Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

SSE-Engineer Palo Alto Networks Security Service Edge Engineer Questions and Answers

Questions 4

What is the network impact when a Prisma Access service connection is set as a dedicated service connection for traffic steering?

Options:

A.

It maintains its zone as Trust and continues to participate in both internal and external BGP routing.

B.

It changes its zone to Untrust, applies source NAT to forwarded traffic, and no longer participates in BGP routing.

C.

It maintains its zone as Trust; however, it disables all Security policies, allowing unrestricted traffic flow through the dedicated service connection.

D.

It applies destination NAT to forwarded traffic, maintains its BGP routing configurations, and allows traffic from both Trust and Untrust zones.

Buy Now
Questions 5

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

Options:

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Buy Now
Questions 6

How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage the Security policy in a single tenant while restricting access to other tenants in a multitenant deployment?

Options:

A.

Add the team to the Parent Tenant, select the Prisma Access Configuration Scope, and set the role to Security Administrator.

B.

Add the team to the Child Tenant, select All Apps & Services, and set the role to Security Administrator.

C.

Add the team to the Parent Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

D.

Add the team to the Child Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

Buy Now
Questions 7

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

Options:

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Buy Now
Questions 8

How can an engineer use risk score customization in SaaS Security Inline to limit the use of unsanctioned SaaS applications by employees within a Security policy?

Options:

A.

Lower the risk score of sanctioned applications and increase the risk score for unsanctioned applications.

B.

Increase the risk score for all SaaS applications to automatically block unwanted applications.

C.

Build an application filter using unsanctioned SaaS as the category.

D.

Build an application filter using unsanctioned SaaS as the characteristic.

Buy Now
Questions 9

When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by showing only unique devices?

Options:

A.

Add the duplicate entries to the ignore list in IoT Security.

B.

Merge individual devices into a single device with multiple interfaces.

C.

Create a custom role to merge devices with the same hostname and operating system.

D.

Delete all duplicate devices, keeping only those discovered using their management IP addresses.

Buy Now
Questions 10

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?

Options:

A.

Advanced Threat Prevention option to block " Domain Fronting "

B.

Advanced URL Filtering and block the " Malicious Behavior " category

C.

Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "

D.

SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "

Buy Now
Questions 11

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. The solution must meet these requirements: The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations. The branch locations must have internet filtering and data center connectivity. The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports. The security team must have access to manage the mobile user and access to branch locations. The network team must have access to manage only the partner access. How can the engineer configure mobile users and branch locations to meet the requirements?

Options:

A.

Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

B.

Use Explicit Proxy to filter internet traffic and provide access to data center resources using service connections.

C.

Use GlobalProtect to filter internet traffic and provide access to data center resources using service connections.

D.

Use Explicit Proxy and Remote Networks to filter internet traffic and provide access to data center resources using service connections.

Buy Now
Questions 12

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

Options:

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.

B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.

C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.

D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.

Buy Now
Questions 13

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. [Same scenario.] Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)

Options:

A.

ZTNA Connector

B.

SD-WAN Connector

C.

Service connections

D.

Colo-Connect

Buy Now
Questions 14

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy. Which statement explains the branch traffic behavior?

Options:

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as " Trust. "

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Buy Now
Questions 15

What is the purpose of embargo rules in Prisma Access?

Options:

A.

Rate-limiting connections originating from specific countries

B.

Allowing traffic only from specific countries

C.

Blocking connections from specific countries

D.

Blocking traffic from Russia, China, and North Korea only

Buy Now
Questions 16

A company is migrating from NGFW-hosted Global Protect to Prisma Access Mobile Users. The authentication method will change from LDAP with Windows Active Directory Domain Controllers to SAML with Microsoft Entra ID. After configuring and applying the SAML Authentication Profile to the Mobile Users configuration, the migrated group-based Security policies are no longer functioning. Which User-ID setting must be updated for the group-based Security policies to begin functioning?

Options:

A.

Configure a redistribution profile to send user-to-group mapping from the Global Protect firewalls to Prisma Access.

B.

Migrate group mapping to Cloud Identity Engine using an agent to query the Windows Active Directory Domain Controllers.

C.

Modify the group mapping settings by updating the User Attributes to include " userPrincipalName. "

D.

Change the SAML Authentication profile Username Modifier to %USERDOMAIN%\%USERINPUT%.

Buy Now
Questions 17

Which two Prisma Access Browser (PAB) configurations will provide a contractor SSH access to an internal system? (Choose two.)

Options:

A.

Configure Internal Application entries, Configure Access & Data Control policy

B.

Enable Remote Connections

C.

Configure Remote Connection Application entries, Configure Access & Data Control policy

D.

Enable Internal Connections

Buy Now
Questions 18

How can a network security team be granted full administrative access to a tenant ' s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

Options:

A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant ' s scope and assign it to the security team ' s user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team ' s user accounts.

D.

Set the administrative accounts for the security team to the " Superuser " role.

Buy Now
Questions 19

Which advanced AI-powered functionality does Strata Copilot provide to enhance the capabilities of Prisma Access security teams?

Options:

A.

Real-time traffic analysis for automated threat prevention

B.

Initial configuration of Prisma Access using a natural language interface

C.

Customized guidance for resolving issues through recommended next steps

D.

Automated remediation of misconfigured security policies

Buy Now
Questions 20

How can a senior engineer use Strata Cloud Manager (SCM) to ensure that junior engineers are able to create compliant policies while preventing the creation of policies that may result in security gaps?

Options:

A.

Use security checks under posture settings and set the action to " deny " for all checks that do not meet the compliance standards.

B.

Configure role-based access controls (RBACs) for all junior engineers to limit them to creating policies in a disabled state, manually review the policies, and enable them using a senior engineer role.

C.

Configure an auto tagging rule in SCM to trigger a Security policy review workflow based on a security rule tag, then instruct junior engineers to use this tag for all new Security policies.

D.

Use a proxy tagging methodology to onboard using firewall management.

Buy Now
Exam Code: SSE-Engineer
Exam Name: Palo Alto Networks Security Service Edge Engineer
Last Update: Aug 21, 2026
Questions: 73
SSE-Engineer pdf

SSE-Engineer PDF

$25.5  $84.99
SSE-Engineer Engine

SSE-Engineer Testing Engine

$30  $99.99
SSE-Engineer PDF + Engine

SSE-Engineer PDF + Testing Engine

$40.5  $134.99