Skip to main content

PAN-SSEE Real Exam Questions

Palo Alto Networks Security Service Edge Engineer

65 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links.

With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?

  1. A

    Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string attribute on the mobile user prefixes in its respective Prisma Access region.

  2. B

    Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.

  3. C

    Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile user prefixes in its respective Prisma Access region.

  4. D

    Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes originating from the other region.

Show answer and explanation

Correct answer: B

Explanation

In Prisma Access's default routing mode, the service connections establish BGP sessions with the customer premises equipment (CPE) in the data centers. To ensure traffic destined for mobile users in a specific region (e.g., North America) traverses the service connection in that same region, you need to control the route advertisements.

Filtering out the mobile user pool prefixes from the other region on each service connection achieves this by: Preventing the data center in one region from learning the specific mobile user prefixes of the other region.For example, the North American service connection would filter out the mobile user pool prefixes allocated to European users.
Ensuring that when a data center needs to send traffic to a mobile user, it will only see and use the route advertised by the service connection in the appropriate geographical region.This forces the traffic to enter the Prisma Access infrastructure through the intended regional service connection.

Let's analyze why the other options are incorrect based on official documentation regarding default routing mode:
A. Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string
attribute on the mobile user prefixes in its respective Prisma Access region.While BGP communities can be used for influencing routing decisions, in the context of default routing mode and ensuring regional traffic flow, relying solely on the CPE to prefer community strings might not be the most robust or direct method to guarantee traffic traverses the correct regional service connection. The service connection itself needs to control the advertisement of prefixes.
C. Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile
user prefixes in its respective Prisma Access region.The BGP MED (Multi-Exit Discriminator) attribute is primarily used to influence the path selection between autonomous systems (AS) or within the same AS at different entry points. In this scenario, where serviceconnections are advertising prefixes, filtering at the source (service connection) is a more direct and reliable way to ensure regional traffic flow than relying on the MED attribute on the CPE.
D. Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes
originating from the other region.BGP AS path prepending is a mechanism to make a path less desirable.
While this could influence routing, it doesn't guarantee that traffic will always take the intended regional path. Filtering provides a more definitive control over which routes are advertised and learned.

Therefore, configuring each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center is the verified method to ensure traffic destined for mobile users traverses the service connection in the appropriate region when using Prisma Access in default routing mode.

Question 2 Single choice

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

  1. A

    There is a misconfiguration in the DNS settings on the connector.

  2. B

    The connector is deployed behind a double NAT.

  3. C

    The connector is using a dynamic IP address.

  4. D

    There is a high latency in the network connection.

Show answer and explanation

Correct answer: B

Explanation

A ZTNA Connector requires a stable and direct connection to the cloud gateway . When the connector is deployed behind a double NAT (Network Address Translation) , it can cause issues with reachability and session establishment because the cloud gateway may not be able to properly identify and communicate with the connector. Double NAT can interfere withsecure tunneling, IP address resolution, and authentication mechanisms , leading to connection failures . To resolve this, the connector should be placed in a network segment with a single NAT or a public IP assignment .

Question 3 Multiple choice

Which two configurations must be enabled to allow App Acceleration for SaaS applications? (Choose two.)

  1. A

    Acceleration agent for the client machines

  2. B

    QoS for user traffic

  3. C

    Trusted Root CA for the CA certificate

  4. D

    Forward Trust Certificate for the CA certificate

Show answer and explanation

Correct answers: C, D

Explanation

To enable App Acceleration for SaaS applications in Prisma Access, the following configurations must be enabled:

Trusted Root CA for the CA certificate ensures that Prisma Access can validate and trust the SaaS application's certificates, allowing seamless inspection and acceleration of traffic without security warnings.

Forward Trust Certificate for the CA certificate enables SSL decryption for SaaS applications, allowing Prisma Access to optimize traffic and apply acceleration techniques while maintaining security policies.

Question 4 Single choice

How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage the Security policy in a single tenant while restricting access to other tenants in a multitenant deployment?

  1. A

    Add the team to the Parent Tenant, select the Prisma Access Configuration Scope, and set the role to Security Administrator.

  2. B

    Add the team to the Child Tenant, select All Apps & Services, and set the role to Security Administrator.

  3. C

    Add the team to the Parent Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

  4. D

    Add the team to the Child Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

Show answer and explanation

Correct answer: D

Explanation

In a multitenant deployment , access control must be configured at the Child Tenant level to ensure that security administrators have full control over Security policy only within their assigned tenant while restricting access to other tenants. By selecting Prisma Access & NGFW Configuration , the assigned users gain full administrative access only for security policy management within the designated tenant, aligning with RBAC best practices for controlled access in Prisma Access Managed by Strata Cloud Manager .

Question 5 Single choice

During a deployment of Prisma Access (Managed by Strata Cloud Manager) for mobile users, a SAML authentication type and authentication profile in the Cloud Identity Engine application is successfully created.

Using this SAML authentication, what is a valid next step to configure authentication for mobile users?

  1. A

    Perform a full commit to Strata Cloud Manager so the Cloud Identity Engine profiles get synchronized from the application.

  2. B

    Permit the Cloud Identity Engine service account RBAC access to the mobile user folder in Strata Cloud Manager.

  3. C

    In Strata Cloud Manager, create a new authentication type of "Cloud Identity Engine."

