Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

SSE-Engineer Questions and Answers

Question # 6

What is the network impact when a Prisma Access service connection is set as a dedicated service connection for traffic steering?

A.

It maintains its zone as Trust and continues to participate in both internal and external BGP routing.

B.

It changes its zone to Untrust, applies source NAT to forwarded traffic, and no longer participates in BGP routing.

C.

It maintains its zone as Trust; however, it disables all Security policies, allowing unrestricted traffic flow through the dedicated service connection.

D.

It applies destination NAT to forwarded traffic, maintains its BGP routing configurations, and allows traffic from both Trust and Untrust zones.

Full Access
Question # 7

An intern is tasked with changing the Anti-Spyware Profile used for security rules defined in the Global Protect folder. All security rules are using the Default Prisma Profile. The intern reports that the options are greyed out and cannot be modified when selecting the Default Prisma Profile. Based on the image below, which action will allow the intern to make the required modifications?

Question # 7

A.

Request edit access for the Global Protect scope.

B.

Change the configuration scope to Prisma Access and modify the profile group.

C.

Create a new profile, because default profile groups cannot be modified.

D.

Modify the existing anti-spyware profile, because best-practice profiles cannot be removed from a group.

Full Access
Question # 8

A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links. With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?

A.

Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string attribute on the mobile user prefixes in its respective Prisma Access region.

B.

Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.

C.

Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile user prefixes in its respective Prisma Access region.

D.

Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes originating from the other region.

Full Access
Question # 9

Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?

A.

Geneve

B.

IPSec

C.

GRE

D.

DTLS

Full Access
Question # 10

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Full Access
Question # 11

What is the flow impact of updating the Cloud Services plugin on existing traffic flows in Prisma Access?

A.

They will experience latency during the plugin upgrade process.

B.

They will automatically terminate when the upgrade begins.

C.

They will be unaffected because the plugin upgrade is transparent to users.

D.

They will be unaffected only if Panorama is deployed in high availability (HA) mode.

Full Access
Question # 12

In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?

A.

LDAP

B.

Kerberos

C.

SAML

D.

SSO

Full Access
Question # 13

An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk. Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)

A.

Configuring the print control as the specific data control for the rule

B.

Configuring the kiosk control, which prevents printing

C.

Defining the policy scope based on location, specifying the location of the corporate offices

D.

Defining the policy scope based on networks, specifying the corporate public IP range or CIDR

Full Access
Question # 14

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Full Access
Question # 15

A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access. What are two reasons for this behavior? (Choose two.)

A.

" Collect HIP data " needs to be enabled in the configuration.

B.

User mapping is learned from sources other than gateway authentication.

C.

Firewall loses user mapping due to missed HIP report checks.

D.

HIP-enforced policy is scheduled for certain hours of the day.

Full Access
Question # 16

An employee is traveling to a country where their employer has not deployed a Prisma Access gateway. Which two mobile user gateways will the VPN client connect to automatically? (Choose two.)

A.

Backup

B.

Global fallback

C.

Regional fallback

D.

Local zone

Full Access
Question # 17

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.

B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.

C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.

D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.

Full Access
Question # 18

What is the purpose of embargo rules in Prisma Access?

A.

Rate-limiting connections originating from specific countries

B.

Allowing traffic only from specific countries

C.

Blocking connections from specific countries

D.

Blocking traffic from Russia, China, and North Korea only

Full Access
Question # 19

Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)

A.

Configure a webhook to receive notifications of IP address changes.

B.

Copy the Egress IP API Key in the service infrastructure settings.

C.

Enable the Egress IP API endpoint in Prisma Access.

D.

Download a client certificate to authenticate to the Egress IP API.

Full Access
Question # 20

Which two statements apply when a customer has a large branch office with employees who all arrive and log in within a five-minute time period? (Choose two.)

A.

DNS results are only cached for frequently used hostnames.

B.

Maximum pending TCP DNS requests is 64.

C.

Maximum number of TCP DNS retries is 3.

D.

DNS results are cached for 300 seconds.

Full Access