Exit demo PAN-SSEE Palo Alto Networks Security Service Edge Engineer PDF format · free preview

Palo Alto Networks PAN-SSEE - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pan-ssee.html

Question 1
Multiple choice

Based on the image below, which two statements describe the reason and action required to resolve the errors? (Choose two.)

A.

The client is misconfigured.

B.

Create a do not decrypt rule for the hostname "google.com."

C.

The server has pinned certificates.

D.

Create a do not decrypt rule for the hostname "certificates.godaddy.com."

Question 2
Single choice

Strata Logging Service is configured to forward logs to an external syslog server; however, a month later,
there is a disruption on the syslog server.

Which action will send the missing logs to the external syslog server?

A.

Configure a replay profile with the affected time range and associate it with the affected syslog server profile.

B.

Delete the affected syslog server profile and create a new one.

C.

Export the logs from Strata Logging Service, and then manually import them to the syslog server.

D.

Configure a log filter under the syslog server profile with the affected time range.

Question 3
Single choice

How can role-based access control (RBAC) for Prisma Access (Managed by Strata Cloud Manager) be used to grant each member of a security team full administrative access to manage the Security policy in a single tenant while restricting access to other tenants in a multitenant deployment?

A.

Add the team to the Parent Tenant, select the Prisma Access Configuration Scope, and set the role to Security Administrator.

B.

Add the team to the Child Tenant, select All Apps & Services, and set the role to Security Administrator.

C.

Add the team to the Parent Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

D.

Add the team to the Child Tenant, select Prisma Access & NGFW Configuration, and set the role to Security Administrator.

Question 4
Single choice

How can a network security team be granted full administrative access to a tenant's configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?

A.

Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.

B.

Create a custom role enabling all privileges within the specific tenant's scope and assign it to the
security team's user accounts.

C.

Create a custom role with Device Group and Template privileges and assign it to the security team's user accounts.

D.

Set the administrative accounts for the security team to the "Superuser" role.

Question 5
Single choice

When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?

A.

A URL access management profile with site access set to "Isolate" applied to a Security policy

B.

A DNS Security profile applied to a Security policy with the action of "Isolate" for the target remote browser DNS categories

C.

An RBI profile applied to the URL access management profile

D.

A Security policy with the target URL categories and set the action to "Isolate"

Question 6
Single choice

A company has four branch offices between Canada Central and Canada East which use the same IPSec termination node and have QoS configured with customized bandwidth per site. An engineer wants to onboard a new branch office on the same IPSec termination node.

What is the QoS behavior for the new branch office?

A.

Automatically distributed to 25% for each site

B.

Unallocated until manually assigned

C.

Automatically distributed to 20% for each site

D.

Cannot be added to existing QoS configuration

Question 7
Single choice

In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?

A.

LDAP

B.

Kerberos

C.

SAML

D.

SSO

Question 8
Single choice

Which statement is valid in relation to certificates used for GlobalProtect and pre-logon?

A.

A public certificate authority (CA) must sign and validate all certificates used.

B.

The certificate used for pre-logon must include both Subject and Subject-Alt fields.

C.

Certificates must be deployed in the Machine Certificate Store.

D.

The GlobalProtect agent may be used to distribute pre-logon certificates.

Question 9
Single choice

What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?

A.

There is a misconfiguration in the DNS settings on the connector.

B.

The connector is deployed behind a double NAT.

C.

The connector is using a dynamic IP address.

D.

There is a high latency in the network connection.

Question 10
Multiple choice

Which two configurations must be enabled to allow App Acceleration for SaaS applications? (Choose two.)

A.

Acceleration agent for the client machines

B.

QoS for user traffic

C.

Trusted Root CA for the CA certificate

D.

Forward Trust Certificate for the CA certificate

Showing 10 of 65 questions · Unlock the full set