最新版を今すぐ試そう![2026年10月] 試験準備には欠かさない!SSE-Engineer問題集
有能な受験者がシミュレーション済みのSSE-Engineer試験PDF問題を試そう
Palo Alto Networks SSE-Engineer 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
質問 # 41
A user connected to Prisma Access reports that traffic intermittently is denied after matching a Catch-All Deny rule at the bottom and bypassing HIP-based policies. Refreshing VPN connection restores the access.
What are two reasons for this behavior? (Choose two.)
- A. HIP-enforced policy is scheduled for certain hours of the day.
- B. "Collect HIP data' needs to be enabled in the configuration.
- C. Firewall loses user mapping due to missed HIP report checks.
- D. User mapping is learned from sources other than gateway authentication.
正解:C、D
解説:
User mapping learned from sources other thangateway authenticationcan cause intermittent access issues if it conflicts with the expected user identity used in HIP-based policies. If the firewall is associatingthe user with an outdated or incorrect mapping, traffic may not match the intended security policies, leading todenials by the Catch-All Deny rule.
If thefirewall loses user mapping due to missed HIP report checks, the user may temporarily lose access to policies that require a validHost Information Profile (HIP)match. When the VPN connection is refreshed, the HIP check is re-initiated, restoring access until the issue repeats.
質問 # 42
Which policy configuration in Prisma Access Browser (PAB) will protect an organization from malicious BYOD and minimize the impact on the user experience?
- A. One that blocks elements such as screen scrapers
- B. One for session recording
- C. One that blocks file exchange
- D. One that allows access to applications with data masking or watermarking
正解:D
解説:
InPrisma Access Browser (PAB), allowing access to applications while enforcingdata masking or watermarkingprovides security forBYOD (Bring Your Own Device)users without heavily impacting the user experience.Data maskingensures that sensitive information isobscured, reducing the risk of data leakage, whilewatermarkingcan deter unauthorized screenshots or data exfiltration. This approachbalances security and usability, allowing users to work efficiently while protecting corporate data.
質問 # 43
A customer is implementing Prisma Access (Managed by Strata Cloud Manager) to connect mobile users, branch locations, and business-to-business (B2B) partners to its data centers. [Scenario as before, with overlapping prefixes advertised by B2B partners.] Which two actions will meet the customer requirements for the B2B connections? (Choose two.)
- A. Configure service connections for data center connectivity.
- B. Configure remote networks with NAT pools for each of the B2B connections.
- C. Advertise the corresponding network prefixes using eBGP or static routes.
- D. NAT the traffic at the customer premises equipment (CPE).
正解:B、C
解説:
B2B partner connections in this scenario present two compounding requirements: partners need reachability specifically to internally hosted proprietary applications on non-standard ports, and - critically - multiple B2B partners are advertising overlapping IP prefixes, which means Prisma Access cannot rely on raw source addressing alone to distinguish one partner ' s traffic from another ' s without introducing address translation.
Onboarding these B2B connections as Remote Networks and applying dedicated NAT pools per connection resolves the overlapping-prefix problem directly at the point of ingress, translating each partner ' s overlapping internal addressing into a unique, non-conflicting address space as it enters the Prisma Access backbone - this is essential specifically because of the overlap condition stated in the scenario, making option B correct. Once translated to unique addressing, those NAT ' d prefixes still need to be made reachable to the specific internal application resources; advertising the corresponding (translated) network prefixes via eBGP or static routes ensures the data center and Prisma Access properly exchange reachability information for that now-unique addressing, making option A the necessary complementary action. Service connections (option C) are the mechanism used for the organization ' s own data center connectivity to Prisma Access broadly, not the specific mechanism for resolving the B2B overlapping-prefix and access-scoping requirement described here, so while service connections exist elsewhere in this deployment, they are not the answer to this specific sub-question. NAT ' ing traffic at the customer premises equipment (option D) pushes the translation responsibility onto each individual B2B partner ' s own infrastructure, which the customer does not control and cannot guarantee is correctly implemented, making it an unreliable and non-scalable solution compared to handling NAT natively within the Remote Networks onboarding.
Reference:Prisma Access Remote Networks - NAT Pools for Overlapping Subnet B2B Connections.
質問 # 44
What are two advantages the Prisma Access Browser (PAB) offers in providing consistent security for accessing web-based resources across corporate-managed laptops and personal devices, as well as contractors using devices issued by third parties? (Choose two.)
- A. It enforces SSL Forward Proxy decryption to enable inspection of encrypted traffic, allowing for enhanced security and threat prevention capabilities.
- B. It provides all users on any devices secure access to the internet with enhanced security and threat prevention capabilities for encrypted traffic.
