Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Paloalto Networks Network Security Administrator SSE-Engineer Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which two actions can a company with Prisma Access deployed take to use the Egress IP API to automate policy rule updates when the IP addresses used by Prisma Access change? (Choose two.)

Options:

A.

Configure a webhook to receive notifications of IP address changes.


B.

Copy the Egress IP API Key in the service infrastructure settings.


C.

Enable the Egress IP API endpoint in Prisma Access.


D.

Download a client certificate to authenticate to the Egress IP API.


Expert Solution
Questions # 12:

What is the impact of selecting the " Disable Server Response Inspection " checkbox after confirming that a Security policy rule has a threat protection profile configured?

Options:

A.

Only HTTP traffic from the server to the client will bypass threat inspection.


B.

The threat protection profile will override the " Disable Server Response Inspection " only for HTTP traffic from the server to the client.


C.

All traffic from the server to the client will bypass threat inspection.


D.

The threat protection profile will override the " Disable Server Response Inspection " for all traffic from the server to the client.


Expert Solution
Questions # 13:

When using the traffic replication feature in Prisma Access, where is the mirrored traffic directed for analysis?

Options:

A.

Specified internal security appliance


B.

Dedicated cloud storage location


C.

Panorama


D.

Strata Cloud Manager (SCM)


Expert Solution
Questions # 14:

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to their data centers. The solution must meet these requirements: The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations. The branch locations must have internet filtering and data center connectivity. The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports. The security team must have access to manage the mobile user and access to branch locations. The network team must have access to manage only the partner access. How should Prisma Access be implemented to meet the customer requirements?

Options:

A.

Deploy two Prisma Access instances - the first with mobile users, remote networks, and private access for all internal connection types, and the second with remote networks and private application access for B2B connections - and use the Strata Multitenant Cloud Manager Prisma Access configuration scope to manage access.


B.

Deploy a Prisma Access instance with mobile users, remote networks, and private access for all connection types, and use the Prisma Access Configuration scope to manage all access.


C.

Deploy two Prisma Access instances - the first with mobile users, remote networks, and private access for all internal connection types, and the second with remote networks and private application access for B2B connections - and use the specific configuration scope for the connection type to manage access.


D.

Deploy a Prisma Access instance with mobile users, remote networks, and private access for all connection types, and use the specific configuration scope for the connection type to manage access.


Expert Solution
Questions # 15:

Which feature within Strata Cloud Manager (SCM) allows an operations team to view applications, threats, and user insights for branch locations for both NGFW and Prisma Access simultaneously?

Options:

A.

Command Center


B.

Log Viewer


C.

Branch Site Monitor


D.

SASE Health Dashboard


Expert Solution
Questions # 16:

What is the network impact when a Prisma Access service connection is set as a dedicated service connection for traffic steering?

Options:

A.

It maintains its zone as Trust and continues to participate in both internal and external BGP routing.


B.

It changes its zone to Untrust, applies source NAT to forwarded traffic, and no longer participates in BGP routing.


C.

It maintains its zone as Trust; however, it disables all Security policies, allowing unrestricted traffic flow through the dedicated service connection.


D.

It applies destination NAT to forwarded traffic, maintains its BGP routing configurations, and allows traffic from both Trust and Untrust zones.


Expert Solution
Questions # 17:

An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up. Which two elements must the engineer validate to solve the issue? (Choose two.)

Options:

A.

Secret


B.

MRAI Timers


C.

Peer AS Number


D.

Advertise Default Route Checkbox


Expert Solution
Questions # 18:

A large retailer has deployed all of its stores with the same IP address subnet. An engineer is onboarding these stores as Remote Networks in Prisma Access. While onboarding each store, the engineer selects the " Overlapping Subnets " checkbox. Which Remote Network flow is supported after onboarding in this scenario?

Options:

A.

To private applications


B.

To the internet


C.

To remote network


D.

To mobile users


Expert Solution
Questions # 19:

An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Options:

A.

The rule was created with improper threat management settings.


B.

The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.


C.

The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.


D.

The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.


Expert Solution
Questions # 20:

In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?

Options:

A.

Apply File Blocking to stop file uploads containing financial information.


B.

Configure an Enterprise DLP rule to block uploads containing financial information.


C.

Add the ChatGPT domains using URL Filtering to block uploads containing financial information.


D.

Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions