sse-engineer Practice Questions
Prepare for sse-engineer with more than an answer.
- Exam fee
- $250 USD
- Level
- Specialist
- Valid for
- Not specified
Domains covered on the exam 5
- Prisma Access Planning and Deployment22%
- Prisma Access Services22%
- Prisma Access Browser (PAB)22%
- Prisma Access Administration and Operation16%
- Prisma Access Troubleshooting18%
- 1
An engineer has deployed the Prisma Access Browser (PAB) extension to all corporate laptops. The goal is to secure access to both public SaaS apps and private internal apps. How does PAB differentiate between traffic destined for a public app versus a private app?
Show answer details
Correct answer: B
The Prisma Access Browser intelligently routes traffic. When a user tries to access a resource, PAB first checks against the list of configured private applications. If the destination FQDN matches a private app, traffic is tunneled through the ZTNA connection. If it does not match, it is treated as public traffic and is forwarded to the nearest Prisma Access Security Processing Node for standard security inspection.
- 2
True or False: Strata Cloud Manager Copilot can automatically generate and suggest security policy rule optimizations based on observed traffic patterns and adherence to best practices.
Show answer details
Correct answer: A
True. Strata Cloud Manager Copilot is an AI-powered assistant that helps administrators manage their security posture. One of its key features is the ability to analyze traffic logs and existing policies to proactively suggest optimizations, such as tightening overly permissive rules, adding more specific applications, or identifying redundant policies.
- 3
An organization is experiencing poor video conferencing quality for its remote workers connected via GlobalProtect. The SSE engineer needs to ensure that real-time traffic like Zoom and Microsoft Teams is prioritized over bulk data transfers. Which profile or policy should be configured in Prisma Access to achieve this?
flowchart TD A[User Traffic] --> B{Application ID}; B -->|Zoom/Teams| C[High Priority Queue]; B -->|Bulk Transfer| D[Low Priority Queue]; C --> E[Internet]; D --> E;Show answer details
Correct answer: B
Quality of Service (QoS) is the feature designed to manage and prioritize network traffic. An engineer would create a QoS profile that defines different traffic classes (e.g., high, medium, low priority) and then create a QoS policy rule that uses Application IDs to map applications like Zoom and Teams to the high-priority class, ensuring they receive preferential bandwidth treatment over less critical traffic.
- 4
A mobile user is unable to access an internal web server. The SSE engineer's initial investigation using the traffic logs shows that the user's traffic is being denied by a security policy. The policy is supposed to allow access for members of the 'Engineering' AD group, and the user is confirmed to be in that group. The logs, however, do not show any user-to-group mapping information for the user. What is the most likely cause of this User-ID mismatch?
Show answer details
Correct answer: B
For Prisma Access to enforce group-based policies, it relies on the Cloud Identity Engine (CIE) to synchronize user and group information from the identity provider (e.g., Azure AD). If the traffic logs show an IP address but no user or group information, it strongly indicates that the User-ID mapping is failing. This is most commonly caused by a communication issue between CIE and the directory server or a delay/failure in the synchronization process.
- 5
When deploying a ZTNA Connector, what is the recommended best practice for ensuring high availability for private application access?
Show answer details
Correct answer: C
The correct method for ZTNA Connector high availability is to deploy multiple connectors (ideally on different hosts or in different failure domains) and organize them into a Connector Group. Prisma Access will automatically load balance traffic across the active connectors in the group and handle failover if one of the connectors becomes unavailable.
- 6
A financial services firm is deploying Prisma Access managed by Strata Cloud Manager. For compliance reasons, they must log all DNS queries made by mobile users to an on-premises SIEM. The current configuration forwards all other traffic logs to the Strata Logging Service. Which configuration change is required to selectively forward only the DNS logs to the on-premises SIEM while maintaining other logging functions?
Show answer details
Correct answer: B
When using the Strata Logging Service, log forwarding is configured centrally within the SCM settings, not via security policy rules like in Panorama. The correct method is to navigate to the logging service configuration, create a specific rule for the desired log type (DNS), and direct it to the appropriate external destination (the SIEM). The other options describe methods used in Panorama-managed firewalls or are conceptually incorrect.
- 7
An organization wants to provide secure, agentless access for third-party contractors to a specific internal web application. The security team's requirements are to prevent data exfiltration by disabling copy-paste and printing, and to isolate the contractors' browser sessions from the internal network. Which combination of Prisma Access features should an engineer implement to meet these requirements?
Show answer details
Correct answer: C
Prisma Access Browser (PAB) is the agentless solution designed for this use case. Remote Browser Isolation (RBI) streams a visual representation of the web application to the user's browser, completely isolating the session from the endpoint and internal network. Enterprise DLP policies applied within PAB can enforce granular controls like disabling copy-paste and printing, directly addressing the data exfiltration concern.
- 8
During a Prisma Access deployment, an engineer observes that mobile user traffic to Microsoft 365 applications is experiencing higher latency than expected. The organization wants to optimize this traffic without compromising security inspection. What is the recommended Prisma Access feature to address this specific issue?
Show answer details
Correct answer: B
App Acceleration is a feature specifically designed to improve the performance of latency-sensitive applications, with pre-defined optimizations for common SaaS applications like Microsoft 365. It uses techniques on the Prisma Access backbone to reduce latency and improve the user experience. While QoS can prioritize traffic, App Acceleration provides a more direct and effective solution for performance optimization of supported applications.
- 9
A network architect is designing a Prisma Access solution for a multinational corporation. The design must ensure that traffic from a remote network in Germany is routed to a service connection in a UK data center over the Palo Alto Networks backbone, bypassing the public internet for the majority of the path. Which routing component is primarily responsible for facilitating this traffic flow?
graph TD subgraph Germany RN[Remote Network] end subgraph UK DC[Data Center] SC[Service Connection] end subgraph Prisma_Access_Cloud [Prisma Access Cloud] SPN_DE[SPN Germany] SPN_UK[SPN UK] Backbone(Palo Alto Networks Backbone) end RN --> SPN_DE SPN_DE --> Backbone Backbone --> SPN_UK SPN_UK --> SC SC --> DCShow answer details
Correct answer: C
Backbone routing is the mechanism that directs traffic between different Prisma Access locations (like from a Security Processing Node handling a remote network to another handling a service connection) over the high-speed, private Palo Alto Networks global backbone. This avoids transiting the public internet, providing better performance and security, which is exactly what the scenario requires.
- 10
True or False: When using the Prisma Access ZTNA Connector for private application access, a service connection is no longer required to establish connectivity between Prisma Access and the data center where the applications are hosted.
Show answer details
Correct answer: A
True. The ZTNA Connector provides a simplified and secure way to connect private applications to Prisma Access without requiring traditional network-level connectivity like IPSec tunnels (service connections). The connector establishes an outbound-only TLS tunnel to the Prisma Access cloud, effectively replacing the need for a service connection for the specific applications it serves.