  4. D

    Create a SAML authentication profile in Strata Cloud Manager and link it to the Cloud Identity Engine profile.

Show answer and explanation

Correct answer: D

Explanation

After successfully creating a SAML authentication type and authentication profile Cloud Identity Engine in , the next step is to configure a corresponding SAML authentication profile in Strata Cloud Manager and link it to the Cloud Identity Engine profile . This ensures that Prisma Access (Managed by Strata Cloud Manager) can authenticate mobile users using the configured SAML identity provider (IdP), enabling seamless user authentication and access control.

Question 6 Multiple choice

A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access.

What are two reasons for this behavior? (Choose two.)

  1. A

    "Collect HIP data' needs to be enabled in the configuration.

  2. B

    User mapping is learned from sources other than gateway authentication.

  3. C

    Firewall loses user mapping due to missed HIP report checks.

  4. D

    HIP-enforced policy is scheduled for certain hours of the day.

Show answer and explanation

Correct answers: B, C

Explanation

User mapping learned from sources other than gateway authentication can cause intermittent access issues if it conflicts with the expected user identity used in HIP-based policies. If the firewall is associatingthe user with an outdated or incorrect mapping, traffic may not match the intended security policies, leading todenials by the Catch-All Deny rule .

If the firewall loses user mapping due to missed HIP report checks , the user may temporarily lose access to policies that require a valid Host Information Profile (HIP) match. When the VPN connection is refreshed, the HIP check is re-initiated, restoring access until the issue repeats.

Question 7 Single choice

In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?

  1. A

    Apply File Blocking to stop file uploads containing financial information.

  2. B

    Configure an Enterprise DLP rule to block uploads containing financial information.

  3. C

    Add the ChatGPT domains using URL Filtering to block uploads containing financial information.

  4. D

    Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.

Show answer and explanation

Correct answer: B

Explanation

Palo Alto Networks AI Access Security integrates with Enterprise Data Loss Prevention (DLP) capabilities to control sensitive data within AI applications like ChatGPT. The most effective way to prevent users from uploading financial information is to: Define an Enterprise DLP rule:This rule would be configured to identify content that matches patterns or keywords associated with financial information (e.g., credit card numbers, bank account details, tax identifiers, financial statements).
Apply the DLP rule to the AI Access Security policy:This policy would be specifically configured to inspect traffic to and from ChatGPT. When the DLP rule detects a user attempting to upload content containing financial information, it can take a defined action, such as blocking the upload.

Let's analyze why the other options are incorrect based on official documentation:
A. Apply File Blocking to stop file uploads containing financial information.While File Blocking can prevent
the upload of certain file types, it is not content-aware. It cannot inspect the content of a file to determine if it contains financial information. Therefore, it's not a granular or effective solution for this specific requirement.
C. Add the ChatGPT domains using URL Filtering to block uploads containing financial information.URL
Filtering controls access to specific websites or categories of websites. While you could potentially block access to ChatGPT entirely, it does not provide the capability to inspect the content being uploaded to a permitted domain and prevent the transfer of sensitive financial data.
D. Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to
financial systems.Vulnerability profiles are designed to detect and prevent attempts to exploit known security vulnerabilities in systems. They are not designed to inspect the content of user uploads for sensitive data like financial information. While importantfor overall security, they do not directly address the requirement of preventing financial data uploads to ChatGPT.

Therefore, configuring an Enterprise DLP rule within AI Access Security is the correct and most effective method to prevent users from uploading financial information to ChatGPT by inspecting the content of the uploads.

Question 8 Single choice

What must be configured to accurately report an application's availability when onboarding a discovered application for ZTNA Connector?

  1. A

    icmp ping

  2. B

    https ping

  3. C

    tcp ping

  4. D

    udp ping

Show answer and explanation

Correct answer: C

Explanation

When onboarding a discovered application for ZTNA Connector , configuring a TCP ping allows Prisma Access to accurately report the application's availability TCP ping . (also known as a TCP connection check ) verifies whether the application's service port is open and responsive , ensuring that the application is reachable before allowing user connections. This method is more reliable than ICMP ping , as many cloud and SaaS applications block ICMP traffic for security reasons.

Question 9 Single choice

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

  1. A

    Verify from the routing table.

  2. B

    Enable dump level logs on GlobalProtect Application.

  3. C

    Verify zoom.us is resolved by the tunnel assigned DNS server.

  4. D

    Ping zoom.us from the CLI.

Show answer and explanation

Correct answer: A

Explanation

After configuring domain-based split tunneling for zoom.us , the expected behavior can be confirmed by checking the routing table on the client machine . If split tunneling is correctly configured, the traffic for zoom.us should be routed outside the GlobalProtect VPN tunnel, while other traffic follows the tunnel path.
Reviewing the routing table ensures that only the intended traffic is excluded from the tunnel , confirming that the split tunnel configuration is working as expected.

Question 10 Single choice

An engineer must configure Prisma Access to enforce different threat prevention profiles for branch offices and mobile users.

Which configuration scope should be used?

  1. A

    Separate policy scopes for Remote Networks and Mobile Users

  2. B

    Shared global policy for all connection types

  3. C

    Centralized template under Strata Cloud Manager

  4. D

    Unified configuration scope for security profiles

Show answer and explanation

Correct answer: A

Explanation

Creating separate scopes for Remote Networks and Mobile Users allows tailored security controls based on traffic origin and deployment type.