Practice Free SSE Engineer Exam Online Questions
In an Explicit Proxy deployment where no agent can be used on the endpoint, which authentication method is supported with mobile users?
- A . LDAP
- B . Kerberos
- C . SAMLD. SSO
How can the Prisma Access Browser (PAB) Extension extend an organization’s web security posture to managed devices that are not connected to a VPN for browser-based access to company-sanctioned web applications?
- A . It enforces consistent web access and data control policies directly within the browser, regardless of device management status.
- B . It tunnels all endpoint traffic on unmanaged devices, ensuring all device traffic is secured.
- C . It incorporates remote browser isolation (RBI) for the endpoint, running web sessions in a contained environment on any browser.
- D . It optimizes network performance for browser traffic to Prisma Access for all operating systems and browsers.
A company has a Prisma Access deployment for mobile users in North America and Europe. Service connections are deployed to the data centers on these continents, and the data centers are connected by private links.
With default routing mode, which action will verify that traffic being delivered to mobile users traverses the service connection in the appropriate regions?
- A . Configure BGP on the customer premises equipment (CPE) to prefer the assigned community string attribute on the mobile user prefixes in its respective Prisma Access region.
- B . Configure each service connection to filter out the mobile user pool prefixes from the other region in the advertisements to the data center.
- C . Configure BGP on the customer premises equipment (CPE) to prefer the MED attribute on the mobile user prefixes in its respective Prisma Access region.
- D . Configure each service connection to prepend the BGP ASN five times for mobile user pool prefixes originating from the other region.
How can an engineer use risk score customization in SaaS Security Inline to limit the use of unsanctioned SaaS applications by employees within a Security policy?
- A . Lower the risk score of sanctioned applications and increase the risk score for unsanctioned applications.
- B . Increase the risk score for all SaaS applications to automatically block unwanted applications.
- C . Build an application filter using unsanctioned SaaS as the category.
- D . Build an application filter using unsanctioned SaaS as the characteristic.
An intern is tasked with changing the Anti-Spyware Profile used for security rules defined in the Global Protect folder. All security rules are using the Default Prisma Profile. The intern reports that the options are greyed out and cannot be modified when selecting the Default Prisma Profile.

Based on the image below, which action will allow the intern to make the required modifications?
- A . Request edit access for the Global Protect scope.
- B . Change the configuration scope to Prisma Access and modify the profile group.
- C . Create a new profile, because default profile groups cannot be modified.
- D . Modify the existing anti-spyware profile, because best-practice profiles cannot be removed from a group.
An administrator is configuring a dedicated visitor sign-in kiosk in the main corporate office using Prisma Access Browser (PAB). A key security requirement is to ensure the device is locked down, which includes preventing users from creating paper copies of any on-screen information. The policy must specifically apply to this fixed-location kiosk.
Which two PAB match criteria will enforce these restrictions on the kiosk? (Choose two.)
- A . Configuring the print control as the specific data control for the rule
- B . Configuring the kiosk control, which prevents printing
- C . Defining the policy scope based on location, specifying the location of the corporate offices
- D . Defining the policy scope based on networks, specifying the corporate public IP range or CIDR
An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications.
What is a reason for this issue?
- A . The rule was created with improper threat management settings.
- B . The rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.
- C . The rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.
- D . The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
Which two options will allow the engineer to support the requirements? (Choose two.)
- A . Configure the CPE with Static Routes pointing to Prisma Access Infrastructure and Mobile User routes.
- B . Enable eBGP for dynamic routing and configure RemoteNetworks.
- C . Configure Remote Networks and define the branch IP subnets using Static Routes.
- D . Enable Remote Networks Advertise Default Route.
An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope.
After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy.
Which statement explains the branch traffic behavior?
- A . The source address was configured with an address object including the branch location prefixes.
- B . The source zone was configured as “Trust.”
- C . The Security policy did not meet best practice standards and was automatically removed.
- D . The traffic is matching a Security policy in the Prisma Access configuration scope.
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to- business (B2B) partners to their data centers.
The solution must meet these requirements:
The mobile users must have internet filtering, data center connectivity, and remote site connectivity to the branch locations.
The branch locations must have internet filtering and data center connectivity.
The B2B partner connections must only have access to specific data center internally developed applications running on non-standard ports.
The security team must have access to manage the mobile user and access to branch locations.
The network team must have access to manage only the partner access.
Which two components can be provisioned to enable data center connectivity over the internet? (Choose two.)
- A . ZTNA Connector
- B . SD-WAN Connector
- C . Service connections
- D . Colo-Connect
