10 free Palo Alto Networks Security Service Edge Engineer practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 68 questions. Work through them, then open each answer to check your reasoning.
Get all 68 questions (US$39) · Download these 10 as a PDF
Question 1
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
How should Prisma Access be implemented to meet the customer requirements?
Show answer and explanation
Correct answer: D. Deploy a Prisma Access instance with mobile users, remote networks, and private access for all connection types, and use the specific configuration scope for the connection type to manage access.
A single Prisma Access instance can support all three connection types (mobile users, remote networks, and private access) simultaneously. Using specific configuration scopes for each connection type allows granular access control, enabling the security team to manage mobile users and remote networks while the network team manages only partner access through private application access scopes. This meets all requirements with one deployment rather than unnecessarily splitting into two instances.
Why the other options are wrong
- A. Deploying two instances is unnecessary when one instance with properly configured scopes can meet all requirements.
- B. The Prisma Access Configuration scope is too broad and does not provide the granular access control needed to separate security team and network team permissions.
- C. Deploying two instances adds complexity and operational overhead that is not required by the stated requirements.
Question 2
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
How can the engineer configure mobile users and branch locations to meet the requirements?
Show answer and explanation
Correct answer: A. Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.
GlobalProtect is the appropriate technology for mobile users requiring internet filtering and data center connectivity. Remote Networks is the appropriate technology for branch locations (static sites) requiring the same capabilities. Together, they provide internet filtering via Prisma Access and data center connectivity through service connections. Explicit Proxy is not needed since GlobalProtect and Remote Networks provide the required functionality.
Why the other options are wrong
- B. Explicit Proxy is used for traffic inspection and filtering but does not provide the sit-o-site connectivity required for branch locations.
- C. GlobalProtect alone does not support branch location connectivity; Remote Networks is required for static branch site connectivity.
- D. Explicit Proxy is not needed when GlobalProtect and Remote Networks together provide all required capabilities.
Question 3
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
Which two options will allow the engineer to support the requirements? (Choose two.)
Show answer and explanation
Correct answer: B, C
B. Enable eBGP for dynamic routing and configure RemoteNetworks. C. Configure Remote Networks and define the branch IP subnets using Static Routes. Remote Networks with eBGP enables dynamic routing for branch locations, allowing automatic route updates as network topology changes. This is more scalable than static routes. Alternatively, Remote Networks with Static Routes explicitly defining branch IP subnets provides a simpler, deterministic approach for customers who prefer manual control. Both options leverage Remote Networks to establish the site-to-site connectivity required. eBGP provides automation while Static Routes provides manual control, both are valid architectural choices.
Why the other options are wrong
- A. Configuring static routes on the CPE alone does not establish the managed site-t-ite connectivity provided by Remote Networks.
- D. Enabling Advertise Default Route on Remote Networks is used for internet egress scenarios, not for establishing branch-to-data-center connectivity.
Question 4
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)
Show answer and explanation
Correct answer: A, C
A. ZTNA Connector C. Service connections Service connections are the primary Prisma Access component for establishing secure connectivity from mobile users and branch locations to data center resources. ZTNA Connector (Zero Trust Network Access) is used to publish and provide access to internal applications, supporting the requirement for B2B partner access to specific data center applications. Together, these enable data center connectivity over the internet for all user types.
Why the other options are wrong
- B. SD-WAN Connector is not a Prisma Access component for data center connectivity; it is for hybrid SD-WAN deployments.
- D. Colo-Connect is not a standard Prisma Access component for enabling data center connectivity.
Question 5
Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)
Show answer and explanation
Correct answer: A, B
A. Configure a webhook to receive notifications of IP address changes. B. Copy the Egress IP API Key in the service infrastructure settings. To automate policy rule updates when Prisma Access egress IPs change, a webhook must be configured to receive notifications of IP address changes, triggering automated policy updates. The Egress IP API Key must be copied from the service infrastructure settings to authenticate API requests. These two actions work together to enable full automation of IP address management.
