sse-engineer Sample Questions

sse-engineer Sample Questions & Answers

Expect questions on three tied leaders: Prisma Access's own architecture and routing, advanced data security features, and the Prisma Access Browser, plus logging, troubleshooting connectivity, and managing Prisma Access through Panorama and Strata Cloud Manager.

Launch the full sse-engineer simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Prisma Access Planning and Deployment · Configure, implement, and deploy Prisma Access for remote networks

    A retail company is onboarding 500 branch locations as remote networks into Prisma Access. The network team wants to use dynamic routing to advertise the branch subnets and receive routes from the data center. Each branch has a single CPE device. What is the most scalable and efficient method to configure routing for these remote networks?

    Show answer & explanation

    Correct answer: C

    For dynamic routing with remote networks, the standard and scalable method is to establish an eBGP peering session over the IPSec tunnel. This allows the branch CPE to advertise its local subnets to Prisma Access and learn routes from the rest of the SASE fabric (like data center subnets learned via service connections) automatically. Static routing is not scalable for 500 sites. iBGP is typically used within the same autonomous system, whereas eBGP is correct for peering between the customer site and Prisma Access.

  2. Question 2Intermediate

    Prisma Access Administration and Operation · Maintain security posture in Prisma Access

    An administrator is using the Best Practice Assessment (BPA) tool within Strata Cloud Manager to evaluate their Prisma Access configuration. The BPA report indicates a failing check related to 'Decryption Profile with no-decrypt action'. What is the most likely reason for this failing check and the recommended remediation?

    Show answer & explanation

    Correct answer: B

    The Best Practice Assessment (BPA) tool flags configurations that deviate from recommended security postures. A decryption profile set to 'no decrypt' and applied to a security policy means that encrypted traffic matching that rule is not being inspected for threats. This significantly reduces security visibility. The best practice is to enable SSL Forward Proxy decryption to inspect outbound SSL/TLS traffic for threats.

  3. Question 3IntermediateSelect 2

    Prisma Access Planning and Deployment · Configure and implement identity authentication within Prisma Access

    An SSE engineer needs to configure Prisma Access to authenticate mobile users based on their membership in specific Active Directory groups. The organization uses Azure AD as its identity provider and has synchronized its on-premises AD. Which Prisma Access component is essential for retrieving user and group information from Azure AD to enforce user-based policies? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    The Cloud Identity Engine is the component that integrates with cloud-based identity providers like Azure AD to pull user and group mapping information. SAML is the protocol used for the authentication and authorization exchange with the IdP.

    The Cloud Identity Engine is the component that integrates with cloud-based identity providers like Azure AD to pull user and group mapping information. SAML is the protocol used for the authentication and authorization exchange with the IdP.

  4. Question 4Intermediate

    Prisma Access Services · Configure and implement Prisma Access data security services

    A security team is concerned about employees using unsanctioned generative AI services, which could lead to sensitive data exposure. They want to allow access to their corporate-sanctioned AI tool but block all others, while also logging all prompts sent to the sanctioned tool. Which Prisma Access service is specifically designed to meet these requirements?

    Show answer & explanation

    Correct answer: B

    AI Access Security is the purpose-built service within Prisma Access for discovering, securing, and controlling the use of generative AI applications. It can identify hundreds of AI tools, allow administrators to set granular policies (e.g., allow/block specific tools, control data uploads, log prompts), and prevent data leakage, directly addressing all the stated requirements.

  5. Question 5Intermediate

    Prisma Access Troubleshooting · Monitor and troubleshoot Prisma Access connectivity

    A user reports intermittent connectivity issues when connected to Prisma Access via the GlobalProtect client. The help desk has verified the user has a stable internet connection. As a troubleshooting step, the SSE engineer wants to analyze the traffic flow from the user's endpoint through the Prisma Access infrastructure. Which tool within Strata Cloud Manager provides detailed, hop-by-hop visibility and performance metrics for a user's connection to a specific application?

    Show answer & explanation

    Correct answer: C

    Autonomous Digital Experience Management (ADEM) is the service that provides detailed visibility into the user's digital experience. It can trace the path from the user's endpoint, across their local network, the internet, and the Prisma Access infrastructure all the way to the application. It provides performance metrics for each segment, making it the ideal tool for diagnosing intermittent connectivity and performance issues.