- C. It routes all traffic to Prisma Access to perform deep packet inspection of encrypted traffic, allowing for enhanced security and threat prevention capabilities.
- D. It applies an encryption layer to protect all browser assets with a trusted encryption chain that is independent of the operating system.
正解:B、D
解説:
PAB ' s core architectural advantage over a traditional inline decrypt-and-inspect gateway model is that it delivers security consistently to any user on any device - including managed laptops, personal BYOD devices, and third-party contractor equipment the organization does not own or administer - precisely because enforcement happens inside the browser session itself rather than requiring the device to be tunneled through, or trusted by, corporate network infrastructure; this device-agnostic, universally consistent protection for encrypted web traffic is exactly what option B describes. Because PAB operates as its own managed, isolated browser environment, it can maintain its own trusted encryption chain for protecting browser assets and session data that does not depend on, or vary with, the underlying operating system ' s own certificate store or security posture - a meaningful advantage precisely on unmanaged and third-party devices where the OS-level trust configuration is outside the organization ' s control, matching option D. Option A describes SSL Forward Proxy decryption, which is the mechanism used by full network-layer inline inspection (such as GlobalProtect tunneled traffic through Prisma Access gateways), not the defining advantage of the browser- native PAB model, which achieves visibility into encrypted sessions without requiring that same network- layer decryption architecture. Option C similarly describes routing all traffic to Prisma Access for deep packet inspection, which mischaracterizes PAB ' s browser-native enforcement model as a network-tunneling model, conflating it with GlobalProtect ' s full-tunnel architecture rather than PAB ' s actual browser-isolated approach.
Reference:Prisma Access Browser - Consistent Security Across Managed, Unmanaged, and Third-Party Devices.
質問 # 45
An engineer has configured a new Remote Networks connection using BGP for route advertisements. The IPSec tunnel has been established, but the BGP peer is not up. Which two elements must the engineer validate to solve the issue? (Choose two.)
- A. Advertise Default Route Checkbox
- B. Secret
- C. Peer AS Number
- D. MRAI Timers
正解:B、C
解説:
With the IPSec tunnel already established, the underlying transport connectivity is confirmed to be working correctly, which narrows the troubleshooting focus specifically to the BGP session parameters themselves rather than network reachability. Two configuration values are the most common and immediate causes of a BGP peer failing to come up even over a healthy tunnel: the MD5 authentication secret, if BGP authentication is enabled on either side, must match exactly between Prisma Access and the customer ' s CPE, since any mismatch causes the peer session to be silently rejected during the initial OPEN message exchange, matching option A. Equally critical is the Peer AS Number - if the AS number configured on either the Prisma Access side or the CPE side does not match what the other side expects for that specific peering relationship, the BGP session will never successfully establish, regardless of how correctly every other setting is configured, matching option C. MRAI (Minimum Route Advertisement Interval) timers, referenced in option B, govern how frequently route updates are sent once a BGP session is already established and exchanging routes - they have no bearing on whether the initial peer session comes up in the first place, making them irrelevant to this specific symptom. The Advertise Default Route checkbox (option D) controls whether Prisma Access advertises a 0.0.0.0/0 route once peering is functional; it is a route-advertisement behavior setting, not a prerequisite for the BGP peer session itself to establish.
Reference:Prisma Access Remote Networks - BGP Peer Establishment Troubleshooting.
質問 # 46
A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header.
Which option will prevent this form of attack?
- A. Advanced URL Filtering and block the "Malicious Behavior" category
- B. Advanced URL Filtering and block "SNI mismatch with Server Certificate (SAN/CN)"
- C. Advanced Threat Prevention option to block "Domain Fronting"
- D. SSL Decryption to "Block sessions on SNI mismatch with Server Certificate (SAN/CN)"
正解:D
解説:
This option ensures thatSSL Decryptionchecks for mismatches between theServer Name Indication (SNI) fieldin the TLS handshake and theCommon Name (CN) or Subject Alternative Name (SAN) in the server certificate. If a malicious user tries to bypass content filtering by spoofing theSNI while using the real blocked website in the HTTP host header, this setting will detect the discrepancy andblock the session, preventing unauthorized access.
質問 # 47
Which two Prisma Access Browser (PAB) configurations will provide a contractor SSH access to an internal system? (Choose two.)
