Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator SSE-Engineer Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

How can an engineer use risk score customization in SaaS Security Inline to limit the use of unsanctioned SaaS applications by employees within a Security policy?

Options:

A.

Lower the risk score of sanctioned applications and increase the risk score for unsanctioned applications.


B.

Increase the risk score for all SaaS applications to automatically block unwanted applications.


C.

Build an application filter using unsanctioned SaaS as the category.


D.

Build an application filter using unsanctioned SaaS as the characteristic.


Expert Solution
Questions # 2:

All mobile users are unable to authenticate to Prisma Access (Managed by Strata Cloud Manager) using SAML authentication through the Cloud Identity Engine. Users report that after entering their credentials on the Identity Provider (IdP) login page, they are redirected to the Prisma Access portal without successful authentication, and they receive this error message: Error: Prisma Access Portal Authentication Failed using CIE-SAML with message " 400 Bad Request " . Which action will identify the root cause of this error? URLs and certificates are correctly configured.

Options:

A.

Verify the SAML metadata configuration in both Strata Cloud Manager and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.


B.

Examine the Security policy rules in Prisma Access to ensure that traffic from the IdP is allowed and not blocked.


C.

Verify the SAML metadata configuration in both the Cloud Identity Engine and the IdP portal to confirm that the endpoint URLs and certificates are correctly configured.


D.

Review the Authentication logs in Strata Cloud Manager to check for any SAML error messages or authentication failures.


Expert Solution
Questions # 3:

How can an engineer verify that only the intended changes will be applied when modifying Prisma Access policy configuration in Strata Cloud Manager (SCM)?

Options:

A.

Review the SCM portal for blue circular indicators next to each configuration menu item and ensure only the intended areas of configuration have this indicator.


B.

Compare the candidate configuration and the most recent version under " Config Version Snapshots. "


C.

Select the most recent job under Operations > Push Status to view the pending changes that would apply to Prisma Access.


D.

Open the push dialogue in SCM to preview all changes which would be pushed to Prisma Access.


Expert Solution
Questions # 4:

In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?

Options:

A.

LDAP


B.

Kerberos


C.

SAML


D.

SSO


Expert Solution
Questions # 5:

An engineer configures User-ID redistribution from an on-premises firewall connected to Prisma Access (Managed by Panorama) using a service connection. After committing the configuration, traffic from remote network connections is still not matching the correct user-based policies. Which two configurations need to be validated? (Choose two.)

Options:

A.

Ensure the Remote_Network_Template is selected when adding the User-ID Agent in Panorama.


B.

Confirm there is a Security policy configured in Prisma Access to allow the communication on port 5007.


C.

Confirm the Collector Pre-Shared Keys match between Prisma Access and the on-premises firewall.


D.

Ensure the Service_Conn_Template is selected when adding the User-ID Agent in Panorama.


Expert Solution
Questions # 6:

A company is migrating from NGFW-hosted Global Protect to Prisma Access Mobile Users. The authentication method will change from LDAP with Windows Active Directory Domain Controllers to SAML with Microsoft Entra ID. After configuring and applying the SAML Authentication Profile to the Mobile Users configuration, the migrated group-based Security policies are no longer functioning. Which User-ID setting must be updated for the group-based Security policies to begin functioning?

Options:

A.

Configure a redistribution profile to send user-to-group mapping from the Global Protect firewalls to Prisma Access.


B.

Migrate group mapping to Cloud Identity Engine using an agent to query the Windows Active Directory Domain Controllers.


C.

Modify the group mapping settings by updating the User Attributes to include " userPrincipalName. "


D.

Change the SAML Authentication profile Username Modifier to %USERDOMAIN%\%USERINPUT%.


Expert Solution
Questions # 7:

When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?

Options:

A.

A URL access management profile with site access set to " Isolate " applied to a Security policy


B.

A DNS Security profile applied to a Security policy with the action of " Isolate " for the target remote browser DNS categories


C.

An RBI profile applied to the URL access management profile


D.

A Security policy with the target URL categories and set the action to " Isolate "


Expert Solution
Questions # 8:

A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?

Options:

A.

Advanced Threat Prevention option to block " Domain Fronting "


B.

Advanced URL Filtering and block the " Malicious Behavior " category


C.

Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "


D.

SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "


Expert Solution
Questions # 9:

Which statement is valid in relation to certificates used for Global Protect and pre-logon?

Options:

A.

A public certificate authority (CA) must sign and validate all certificates used.


B.

The certificate used for pre-logon must include both Subject and Subject-Alt fields.


C.

Certificates must be deployed in the Machine Certificate Store.


D.

The Global Protect agent may be used to distribute pre-logon certificates.


Expert Solution
Questions # 10:

An engineer deploys a new branch connected to Prisma Access. From the customer premises equipment (CPE) device at the branch, Phase 1 on the tunnel is established, but Phase 2-encrypted packets are not coming back from Prisma Access. Which Strata Logging Service log facility should the engineer review to determine why Phase 2-encrypted traffic is not being received?

Options:

A.

Decrypt logs


B.

System logs


C.

Traffic logs


D.

Tunnel logs


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions