Practice Free SSE Engineer Exam Online Questions
What is the impact of selecting the “Disable Server Response Inspection” checkbox after confirming that a Security policy rule has a threat protection profile configured?
- A . Only HTTP traffic from the server to the client will bypass threat inspection.
- B . The threat protection profile will override the “Disable Server Response Inspection” only for HTTP traffic from the server to the client.
- C . All traffic from the server to the client will bypass threat inspection.
- D . The threat protection profile will override the “Disable Server Response Inspection” for all traffic from the server to the client.
Secure Inbound Access has been configured to allow access to an RDP application at a branch location, as shown in the image below.

After a successful commit, return traffic from the application is not reaching the internet user.
What is causing the return traffic to fail?
- A . The Remote Network Security policy source zone is configured as "Untrust."
- B . Source NAT is enabled, but the branch location’s CPE does not have a route back to the Service Endpoint Address of the Inbound Access Remote Network Node.
- C . The "Allow inbound flows to other Remote Networks over the Prisma Access backbone" checkbox is selected.
- D . Source NAT is enabled, but the branch location’s CPE does not have a route back to the eBGP Router ID of the Inbound Access Remote Network Node.
Which overlay protocol must a customer premises equipment (CPE) device support when terminating a Partner Interconnect-based Colo-Connect in Prisma Access?
- A . Geneve
- B . IPSec
- C . GRE
- D . DTLS
What will cause a connector to fail to establish a connection with the cloud gateway during the deployment of a new ZTNA Connector in a data center?
- A . There is a misconfiguration in the DNS settings on the connector.
- B . The connector is deployed behind a double NAT.
- C . The connector is using a dynamic IP address.
- D . There is a high latency in the network connection.
An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up.
Which two elements must the engineer validate to solve the issue? (Choose two.)
- A . Secret
- B . MRAI Timers
- C . Peer AS Number
- D . Advertise Default Route Checkbox
What is the flow impact of updating the Cloud Services plugin on existing traffic flows in Prisma Access?
- A . They will experience latency during the plugin upgrade process.
- B . They will automatically terminate when the upgrade begins.
- C . They will be unaffected because the plugin upgrade is transparent to users.
- D . They will be unaffected only if Panorama is deployed in high availability (HA) mode.
After configuring domain-based split tunnel for zoom.us, how is expected behavior on the client machine confirmed?
- A . Verify from the routing table.
- B . Enable dump level logs on Global Protect Application.
- C . Verify zoom.us is resolved by the tunnel assigned DNS server.
- D . Ping zoom.us from the CLI.
How can a network security team be granted full administrative access to a tenant’s configuration while restricting access to other tenants by using role-based access control (RBAC) for Panorama Managed Prisma Access in a multitenant environment?
- A . Create an Access Domain and restrict access to only the Device Groups and Templates for the Target Tenant.
- B . Create a custom role enabling all privileges within the specific tenant’s scope and assign it to the security team’s user accounts.
- C . Create a custom role with Device Group and Template privileges and assign it to the security team’s user accounts.
- D . Set the administrative accounts for the security team to the “Superuser” role.
A network administrator is enabling users, via Prisma Access Browser (PAB), to securely access internal web applications hosted exclusively within the organization’s private data center.
Which two Prisma Access infrastructure components are primarily configured to establish the necessary connection pathways from Prisma Access to these internal data center resources? (Choose two.)
- A . Explicit Proxy
- B . ZTNA Connector
- C . Privileged Remote Access
- D . Service Connection
In addition to creating a Security policy, how can an AI Access Security be used to prevent users from uploading financial information to ChatGPT?
- A . Apply File Blocking to stop file uploads containing financial information.
- B . Configure an Enterprise DLP rule to block uploads containing financial information.
- C . Add the ChatGPT domains using URL Filtering to block uploads containing financial information.
- D . Apply a vulnerability profile to stop attempts to exploit system flaws or gain unauthorized access to financial systems.