- A. Configure Internal Application entries, Configure Access & Data Control policy
- B. Configure Remote Connection Application entries, Configure Access & Data Control policy
- C. Enable Internal Connections
- D. Enable Remote Connections
正解:B、D
解説:
SSH is fundamentally different from a standard HTTP/HTTPS-based internal web application, since it is a non-web, terminal-based protocol, and PAB accommodates protocols like SSH and RDP through a distinct capability generally referred to as Remote Connections rather than the standard internal web application publishing workflow. Enabling Remote Connections is the prerequisite platform capability that allows PAB to broker non-web protocol sessions such as SSH at all, making option B a necessary first configuration step.
Once that capability is enabled, the administrator must define the actual target system as a Remote Connection Application entry - specifying the internal host, port, and protocol (SSH in this case) the contractor needs to reach - and then build an Access & Data Control policy that authorizes the specific contractor or contractor group to reach that defined Remote Connection application entry, which is exactly what option C describes and is the configuration pairing that actually grants and governs the access. Option A describes " Internal Application entries " rather than " Remote Connection Application entries " - internal (web) application entries are the construct used for standard HTTP/HTTPS internal application publishing, not SSH, so this pairing misapplies the wrong application object type to a non-web protocol use case. Option D references " Internal Connections " as a toggle, which is not the correctly named capability for enabling non-web protocol brokering in PAB; the documented feature and terminology for SSH/RDP-style access is Remote Connections, not " Internal Connections. " Reference:Prisma Access Browser - Remote Connections for SSH/RDP Access to Internal Systems.
質問 # 48
An engineer has configured IPSec tunnels for two remote network locations; however, users are experiencing intermittent connectivity issues across the tunnels.
What action will allow the engineer to receive notifications when the IPSec tunnels are down or experiencing instability?
- A. Create a tunnel log notification rule to alert on specified remote network IPSec tunnel conditions.
- B. Create a new notification profile specifying conditions for remote network IPSec tunnels.
- C. Select the IPSec tunnel monitoring and notifications checkbox when configuring the remote network IPSec tunnels.
- D. Set up the operational health dashboard to email alerts for remote Network IPSec tunnel issues.
正解:B
解説:
InPrisma Access, configuring anotification profileallows engineers to receive alerts when IPSec tunnels experience downtime or instability. By definingspecific conditions for remote network IPSec tunnels, the notification profile ensures that the engineer is proactively informed abouttunnel failures, flapping, or degraded performance. This approach enables timely troubleshooting and minimizes disruptions for users relying on the IPSec tunnels.
質問 # 49
How can a senior engineer use Strata Cloud Manager (SCM) to ensure that junior engineers are able to create compliant policies while preventing the creation of policies that may result in security gaps?
- A. Use security checks under posture settings and set the action to "deny" for all checks that do not meet the compliance standards.
- B. Configure an auto tagging rule in SCM to trigger a Security policy review workflow based on a security rule tag, then instruct junior engineers to use this tag for all new Security policies.
- C. Configure role-based access controls (RBACs) for all junior engineers to limit them to creating policies in a disabled state, manually review the policies, and enable them using a senior engineer role.
- D. Run a Best Practice Assessment (BPA) at regular intervals and manually revert any policies not meeting company compliance standards.
正解:A
解説:
By usingsecurity checks under posture settingsinStrata Cloud Manager (SCM), the senior engineer can enforcepolicy compliance standardsbyautomatically denyingany security policy that does notalign with best practices. This ensures that junior engineers can create policies while preventing configurations that might introduce security gaps. This proactive approacheliminates manual oversightand enforces compliance at the time of policy creation, reducing risk and ensuring consistent security enforcement.
質問 # 50
Based on the image below, which two statements describe the reason and action required to resolve the errors? (Choose two.)
- A. The server has pinned certificates.
- B. Create a do not decrypt rule for the hostname "google.com."
- C. Create a do not decrypt rule for the hostname "certificates.godaddy.com."
- D. The client is misconfigured.
正解:A、B
解説:
The error messages indicate that Prisma Access is encountering certificate issues while attempting to decrypt traffic to "google.com." This suggests that theserver has pinned certificates, meaning it does not allow man- in-the-middle (MITM) decryption by Prisma Access. Since pinned certificates prevent traffic decryption, a solution is tocreate a "do not decrypt" rule for the hostname "google.com."This will allow traffic to flow without triggering certificate errors while maintaining secure communication with Google's servers.
質問 # 51
Which statement applies when enabling multitenancy in Prisma Access (Managed by Panorama)?
- A. Service connection licenses will be assigned only to the first tenant, and these service connections can be shared with the other tenants.
- B. There is flexibility to manage different tenants using separate Panoramas, which allows for better organization and management of the multiple tenants.
- C. Each tenant is allocated its own dedicated Prisma Access instances, with compute resources that are not shared across tenants.
- D. A single tenant cannot consist solely of mobile users or solely of remote networks.