  6. Question 6Advanced

    Prisma Access Planning and Deployment · Identify and describe Prisma Access architecture and components

    Case Study:

    A global logistics company, "ShipFast," is modernizing its network security by migrating to Prisma Access managed by Strata Cloud Manager. The company has a central headquarters (HQ), two large regional data centers (US and APAC), and 300 small branch offices worldwide. A significant portion of its workforce consists of mobile users who need access to both cloud applications (SaaS) and internal logistics software hosted in the data centers.

    Current Situation:
    The branch offices connect to the data centers via MPLS links, which are becoming costly and inflexible. Mobile users connect using a legacy VPN solution that backhauls all traffic through the HQ, causing high latency for SaaS applications. The IT team is split into a Network team, responsible for connectivity, and a Security team, responsible for policy.

    Requirements:

    1. Replace MPLS with a more agile internet-based WAN for branch offices.
    2. Provide optimized, low-latency access to SaaS applications for all users.
    3. Implement Zero Trust access to internal applications hosted in the data centers.
    4. Enable role-based access control (RBAC) in Strata Cloud Manager to allow the Network team to manage remote network onboarding and the Security team to manage security policies, without overlap.
    5. Ensure high availability for data center connectivity.

    Which combination of Prisma Access components and configurations best fulfills all of ShipFast's requirements?

    Show answer & explanation

    Correct answer: C

    This option correctly addresses all requirements. BGP for remote networks replaces MPLS with a scalable dynamic routing solution. Redundant service connections provide high availability. ZTNA Connectors implement the Zero Trust model for internal apps. GlobalProtect serves mobile users, and with Prisma Access, SaaS traffic is optimized by default. Critically, custom RBAC roles in SCM fulfill the requirement for segregated administrative duties.

  7. Question 7Beginner

    Prisma Access Planning and Deployment · Identify and describe Prisma Access architecture and components

    What is the primary function of the 'Compute Location' in the Prisma Access architecture?

    Show answer & explanation

    Correct answer: C

    A compute location is a specific geographic region (e.g., US East, Germany Central) where Palo Alto Networks has deployed the infrastructure, including Security Processing Nodes (SPNs) and gateways, that process and secure customer traffic. Administrators select these locations when onboarding users and sites to ensure optimal performance and data residency.

  8. Question 8Advanced

    Prisma Access Troubleshooting · Troubleshoot Prisma Access traffic enforcement issues

    A user with the GlobalProtect client is configured for split tunneling based on the 'Include Domain/Application' method. The include list contains 'salesforce.com'. The user attempts to access 'status.salesforce.com'. Will the traffic for 'status.salesforce.com' be sent through the Prisma Access tunnel?

    Show answer & explanation

    Correct answer: A

    When using domain-based split tunneling in GlobalProtect, including a parent domain (e.g., 'salesforce.com') will also include all its subdomains (e.g., 'status.salesforce.com', 'help.salesforce.com'). Therefore, the traffic will be captured and sent through the Prisma Access tunnel for security inspection.

  9. Question 9Intermediate

    Prisma Access Services · Configure and implement advanced Prisma Access features and services

    An administrator needs to provide temporary, privileged access for an external vendor to a specific server in their data center. The security policy requires that the entire session be recorded for auditing. Which Prisma Access feature is best suited for this requirement?

    Show answer & explanation

    Correct answer: C

    Privileged Remote Access is the Prisma Access feature designed specifically for securing, controlling, and auditing access for privileged users like vendors or administrators. It provides capabilities such as session recording, credential vaulting, and just-in-time access, which directly meet the scenario's auditing and temporary access requirements.

  10. Question 10BeginnerSelect 2

    Prisma Access Planning and Deployment · Configure and deploy Prisma Access for mobile users

    Which of the following are valid methods for onboarding mobile users to Prisma Access? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    Prisma Access supports onboarding mobile users via the GlobalProtect VPN client for full device-level protection and Explicit Proxy for browser-based traffic from devices that can be configured to use a proxy.

    Prisma Access supports onboarding mobile users via the GlobalProtect VPN client for full device-level protection and Explicit Proxy for browser-based traffic from devices that can be configured to use a proxy.

Ready for the real thing?

The full sse-engineer simulator has every exam-style question, timed mode, and instant scoring.