Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Paloalto Networks SSE-Engineer Practice Exam with Questions & Answers

Questions 1

How can an engineer verify that only the intended changes will be applied when modifying Prisma Access policy configuration in Strata Cloud Manager (SCM)?

Options:
A.

Review the SCM portal for blue circular indicators next to each configuration menu item and ensure only the intended areas of configuration have this indicator.

B.

Compare the candidate configuration and the most recent version under "Config Version Snapshots/

C.

Select the most recent job under Operations > Push Status to view the pending changes that would apply to Prisma Access.

D.

Open the push dialogue in SCM to preview all changes which would be pushed to Prisma Access.

Paloalto Networks SSE-Engineer Premium Access
Questions 2

Which feature will fetch user and group information to verify whether a group from the Cloud Identity Engine is present on a security processing node (SPN)?

Options:
A.

SASE Health Dashboard

B.

User Activity Insights

C.

Prisma Access Locations

D.

Region Activity Insights

Questions 3

What is the purpose of embargo rules in Prisma Access?

Options:
A.

Rate-limiting connections originating from specific countries

B.

Allowing traffic only from specific countries

C.

Blocking connections from specific countries

D.

Blocking traffic from Russia. China, and North Korea only

Questions 4

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy.

Which statement explains the branch traffic behavior?

Options:
A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as “Trust.”

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Questions 5

Which policy configuration in Prisma Access Browser (PAB) will protect an organization from malicious BYOD and minimize the impact on the user experience?

Options:
A.

One that blocks file exchange

B.

One for session recording

C.

One that blocks elements such as screen scrapers

D.

One that allows access to applications with data masking or watermarking

Questions 6

A customer using Prisma Access (Managed by Panorama) wants to monitor traffic patterns across all remote networks and use Strata Logging Service to gather insights on network usage. An engineer notices that some network data is missing from the Application Command Center (ACC).

What should the engineer do to ensure complete data visibility?

Options:
A.

Reconfigure the Prisma Access remote networks to log directly to Panorama instead of using Strata Logging Service.

B.

Verify that the Panorama web interface has been configured to aggregate logs from both the Panorama data and RN-SPNs.

C.

Enable the Use Data for Pre-Defined Reports' setting in the Logging and Reporting configuration on Panorama.

D.

Ensure that log forwarding profiles are applied to all Prisma Access policies and directed to Strata Logging Service.

Questions 7

A company has four branch offices between Canada Central and Canada East which use the same IPSec termination node and have QoS configured with customized bandwidth per site. An engineer wants to onboard a new branch office on the same IPSec termination node.

What is the QoS behavior for the new branch office?

Options:
A.

Automatically distributed to 25% for each site

B.

Unallocated until manually assigned

C.

Automatically distributed to 20% for each site

D.

Cannot be added to existing QoS configuration

Questions 8

A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access.

What are two reasons for this behavior? (Choose two.)

Options:
A.

"Collect HIP data' needs to be enabled in the configuration.

B.

User mapping is learned from sources other than gateway authentication.

C.

Firewall loses user mapping due to missed HIP report checks.

D.

HIP-enforced policy is scheduled for certain hours of the day.

Questions 9

How can a senior engineer use Strata Cloud Manager (SCM) to ensure that junior engineers are able to create compliant policies while preventing the creation of policies that may result in security gaps?

Options:
A.

Use security checks under posture settings and set the action to “deny” for all checks that do not meet the compliance standards.

B.

Configure role-based access controls (RBACs) for all junior engineers to limit them to creating policies in a disabled state, manually review the policies, and enable them using a senior engineer role.

C.

Configure an auto tagging rule in SCM to trigger a Security policy review workflow based on a security rule tag, then instruct junior engineers to use this tag for all new Security policies.

D.

Run a Best Practice Assessment (BPA) at regular intervals and manually revert any policies not meeting company compliance standards.

Questions 10

Which two statements apply when a customer has a large branch office with employees who all arrive and log in within a five-minute time period? (Choose two.)

Options:
A.

DNS results are only cached for frequently used hostnames.

B.

Maximum pending TCP DNS requests is 64.

C.

Maximum number of TCP DNS retries is 3.

D.

DNS results are cached for 300 seconds.

Exam Code: SSE-Engineer
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks Security Service Edge Engineer
Last Update: Jul 10, 2025
Questions: 50