Why the other options are wrong
- C. The Egress IP API endpoint is always available in Prisma Access and does not require explicit enablement.
- D. Client certificates are not the authentication method for Egress IP API; API keys are used for authentication.
Question 6
How can an engineer verify that only the intended changes will be applied when modifying Prisma Access policy configuration in Strata Cloud Manager (SCM)?
Show answer and explanation
Correct answer: B. Compare the candidate configuration and the most recent version under “Config Version Snapshots.”
Config Version Snapshots in SCM allow engineers to compare the candidate configuration against the most recent deployed version. This provides a clear, detailed view of all pending changes before they are pushed to Prisma Access, enabling verification that only intended modifications will be applied.
Why the other options are wrong
- A. Blue circular indicators in the SCM portal indicate areas with uncommitted changes but do not provide a detailed comparison of what will be pushed.
- C. Push Status shows completed jobs, not pending changes that would be applied in the next push.
- D. While a push dialogue may show some information, Config Version Snapshots provide the most comprehensive comparison of candidate versus deployed configuration.
Question 7
When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?
Show answer and explanation
Correct answer: B. Dedicated cloud storage location
When using traffic replication in Prisma Access, mirrored traffic is directed to dedicated cloud storage locations where it can be analyzed, retained, and accessed for security investigations and forensic analysis.
Why the other options are wrong
- A. Internal security appliances are not the destination for Prisma Access traffic replication.
- C. Panorama is not used as a destination for Prisma Access traffic replication.
- D. SCM is the management interface but not the destination for mirrored traffic analysis.
Question 8
When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by showing only unique devices?
Show answer and explanation
Correct answer: B. Merge individual devices into a single device with multiple interfaces.
When network devices like routers appear multiple times with different IP addresses (e.g., management IP, data plane IP), merging individual devices into a single device with multiple interfaces resolves the duplication issue by consolidating the logical device while preserving the multiple network identities it uses.
Why the other options are wrong
- A. Adding duplicates to an ignore list hides the problem rather than resolving it, leaving duplicate entries in the inventory.
- C. Custom roles are for access control and permissions, not for consolidating duplicate device entries.
- D. Deleting duplicate entries loses network visibility and data, whereas merging preserves all interface information.
Question 9
What is the impact of selecting the “Disable Server Response Inspection” checkbox after confirming that a Security policy rule has a threat protection profile configured?
Show answer and explanation
Correct answer: C. All traffic from the server to the client will bypass threat inspection.
When the 'Disable Server Response Inspection' checkbox is selected in a security policy rule, all traffic from the server to the client bypasses threat inspection. This setting disables the inspection of server responses completely, regardless of the type of traffic or protocol being used. The directive applies broadly to prevent the security appliance from analyzing return traffic from the server.
Why the other options are wrong
- A. This incorrectly limits the bypass to only HTTP traffic when the setting applies to all server response traffic.
- B. This suggests the threat protection profile would override the disable setting, which contradicts how the setting functions when explicitly configured.
- D. While close to the correct answer, this incorrectly suggests that the threat protection profile can override the disable setting, when in fact the disable setting takes effect as configured.
Question 10
A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links.
With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?
Show answer and explanation
Correct answer: B. Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.
In a multitenant Prisma Access deployment with service connections in different regions, filtering out mobile user pool prefixes from other regions in BGP advertisements ensures traffic routes through the appropriate regional service connection. Each service connection should filter advertisements to prevent traffic from being directed to the wrong region, ensuring users connect through their local region's service connection rather than traversing unnecessary private links.
Why the other options are wrong
- A. Community string attributes are not the standard BGP mechanism for preference in this context; MED or prefix filtering is more appropriate for regional routing control.
- C. While MED can influence BGP path selection, it is not the primary verification method for ensuring traffic routes through the correct regional service connection.
- D. ASN prepending would deprioritize routes rather than ensure proper regional delivery, and five prepends is excessive for this use case.
That was 10 of 68.
The full Palo Alto Networks Security Service Edge Engineer pack has all 68 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
