Pass the Paloalto Networks Network Security Administrator SSE-Engineer Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

During a deployment of Prisma Access (Managed by Strata Cloud Manager) for mobile users, a SAML authentication type and authentication profile in the Cloud Identity Engine application is successfully created.

Using this SAML authentication, what is a valid next step to configure authentication for mobile users?

Options:

A.

Perform a full commit to Strata Cloud Manager so the Cloud Identity Engine profiles get synchronized from the application.


B.

Permit the Cloud Identity Engine service account RBAC access to the mobile user folder in Strata Cloud Manager.


C.

In Strata Cloud Manager, create a new authentication type of “Cloud Identity Engine.”


D.

Create a SAML authentication profile in Strata Cloud Manager and link it to the Cloud Identity Engine profile.


Questions # 12:

An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up.

Which two elements must the engineer validate to solve the issue? (Choose two.)

Options:

A.

Secret


B.

MRAI Timers


C.

Peer AS Number


D.

Advertise Default Route Checkbox


Questions # 13:

A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers.

The solution must meet these requirements:

The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.

The branch locations must have internet filtering and data center connectivity.

The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.

The security team must have access to manage the mobile user and access to branch locations.

The network team must have access to manage only the partner access.

How can the engineer configure mobile users and branch locations to meet the requirements?

Options:

A.

Use GlobalProtect and Remote Networks to filter internet traffic and provide access to data center resources using service connections.


B.

Use Explicit Proxy to filter internet traffic and provide access to data center resources using service connections.


C.

Use GlobalProtect to filter internet traffic and provide access to data center resources using service connections.


D.

Use Explicit Proxy and Remote Networks to filter internet traffic and provide access to data center resources using service connections.


Questions # 14:

After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?

Options:

A.

Verify from the routing table.


B.

Enable dump level logs on GlobalProtect Application.


C.

Verify zoom.us is resolved by the tunnel assigned DNS server.


D.

Ping zoom.us from the CLI.


Questions # 15:

An intern is tasked with changing the Anti-Spyware Profile used for security rules defined in the GlobalProtect folder. All security rules are using the Default Prisma Profile. The intern reports that the options are greyed out and cannot be modified when selecting the Default Prisma Profile.

Based on the image below, which action will allow the intern to make the required modifications?

Question # 15

Options:

A.

Request edit access for the GlobalProtect scope.


B.

Change the configuration scope to Prisma Access and modify the profile group.


C.

Create a new profile, because default profile groups cannot be modified.


D.

Modify the existing anti-spyware profile, because best-practice profiles cannot be removed from a group.


Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions