Palo Alto Networks Certified Security Service Edge Engineer Free Sample Questions

20 free sample questions203 in the full practice test

Try simulator

sse-engineer Sample Questions

  1. Question 1

    A financial services firm is deploying Prisma Access managed by Strata Cloud Manager. For compliance reasons, they must log all DNS queries made by mobile users to an on-premises SIEM. The current configuration forwards all other traffic logs to the Strata Logging Service. Which configuration change is required to selectively forward only the DNS logs to the on-premises SIEM while maintaining other logging functions?

    Answer and explanation

    Correct answer: B

    When using the Strata Logging Service, log forwarding is configured centrally within the SCM settings, not via security policy rules like in Panorama. The correct method is to navigate to the logging service configuration, create a specific rule for the desired log type (DNS), and direct it to the appropriate external destination (the SIEM). The other options describe methods used in Panorama-managed firewalls or are conceptually incorrect.

  2. Question 2

    An organization wants to provide secure, agentless access for third-party contractors to a specific internal web application. The security team's requirements are to prevent data exfiltration by disabling copy-paste and printing, and to isolate the contractors' browser sessions from the internal network. Which combination of Prisma Access features should an engineer implement to meet these requirements?

    Answer and explanation

    Correct answer: C

    Prisma Access Browser (PAB) is the agentless solution designed for this use case. Remote Browser Isolation (RBI) streams a visual representation of the web application to the user's browser, completely isolating the session from the endpoint and internal network. Enterprise DLP policies applied within PAB can enforce granular controls like disabling copy-paste and printing, directly addressing the data exfiltration concern.

  3. Question 3

    During a Prisma Access deployment, an engineer observes that mobile user traffic to Microsoft 365 applications is experiencing higher latency than expected. The organization wants to optimize this traffic without compromising security inspection. What is the recommended Prisma Access feature to address this specific issue?

    Answer and explanation

    Correct answer: B

    App Acceleration is a feature specifically designed to improve the performance of latency-sensitive applications, with pre-defined optimizations for common SaaS applications like Microsoft 365. It uses techniques on the Prisma Access backbone to reduce latency and improve the user experience. While QoS can prioritize traffic, App Acceleration provides a more direct and effective solution for performance optimization of supported applications.

  4. Question 4

    A network architect is designing a Prisma Access solution for a multinational corporation. The design must ensure that traffic from a remote network in Germany is routed to a service connection in a UK data center over the Palo Alto Networks backbone, bypassing the public internet for the majority of the path. Which routing component is primarily responsible for facilitating this traffic flow?

    graph TD subgraph Germany RN[Remote Network] end subgraph UK DC[Data Center] SC[Service Connection] end subgraph Prisma_Access_Cloud [Prisma Access Cloud] SPN_DE[SPN Germany] SPN_UK[SPN UK] Backbone(Palo Alto Networks Backbone) end RN --> SPN_DE SPN_DE --> Backbone Backbone --> SPN_UK SPN_UK --> SC SC --> DC
    Answer and explanation

    Correct answer: C

    Backbone routing is the mechanism that directs traffic between different Prisma Access locations (like from a Security Processing Node handling a remote network to another handling a service connection) over the high-speed, private Palo Alto Networks global backbone. This avoids transiting the public internet, providing better performance and security, which is exactly what the scenario requires.

  5. Question 5

    True or False: When using the Prisma Access ZTNA Connector for private application access, a service connection is no longer required to establish connectivity between Prisma Access and the data center where the applications are hosted.

    Answer and explanation

    Correct answer: A

    True. The ZTNA Connector provides a simplified and secure way to connect private applications to Prisma Access without requiring traditional network-level connectivity like IPSec tunnels (service connections). The connector establishes an outbound-only TLS tunnel to the Prisma Access cloud, effectively replacing the need for a service connection for the specific applications it serves.

  6. Question 6

    A retail company is onboarding 500 branch locations as remote networks into Prisma Access. The network team wants to use dynamic routing to advertise the branch subnets and receive routes from the data center. Each branch has a single CPE device. What is the most scalable and efficient method to configure routing for these remote networks?

    Answer and explanation

    Correct answer: C

    For dynamic routing with remote networks, the standard and scalable method is to establish an eBGP peering session over the IPSec tunnel. This allows the branch CPE to advertise its local subnets to Prisma Access and learn routes from the rest of the SASE fabric (like data center subnets learned via service connections) automatically. Static routing is not scalable for 500 sites. iBGP is typically used within the same autonomous system, whereas eBGP is correct for peering between the customer site and Prisma Access.

  7. Question 7

    An administrator is using the Best Practice Assessment (BPA) tool within Strata Cloud Manager to evaluate their Prisma Access configuration. The BPA report indicates a failing check related to 'Decryption Profile with no-decrypt action'. What is the most likely reason for this failing check and the recommended remediation?

    Answer and explanation

    Correct answer: B

    The Best Practice Assessment (BPA) tool flags configurations that deviate from recommended security postures. A decryption profile set to 'no decrypt' and applied to a security policy means that encrypted traffic matching that rule is not being inspected for threats. This significantly reduces security visibility. The best practice is to enable SSL Forward Proxy decryption to inspect outbound SSL/TLS traffic for threats.

  8. Question 8

    Multiple answers

    An SSE engineer needs to configure Prisma Access to authenticate mobile users based on their membership in specific Active Directory groups. The organization uses Azure AD as its identity provider and has synchronized its on-premises AD. Which Prisma Access component is essential for retrieving user and group information from Azure AD to enforce user-based policies? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    The Cloud Identity Engine is the component that integrates with cloud-based identity providers like Azure AD to pull user and group mapping information. SAML is the protocol used for the authentication and authorization exchange with the IdP.

  9. Question 9

    A security team is concerned about employees using unsanctioned generative AI services, which could lead to sensitive data exposure. They want to allow access to their corporate-sanctioned AI tool but block all others, while also logging all prompts sent to the sanctioned tool. Which Prisma Access service is specifically designed to meet these requirements?

    Answer and explanation

    Correct answer: B

    AI Access Security is the purpose-built service within Prisma Access for discovering, securing, and controlling the use of generative AI applications. It can identify hundreds of AI tools, allow administrators to set granular policies (e.g., allow/block specific tools, control data uploads, log prompts), and prevent data leakage, directly addressing all the stated requirements.

  10. Question 10

    A user reports intermittent connectivity issues when connected to Prisma Access via the GlobalProtect client. The help desk has verified the user has a stable internet connection. As a troubleshooting step, the SSE engineer wants to analyze the traffic flow from the user's endpoint through the Prisma Access infrastructure. Which tool within Strata Cloud Manager provides detailed, hop-by-hop visibility and performance metrics for a user's connection to a specific application?

    Answer and explanation

    Correct answer: C

    Autonomous Digital Experience Management (ADEM) is the service that provides detailed visibility into the user's digital experience. It can trace the path from the user's endpoint, across their local network, the internet, and the Prisma Access infrastructure all the way to the application. It provides performance metrics for each segment, making it the ideal tool for diagnosing intermittent connectivity and performance issues.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 203 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon