THREE settings are typically defined within the GlobalProtect Client Settings configuration? (Choose three)

Select 3 answers
A.Connect method (e.g., On-Demand, Always-On)
B.GlobalProtect Gateway preference list
C.Prisma Access Remote Network BGP ASN
D.Internal DNS server IP addresses
E.Service Connection public gateway IP address
AnswersA, B, D

The connection method is configured within the client settings.

Why this answer

GlobalProtect Client Settings define client behavior such as internal DNS servers, gateway preferences, and connection modes.

8
MCQeasy

Which cloud infrastructure providers host the backend Security Processing Nodes (SPNs) used by Prisma Access?

A.Oracle Cloud Infrastructure (OCI) and IBM Cloud
B.Microsoft Azure only
C.AWS and Google Cloud Platform (GCP)
D.On-premises enterprise datacenters exclusively
AnswerC

Prisma Access leverages AWS and GCP to provide global scale and low latency.

Why this answer

Prisma Access is built on leading hyper-scaler cloud infrastructure, specifically AWS and Google Cloud Platform (GCP).

9
MCQhard

An enterprise is planning a Prisma Access Remote Networks deployment with overlapping RFC 1918 IP address spaces across several acquired branch offices. Which Prisma Access feature must the architect implement to successfully route traffic without changing the local branch IP schemes?

A.Destination NAT rules on the Service Connections
B.GRE tunneling with static default routes
C.Source NAT (SNAT) configured for Remote Networks traffic
D.BGP AS-Path Prepending across all branch tunnels
AnswerC

Source NAT allows Prisma Access to translate overlapping local branch IPs to non-overlapping allocated IP pools.

Why this answer

Source NAT (SNAT) or Network Address Translation mechanisms must be used to handle overlapping IP spaces when connecting multiple remote networks to Prisma Access.

10
Multi-Selectmedium

An administrator is planning a Prisma Access deployment and needs to configure Service Connections to connect the enterprise data center to the cloud. Which TWO requirements must be met for a successful BGP peering session over a Service Connection? (Choose two)

Select 2 answers
A.Deploy a physical hardware firewall inside the AWS cloud VPC
B.Configure LACP active-active bonding on the Service Connection tunnel interfaces
C.Ensure the advertised BGP routes do not overlap with Prisma Access internal reserved subnets
D.Enable static default routing without configuring any routing protocols
E.Configure a unique Local ASN on the Panorama Service Connection settings
AnswersC, E

Overlapping routes with internal Prisma Access subnets will cause routing failures.

Why this answer

Service Connections require a valid BGP Autonomous System Number (ASN) and proper IP subnet addressing that does not conflict with Prisma Access reserved ranges.

11
MCQmedium

An administrator needs to configure secure connectivity between a corporate data center and Prisma Access for headquarters-bound traffic. Which type of connection object should be created in Panorama?

A.Prisma SD-WAN Hub Integration
B.GlobalProtect Gateway Connection
C.Remote Network Connection
D.Service Connection
AnswerD

Service Connections connect enterprise datacenters and headquarters to Prisma Access.

Why this answer

A Service Connection is used to connect enterprise headquarters or data centers to Prisma Access.

12
MCQeasy

During the initial deployment of Prisma Access for remote networks, an administrator needs to define the bandwidth allocation for a specific compute location. Which tool is used to manage and push this bandwidth allocation?

A.Panorama
B.Prisma SD-WAN Cloud Controller
C.Prisma Access Plugin for AWS Console
D.GlobalProtect Portal standalone web GUI
AnswerA

Panorama provides the centralized interface to configure Prisma Access locations and bandwidth.

Why this answer

Panorama is the centralized management tool used to configure and push Prisma Access settings, including bandwidth allocation for remote networks and mobile users.

13
MCQhard

An architect is designing a Prisma Access deployment where branch offices require high availability using redundant IPSec VPN tunnels to Prisma Access Remote Networks. How does Prisma Access handle active-active redundant tunnels from a single branch router?

A.By utilizing VRRP across the cloud public IP addresses
B.By establishing multiple tunnels terminating on separate SPNs and using BGP multi-path or local preference for failover
C.By enabling Spanning Tree Protocol (STP) over the IPsec tunnel interfaces
D.By configuring LACP bonding directly across the cloud IPSec endpoints
AnswerB

Redundant tunnels terminate on Prisma Access nodes and rely on BGP metrics for active-active or active-passive behavior.

Why this answer

Prisma Access supports redundant IPSec tunnels from branch routers, utilizing BGP to manage path selection and failover between the tunnels.

14
MCQhard

An architect is sizing a Prisma Access Remote Network location that experiences heavy video streaming traffic. Which factor is most critical when determining the required bandwidth license for this location?

A.The peak aggregate throughput of all users at the branch location
B.The total number of IP addresses in the branch local DHCP scope
C.The number of active BGP peers configured on the branch router
D.The maximum transmission unit (MTU) size configured on the IPSec tunnel
AnswerA

Bandwidth provisioning in Prisma Access is based on peak aggregate throughput requirements.

Why this answer

Remote Network bandwidth must be provisioned based on the peak aggregate throughput expected from all users behind the branch router.

15
MCQeasy

When deploying Prisma Access, which component acts as the central management plane to push security policies, configurations, and software updates to all cloud-managed SPNs?

A.Panorama
B.GlobalProtect Portal
C.AWS Transit Gateway Manager
D.Prisma Access Cloud Controller
AnswerA

Panorama is the centralized management platform for Prisma Access.

Why this answer

Panorama acts as the central management plane for Prisma Access.

