Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

SSE-Engineer Palo Alto Networks Security Service Edge Engineer Questions and Answers

Questions 4

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Options:

A.

The rule was created with improper threat management settings.

B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.

C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.

D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.

Buy Now
Questions 5

What is the impact of selecting the " Disable Server Response Inspection " checkbox after confirming that a Security policy rule has a threat protection profile configured?

Options:

A.

Only HTTP traffic from the server to the client will bypass threat inspection.

B.

The threat protection profile will override the " Disable Server Response Inspection " only for HTTP traffic from the server to the client.

C.

All traffic from the server to the client will bypass threat inspection.

D.

The threat protection profile will override the " Disable Server Response Inspection " for all traffic from the server to the client.

Buy Now

SSE-Engineer Report Card

Questions 6

Which two statements apply when a customer has a large branch office with employees who all arrive and log in within a five-minute time period? (Choose two.)

Options:

A.

DNS results are only cached for frequently used hostnames.

B.

Maximum pending TCP DNS requests is 64.

C.

Maximum number of TCP DNS retries is 3.

D.

DNS results are cached for 300 seconds.

Buy Now
Questions 7

What is the purpose of embargo rules in Prisma Access?

Options:

A.

Rate-limiting connections originating from specific countries

B.

Allowing traffic only from specific countries

C.

Blocking connections from specific countries

D.

Blocking traffic from Russia, China, and North Korea only

Buy Now
Questions 8

How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage the Security policy in a single tenant while restricting access to other tenants in a multitenant deployment?

Options:

A.

Add the team to the Parent Tenant, select the Prisma Access Configuration Scope, and set the role to Security Administrator.

B.

Add the team to the Child Tenant, select All Apps & Services, and set the role to Security Administrator.

C.

Add the team to the Parent Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

D.

Add the team to the Child Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

Buy Now
Questions 9

How can a network security team be granted full administrative access to a tenant ' s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

Options:

A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant ' s scope and assign it to the security team ' s user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team ' s user accounts.

D.

Set the administrative accounts for the security team to the " Superuser " role.

Buy Now
Questions 10

Which feature can help address a customer concern about the length of time it takes to update their SaaS-allowed IP addresses while onboarding to Prisma Access?

Options:

A.

Dynamic IP pooling

B.

DNS-based load balancing

C.

Traffic steering

D.

Dedicated IP addresses

Buy Now
Questions 11

Which statement applies when enabling multitenancy in Prisma Access (Managed by Panorama)?

Options:

A.

Service connection licenses will be assigned only to the first tenant, and these service connections can be shared with the other tenants.

B.

A single tenant cannot consist solely of mobile users or solely of remote networks.

C.

Each tenant is allocated its own dedicated Prisma Access instances, with compute resources that are not shared across tenants.

D.

There is flexibility to manage different tenants using separate Panoramas, which allows for better organization and management of the multiple tenants.

Buy Now
Questions 12

An engineer deploys a new branch connected to Prisma Access. From the customer premises equipment (CPE) device at the branch, Phase 1 on the tunnel is established, but Phase 2-encrypted packets are not coming back from Prisma Access. Which Strata Logging Service log facility should the engineer review to determine why Phase 2-encrypted traffic is not being received?

Options:

A.

Decrypt logs

B.

System logs

C.

Traffic logs

D.

Tunnel logs

Buy Now
Questions 13

Which Cloud Identity Engine capability will create a Security policy that uses Entra ID attributes as the source identification?

Options:

A.

Entra ID Group Attribute

B.

Attribute Group Mapping

C.

Entra ID Cloud Group

D.

Cloud Dynamic User Group

Buy Now
Questions 14

An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy. Which statement explains the branch traffic behavior?

Options:

A.

The source address was configured with an address object including the branch location prefixes.

B.

The source zone was configured as " Trust. "

C.

The Security policy did not meet best practice standards and was automatically removed.

D.

The traffic is matching a Security policy in the Prisma Access configuration scope.

Buy Now
Questions 15

Which configuration change will allow an organization using Prisma Access (Managed by Panorama) to minimize the consumption of Strata Logging Service storage due to a high volume of asymmetric traffic flows on its data center?

Options:

A.

Configure a log forwarding profile on the service connection to filter out asymmetric traffic.

B.

Disable traffic logging on the service connection.

C.

Disable the log forwarding profile for the service connection.

D.

Reduce the log retention period for Strata Logging Service.

Buy Now
Questions 16

An engineer has configured IPSec tunnels for two remote network locations; however, users are experiencing intermittent connectivity issues across the tunnels. What action will allow the engineer to receive notifications when the IPSec tunnels are down or experiencing instability?

Options:

A.

Create a new notification profile specifying conditions for remote network IPSec tunnel conditions.

B.

Create a tunnel log notification rule to alert on specified remote network IPSec tunnel conditions.

C.

Set up the operational health dashboard to email alerts for remote Network IPSec tunnel issues.

D.

Select the IPSec tunnel monitoring and notifications checkbox when configuring the remote network IPSec tunnels.

Buy Now
Questions 17

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Options:

A.

Verify from the routing table.

B.

Enable dump level logs on Global Protect Application.

C.

Verify zoom.us is resolved by the tunnel assigned DNS server.

D.

Ping zoom.us from the CLI.

Buy Now
Questions 18

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

Options:

A.

There is a misconfiguration in the DNS settings on the connector.

B.

The connector is deployed behind a double NAT.

C.

The connector is using a dynamic IP address.

D.

There is a high latency in the network connection.

Buy Now
Questions 19

Which feature will fetch user and group information to verify whether a group from the Cloud Identity Engine is present on a security processing node (SPN)?

Options:

A.

SASE Health Dashboard

B.

User Activity Insights

C.

Prisma Access Locations

D.

Region Activity Insights

Buy Now
Questions 20

A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access. What are two reasons for this behavior? (Choose two.)

Options:

A.

" Collect HIP data " needs to be enabled in the configuration.

B.

User mapping is learned from sources other than gateway authentication.

C.

Firewall loses user mapping due to missed HIP report checks.

D.

HIP-enforced policy is scheduled for certain hours of the day.

Buy Now
Exam Code: SSE-Engineer
Exam Name: Palo Alto Networks Security Service Edge Engineer
Last Update: Aug 21, 2026
Questions: 73

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now SSE-Engineer testing engine

PDF (Q&A)

$31.5  $104.99
buy now SSE-Engineer pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 21 Aug 2026