Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Paloalto Networks SSE-Engineer Practice Exam with Questions & Answers

Questions 1

In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?

Options:
A.

Apply File Blocking to stop file uploads containing financial information.

B.

Configure an Enterprise DLP rule to block uploads containing financial information.

C.

Add the ChatGPT domains using URL Filtering to block uploads containing financial information.

D.

Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.

Paloalto Networks SSE-Engineer Premium Access
Questions 2

When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by showing only unique devices?

Options:
A.

Add the duplicate entries to the ignore list in IoT Security.

B.

Merge individual devices into a single device with multiple interfaces.

C.

Create a custom role to merge devices with the same hostname and operating system.

D.

Delete all duplicate devices, keeping only those discovered using their management IP addresses.

Questions 3

What is the network impact when a Prisma Access service connection is set as a dedicated service connection for traffic steering?

Options:
A.

It maintains its zone as Trust and continues to participate in both internal and external BGP routing.

B.

It changes its zone to Untrust, applies source NAT to forwarded traffic, and no longer participates in BGP routing.

C.

It maintains its zone as Trust; however, it disables all Security policies, allowing unrestricted traffic flow through the dedicated service connection.

D.

It applies destination NAT to forwarded traffic, maintains its BGP routing configurations, and allows traffic from both Trust and Untrust zones.

Questions 4

Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)

Options:
A.

Configure a webhook to receive notifications of IP address changes.

B.

Copy the Egress IP API Key in the service infrastructure settings.

C.

Enable the Egress IP API endpoint in Prisma Access.

D.

Download a client certificate to authenticate to the Egress IP API.

Questions 5

Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below. After a successful commit, return traffic from the application is not reaching the internet user. What is causing the return traffic to fail?

SSE-Engineer Question 5

Options:
A.

The Remote Network Security policy source zone is configured as " Untrust. "

B.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.

C.

The " Allow inbound flows to other Remote Networks over the Prisma Access backbone " checkbox is selected.

D.

Source NAT is enabled, but the branch location ' s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.

Questions 6

An organization deploys the Prisma Access Browser (PAB) to secure web access from diverse endpoints, including personal devices where IT has limited control. To maintain a strong and proactive security posture across these varied environments, why is the use of PAB device posture attributes, such as OS version, file system encryption, and device type, considered essential?

Options:
A.

It permits PAB to function as a standalone endpoint detection and response (EDR) solution.

B.

It provides the administrators of PAB the ability to enable disk encryption on all endpoints.

C.

It allows administrators to identify and restrict access based on OS version and browser type on unmanaged devices.

D.

It enables the administrators of PAB to independently perform OS and browser patching on unmanaged devices.

Questions 7

A company is using Prisma Access with Cloud Identity Engine for user-based policies. Which two system configurations will dynamically grant users access to specific projects based on their group membership in Microsoft Entra ID? (Choose two.)

Options:
A.

Configure Dynamic Privilege Access settings in Prisma Access and associate the user groups with the corresponding project IP address pools.

B.

Create a custom application in Microsoft Entra ID representing each project and configure SSO with the Cloud Identity Engine.

C.

Implement an authentication sequence in Prisma Access that prioritizes Cloud Identity Engine authentication for users belonging to project-specific groups.

D.

In the Cloud Identity Engine, add the Microsoft Entra ID directory as an IdP and configure the required user group mappings for each project.

Questions 8

Which two configurations must be enabled to allow App Acceleration for SaaS applications? (Choose two.)

Options:
A.

Acceleration agent for the client machines

B.

QoS for user traffic

C.

Trusted Root CA for the CA certificate

D.

Forward Trust Certificate for the CA certificate

Questions 9

How can a network security team be granted full administrative access to a tenant ' s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

Options:
A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant ' s scope and assign it to the security team ' s user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team ' s user accounts.

D.

Set the administrative accounts for the security team to the " Superuser " role.

Questions 10

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Options:
A.

Verify from the routing table.

B.

Enable dump level logs on Global Protect Application.

C.

Verify zoom.us is resolved by the tunnel assigned DNS server.

D.

Ping zoom.us from the CLI.

Exam Code: SSE-Engineer
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks Security Service Edge Engineer
Last Update: Aug 20, 2026
Questions: 73
PDF + Testing Engine
$164.99
$49.5
Testing Engine
$124.99
$37.5
PDF (Q&A)
$104.99
$31.5