Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Paloalto Networks SSE-Engineer Dumps

Palo Alto Networks Security Service Edge Engineer Questions and Answers

Question 1

A financial institution needs to prevent employees from easily moving textual information from secure financial portals accessed using Prisma Access Browser (PAB) directly into other applications on their workstations. The goal is to stop the practice of selecting data within the browser and then inserting that selected content into external documents or programs. Which PAB control should be configured to disable this particular method of data transference?

Options:

A.

Data loss prevention (DLP)

B.

Data Transfer

C.

Clipboard

D.

Webpage Data Masking

Question 2

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

as

Options:

A.

The Remote Network Security policy source zone is configured as " Untrust. "

B.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

C.

The " Allow inbound flows to other Remote Networks over the Prisma Access backbone " checkbox is selected.

D.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.

Question 3

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Options:

A.

Specified internal security appliance

B.

Dedicated cloud storage location

C.

Panorama

D.

Strata Cloud Manager (SCM)

Question 4

How can a network security team be granted full administrative access to a tenant ' s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

Options:

A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant ' s scope and assign it to the security team ' s user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team ' s user accounts.

D.

Set the administrative accounts for the security team to the " Superuser " role.

Question 5

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

Options:

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Question 6

Which policy configuration in Prisma Access Browser (PAB) will protect an organization from malicious BYOD and minimize the impact on the user experience?

Options:

A.

One that blocks file exchange

B.

One for session recording

C.

One that blocks elements such as screen scrapers

D.

One that allows access to applications with data masking or watermarking

Question 7

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

Options:

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Question 8

Which two Prisma Access Browser (PAB) configurations will provide a contractor SSH access to an internal system? (Choose two.)

Options:

A.

Configure Internal Application entries, Configure Access & Data Control policy

B.

Enable Remote Connections

C.

Configure Remote Connection Application entries, Configure Access & Data Control policy

D.

Enable Internal Connections

Question 9

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

Options:

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Question 10

Strata Logging Service is configured to forward logs to an external syslog server; however, a month later, there is a disruption on the syslog server. Which action will send the missing logs to the external syslog server?

Options:

A.

Configure a replay profile with the affected time range and associate it with the affected syslog server profile.

B.

Delete the affected syslog server profile and create a new one.

C.

Export the logs from Strata Logging Service, and then manually import them to the syslog server.

D.

Configure a log filter under the syslog server profile with the affected time range.

Question 11

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. The solution must meet these requirements: The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations. The branch locations must have internet filtering and data center connectivity. The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports. The security team must have access to manage the mobile user and access to branch locations. The network team must have access to manage only the partner access. How should Prisma Access be implemented to meet the customer requirements?

Options:

A.

Deploy two Prisma Access instances - the first with mobile users, remote networks, and private access for all internal connection types, and the second with remote networks and private application access for B2B connections - and use the Strata Multitenant Cloud Manager Prisma Access configuration scope to manage access.

B.

Deploy a Prisma Access instance with mobile users, remote networks, and private access for all connection types, and use the Prisma Access Configuration scope to manage all access.

C.

Deploy two Prisma Access instances - the first with mobile users, remote networks, and private access for all internal connection types, and the second with remote networks and private application access for B2B connections - and use the specific configuration scope for the connection type to manage access.

D.

Deploy a Prisma Access instance with mobile users, remote networks, and private access for all connection types, and use the specific configuration scope for the connection type to manage access.

Question 12

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to its data centers. [Scenario as before, with overlapping prefixes advertised by B2B partners.] Which two actions will meet the customer requirements for the B2B connections? (Choose two.)

Options:

A.

Advertise the corresponding network prefixes using eBGP or static routes.

B.

Configure remote networks with NAT pools for each of the B2B connections.

C.

Configure service connections for data center connectivity.

D.

NAT the traffic at the customer premises equipment (CPE).

Question 13

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy. Which statement explains the branch traffic behavior?

Options:

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as " Trust. "

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Question 14

A company is migrating from NGFW-hosted Global Protect to Prisma Access Mobile Users. The authentication method will change from LDAP with Windows Active Directory Domain Controllers to SAML with Microsoft Entra ID. After configuring and applying the SAML Authentication Profile to the Mobile Users configuration, the migrated group-based Security policies are no longer functioning. Which User-ID setting must be updated for the group-based Security policies to begin functioning?

Options:

A.

Configure a redistribution profile to send user-to-group mapping from the Global Protect firewalls to Prisma Access.

B.

Migrate group mapping to Cloud Identity Engine using an agent to query the Windows Active Directory Domain Controllers.

C.

Modify the group mapping settings by updating the User Attributes to include " userPrincipalName. "

D.

Change the SAML Authentication profile Username Modifier to %USERDOMAIN%\%USERINPUT%.

Question 15

A network administrator is enabling users, via Prisma Access Browser (PAB), to securely access internal web applications hosted exclusively within the organization ' s private data center. Which two Prisma Access infrastructure components are primarily configured to establish the necessary connection pathways from Prisma Access to these internal data center resources? (Choose two.)

Options:

A.

Explicit Proxy

B.

ZTNA Connector

C.

Privileged Remote Access

D.

Service Connection

Question 16

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

Options:

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.

B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.

C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.

D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.

Question 17

When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?

Options:

A.

A URL access management profile with site access set to " Isolate " applied to a Security policy

B.

A DNS Security profile applied to a Security policy with the action of " Isolate " for the target remote browser DNS categories

C.

An RBI profile applied to the URL access management profile

D.

A Security policy with the target URL categories and set the action to " Isolate "

Question 18

An engineer is troubleshooting split-tunneling on a Palo Alto Networks VPN client. The local LAN interface is on the 192.168.1.0/24 network, and the Prisma Access Mobile User IP Pool is configured as 172.16.72.0/23 in Strata Cloud Manager (SCM). Based on the image below, which statement regarding the split-tunneling configuration for the VPN client is valid?

as

Options:

A.

9.9.9.9/32 has been explicitly configured as an include route.

B.

192.168.5.95/32 has been explicitly configured as an exclude route.

C.

10.10.10.10/32 has been explicitly configured as an include route.

D.

172.16.73.1/32 has been explicitly configured as an exclude route.

Question 19

An intern is tasked with changing the Anti-Spyware Profile used for security rules defined in the Global Protect folder. All security rules are using the Default Prisma Profile. The intern reports that the options are greyed out and cannot be modified when selecting the Default Prisma Profile. Based on the image below, which action will allow the intern to make the required modifications?

as

Options:

A.

Request edit access for the Global Protect scope.

B.

Change the configuration scope to Prisma Access and modify the profile group.

C.

Create a new profile, because default profile groups cannot be modified.

D.

Modify the existing anti-spyware profile, because best-practice profiles cannot be removed from a group.

Question 20

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Options:

A.

Verify from the routing table.

B.

Enable dump level logs on Global Protect Application.

C.

Verify zoom.us is resolved by the tunnel assigned DNS server.

D.

Ping zoom.us from the CLI.

Page: 1 / 7
Total 73 questions