16
MCQmedium

An organization requires traffic from remote users to specific SaaS applications to bypass the Prisma Access cloud security processing nodes and go directly to the internet. Which feature should the administrator configure?

A.Explicit Proxy PAC file routing
B.SD-WAN Traffic Steering Policies
C.GlobalProtect Split Tunneling based on Access Routes and Domains
D.SSL Decryption Exclusion Objects
AnswerC

Split tunneling configuration allows specific traffic domains to bypass the GlobalProtect tunnel.

Why this answer

Prisma Access allows Split Tunneling based on domains or destinations so that specific traffic (like video streaming or trusted SaaS) bypasses the VPN tunnel.

17
Multi-Selecthard

An engineer is troubleshooting a routing issue where a remote network branch connected to Prisma Access cannot reach another remote network branch (branch-to-branch routing). Which THREE configuration items must be verified to ensure successful branch-to-branch traffic flow? (Choose three)

Select 3 answers
A.Verify that local branch DHCP lease times are set to 8 hours
B.Verify that Security Policy rules permit traffic between the respective branch zones
C.Confirm that branch routers are advertising their local subnets via BGP to Prisma Access
D.Check that all mobile user clients have disabled split tunneling
E.Ensure 'Branch-to-Branch' routing is enabled in the Prisma Access infrastructure settings in Panorama
AnswersB, C, E

Firewall security policies must allow inter-branch traffic.

Why this answer

Branch-to-branch routing in Prisma Access requires explicit configuration, including enabling branch-to-branch traffic in Panorama, ensuring proper security policies permit the traffic, and correct route advertisement.

18
MCQmedium

A network engineer is configuring remote user access in Prisma Access and needs to ensure that internal corporate DNS resolution is utilized when users are connected via the GlobalProtect app. Where must the engineer configure the primary and secondary internal DNS server IP addresses?

A.In the Prisma SD-WAN DNS proxy forwarding table
B.In the Panorama GlobalProtect Client Settings configuration under Network Settings
C.Directly on the remote user local machine registry
D.In the cloud Managed Security Services Provider (MSSP) portal
AnswerB

Internal DNS servers assigned to the GlobalProtect agent are configured within the Client Settings.

Why this answer

DNS server IPs for remote users are configured in the GlobalProtect client configuration within Panorama under Cloud Services > Configuration > Users > GlobalProtect.

19
MCQhard

An administrator is configuring QoS in Prisma Access for a Remote Network connection. Where must the QoS profile be applied to ensure priority handling for VoIP traffic coming from the branch?

A.Inside the GlobalProtect Gateway agent configuration profile
B.On the Remote Network configuration in Panorama under Bandwidth Allocation and QoS
C.Globally inside the Palo Alto Networks WildFire configuration
D.Directly on the customer branch router CLI via MQC
AnswerB

QoS for remote networks is configured directly within the Prisma Access Remote Network setup in Panorama.

Why this answer

QoS profiles in Prisma Access for remote networks are applied on the Remote Network configuration settings in Panorama under Cloud Services.

20
MCQmedium

An organization is integrating Prisma Access with their existing Panorama deployment. Which plugin must be installed on Panorama to enable the Prisma Access configuration workflows?

A.Prisma Access plugin
B.SD-WAN plugin
C.VM-Series plugin
D.Cortex Data Lake plugin
AnswerA

The Prisma Access plugin adds the Cloud Services tab and configuration workflows to Panorama.

Why this answer

The Prisma Access plugin is required on Panorama to configure and manage Prisma Access infrastructure.

21
Multi-Selectmedium

An administrator is reviewing the status of a Prisma Access deployment using Prisma Access Insights. Which THREE key metrics or insights can be viewed through this tool? (Choose three)

Select 3 answers
A.Individual endpoint user Windows registry configurations
B.Service health and status of cloud infrastructure and tunnels
C.License consumption and active mobile user counts
D.Bandwidth utilization and allocation across remote locations
E.Local branch switch port VLAN configurations
AnswersB, C, D

Insights displays real-time health and status of nodes and connections.

Why this answer

Prisma Access Insights provides visibility into service health, license utilization, active user counts, and bandwidth consumption across locations.

22
Multi-Selecthard

When designing a multi-region Prisma Access architecture, an architect must consider compute locations and routing preferences. Which THREE factors influence the selection and placement of compute locations? (Choose three)

Select 3 answers
A.The physical desk layout of employee cubicles in branch offices
B.Geographic distribution of remote users and branch offices
C.Data residency and regulatory compliance requirements
D.The local power grid provider utilized by the cloud data center
E.Proximity to primary SaaS applications and enterprise datacenters
AnswersB, C, E

Deploying compute locations close to users minimizes latency.

Why this answer

Compute location selection is driven by user geographic distribution, regulatory compliance requirements, and proximity to enterprise SaaS or data center locations.

23
MCQeasy

An architect is designing a Prisma Access deployment for a global enterprise that requires low-latency connectivity for remote workers across North America, Europe, and Asia. Which component should the architect deploy to ensure traffic processing occurs closest to the user's geographical location?

A.A dedicated hardware Panorama appliance in each branch office
B.Prisma SD-WAN appliances at every remote user laptop
C.A single centralized Prisma Access parent node in the headquarters region
D.Multiple Security Processing Nodes (SPNs) distributed across multiple geographic regions
AnswerD

Deploying SPNs across multiple cloud regions ensures users connect to the nearest compute location.

Why this answer

Remote Networks and Mobile Users require Security Processing Nodes (SPNs) deployed across multiple compute locations globally to ensure traffic is processed closest to the user, minimizing latency.

Ready to test yourself?

Try a timed practice session using only Prisma Access Planning And Deployment questions.