Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

SSE-Engineer Palo Alto Networks Security Service Edge Engineer Questions and Answers

Questions 4

A company is using Prisma Access with Cloud Identity Engine for user-based policies. Which two system configurations will dynamically grant users access to specific projects based on their group membership in Microsoft Entra ID? (Choose two.)

Options:

A.

Configure Dynamic Privilege Access settings in Prisma Access and associate the user groups with the corresponding project IP address pools.

B.

Create a custom application in Microsoft Entra ID representing each project and configure SSO with the Cloud Identity Engine.

C.

Implement an authentication sequence in Prisma Access that prioritizes Cloud Identity Engine authentication for users belonging to project-specific groups.

D.

In the Cloud Identity Engine, add the Microsoft Entra ID directory as an IdP and configure the required user group mappings for each project.

Buy Now
Questions 5

An organization wants Prisma Access Browser (PAB) users to authenticate to public cloud services, such as Microsoft 365, using its existing corporate IdP (e.g., Azure AD). Which integration is essential to enable this automated single sign-on (SSO) experience for public cloud applications accessed via PAB?

Options:

A.

Direct integration of the browser with Microsoft ' s Conditional Access policies

B.

Deployment of a browser-specific SSO extension

C.

Configuration of individual user authentication tokens within the PAB profile

D.

Cloud Identity Engine integration with the corporate IdP

Buy Now
Questions 6

When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?

Options:

A.

A URL access management profile with site access set to " Isolate " applied to a Security policy

B.

A DNS Security profile applied to a Security policy with the action of " Isolate " for the target remote browser DNS categories

C.

An RBI profile applied to the URL access management profile

D.

A Security policy with the target URL categories and set the action to " Isolate "

Buy Now
Questions 7

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

Options:

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.

B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.

C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.

D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.

Buy Now
Questions 8

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

Options:

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Buy Now
Questions 9

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Options:

A.

Specified internal security appliance

B.

Dedicated cloud storage location

C.

Panorama

D.

Strata Cloud Manager (SCM)

Buy Now
Questions 10

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?

Options:

A.

Advanced Threat Prevention option to block " Domain Fronting "

B.

Advanced URL Filtering and block the " Malicious Behavior " category

C.

Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "

D.

SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "

Buy Now
Questions 11

A network administrator is enabling users, via Prisma Access Browser (PAB), to securely access internal web applications hosted exclusively within the organization ' s private data center. Which two Prisma Access infrastructure components are primarily configured to establish the necessary connection pathways from Prisma Access to these internal data center resources? (Choose two.)

Options:

A.

Explicit Proxy

B.

ZTNA Connector

C.

Privileged Remote Access

D.

Service Connection

Buy Now
Questions 12

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Options:

A.

The rule was created with improper threat management settings.

B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.

C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.

D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.

Buy Now
Questions 13

Where are tags applied to control access to Generative AI when implementing AI Access Security?

Options:

A.

To Generative AI applications for identifying sanctioned, tolerated, or unsanctioned applications

B.

To security rules for defining which types of Generative AI applications are allowed or blocked

C.

To user devices for identifying and controlling which Generative AI applications they can access

D.

To Generative AI URL categories for classifying trusted and untrusted Generative AI websites

Buy Now
Questions 14

How can the Prisma Access Browser (PAB) Extension extend an organization ' s web security posture to managed devices that are not connected to a VPN for browser-based access to company-sanctioned web applications?

Options:

A.

It enforces consistent web access and data control policies directly within the browser, regardless of device management status.

B.

It tunnels all endpoint traffic on unmanaged devices, ensuring all device traffic is secured.

C.

It incorporates remote browser isolation (RBI) for the endpoint, running web sessions in a contained environment on any browser.

D.

It optimizes network performance for browser traffic to Prisma Access for all operating systems and browsers.

Buy Now
Questions 15

An employee is traveling to a country where their employer has not deployed a Prisma Access gateway. Which two mobile user gateways will the VPN client connect to automatically? (Choose two.)

Options:

A.

Backup

B.

Global fallback

C.

Regional fallback

D.

Local zone

Buy Now
Questions 16

Which feature will fetch user and group information to verify whether a group from the Cloud Identity Engine is present on a security processing node (SPN)?

Options:

A.

SASE Health Dashboard

B.

User Activity Insights

C.

Prisma Access Locations

D.

Region Activity Insights

Buy Now
Questions 17

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

Options:

A.

The Remote Network Security policy source zone is configured as " Untrust. "

B.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

C.

The " Allow inbound flows to other Remote Networks over the Prisma Access backbone " checkbox is selected.

D.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.

Buy Now
Questions 18

An engineer has configured IPSec tunnels for two remote network locations; however, users are experiencing intermittent connectivity issues across the tunnels. What action will allow the engineer to receive notifications when the IPSec tunnels are down or experiencing instability?

Options:

A.

Create a new notification profile specifying conditions for remote network IPSec tunnel conditions.

B.

Create a tunnel log notification rule to alert on specified remote network IPSec tunnel conditions.

C.

Set up the operational health dashboard to email alerts for remote Network IPSec tunnel issues.

D.

Select the IPSec tunnel monitoring and notifications checkbox when configuring the remote network IPSec tunnels.

Buy Now
Questions 19

Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?

Options:

A.

Geneve

B.

IPSec

C.

GRE

D.

DTLS

Buy Now
Questions 20

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario as above.] Which two options will allow the engineer to support the requirements? (Choose two.)

Options:

A.

Configure the CPE with Static Routes pointing to Prisma Access Infrastructure and Mobile User routes.

B.

Enable eBGP for dynamic routing and configure Remote Networks.

C.

Configure Remote Networks and define the branch IP subnets using Static Routes.

D.

Enable Remote Networks Advertise Default Route.

Buy Now
Exam Code: SSE-Engineer
Exam Name: Palo Alto Networks Security Service Edge Engineer
Last Update: Jul 9, 2026
Questions: 50
SSE-Engineer pdf

SSE-Engineer PDF

$25.5  $84.99
SSE-Engineer Engine

SSE-Engineer Testing Engine

$30  $99.99
SSE-Engineer PDF + Engine

SSE-Engineer PDF + Testing Engine

$40.5  $134.99