正解:C
解説:
When multitenancy is enabled in Prisma Access (Managed by Panorama), a key characteristic is the isolation of resources between tenants. Palo Alto Networks documentation emphasizes that each tenant operates within its own logically separate Prisma Access environment. This includes dedicated compute instances, ensuring that the performance and security of one tenant are not impacted by the activities of another.
Let's analyze why the other options are incorrect based on official documentation:
A: Service connection licenses will be assigned only to the first tenant, and these service connections can be shared with the other tenants. This statement is incorrect. In a multitenant Prisma Access deployment, licenses are typically managed and allocated per tenant. While the underlying infrastructure might be shared by Palo Alto Networks, the logical resources and often the licensing are segmented for each tenant. Sharing service connections across completely separate tenants would violate the principle of tenant isolation.
B: A single tenant cannot consist solely of mobile users or solely of remote networks. This statement is incorrect. Prisma Access multitenancy allows for flexibility in how tenants are configured. A tenant can be designed to exclusively serve mobile users, exclusively connect remote networks, or a combination of both, depending on the organizational structure and requirements.
D: There is flexibility to manage different tenants using separate Panoramas, which allows for better organization and management of the multiple tenants. While it is possible to have multiple Panorama instances managing different parts of a large infrastructure, when discussing multitenancy within a single Prisma Access instance (as implied by the question "enabling multitenancy in Prisma Access (Managed by Panorama))", all configured tenants are managed by that single Panorama instance. Managing different tenants with separate Panoramas is a different architectural consideration, not a defining characteristic of enabling multitenancy within one Prisma Access deployment managed by a specific Panorama.
Therefore, the defining characteristic of Prisma Access multitenancy (Managed by Panorama) is the allocation of dedicated Prisma Access instances and compute resources for each tenant, ensuring logical separation and resource isolation
質問 # 52
When a review of devices discovered by IoT Security reveals network routers appearing multiple times with different IP addresses, which configuration will address the issue by showing only unique devices?
- A. Delete all duplicate devices, keeping only those discovered using their management IP addresses.
- B. Create a custom role to merge devices with the same hostname and operating system.
- C. Merge individual devices into a single device with multiple interfaces.
- D. Add the duplicate entries to the ignore list in IoT Security.
正解:C
解説:
When network routers appear multiple times with different IP addresses in IoT Security, it is likely because they have multiple interfaces with separate IPs. Merging these entries into a single device with multiple interfaces ensures that the system correctly identifies each router as a unique entity while maintaining visibility across all its interfaces. This approach prevents unnecessary duplicates, improves asset management, and enhances security monitoring.
質問 # 53
A malicious user is attempting to connect to a blocked website by crafting a packet using a fake SNI and the correct website in the HTTP host header. Which option will prevent this form of attack?
- A. Advanced URL Filtering and block the " Malicious Behavior " category
- B. Advanced URL Filtering and block " SNI mismatch with Server Certificate (SAN/CN) "
- C. Advanced Threat Prevention option to block " Domain Fronting "
- D. SSL Decryption to " Block sessions on SNI mismatch with Server Certificate (SAN/CN) "
正解:D
解説:
Domain fronting works by presenting a benign or allowed hostname in the TLS ClientHello SNI field while the actual intended destination is embedded in the encrypted HTTP Host header, exploiting the fact that many security controls historically made policy decisions based on the SNI alone, before decryption exposed the true host being requested. The correct defense operates at the SSL Decryption layer itself: when Prisma Access decrypts the session, it can compare the SNI presented during the handshake against the Subject Alternative Name/Common Name actually returned in the server ' s certificate, and the " Block sessions on SNI mismatch with Server Certificate (SAN/CN) " decryption profile setting will terminate any session where these values do not agree - which is exactly the signature of a domain-fronting attempt, since the fake SNI will not match the certificate genuinely presented by the real destination server. This makes option D the correct, purpose-built control. There is no " Domain Fronting " toggle within Advanced Threat Prevention (option A); ATP focuses on exploit and vulnerability signatures, not SNI/certificate correlation. Advanced URL Filtering ' s " Malicious Behavior " category (option B) is a URL reputation classification and does not perform SNI-versus-certificate comparison. Option C names a setting that does not exist as an Advanced URL Filtering control; SNI-mismatch detection and enforcement is a decryption-profile capability, not a URL filtering category action, which is the key distinction separating the correct answer from this distractor.
Reference:PAN-OS Decryption Profiles - Block Sessions with SNI Mismatch (SAN/CN) as a Domain Fronting Defense.
質問 # 54
What is the purpose of embargo rules in Prisma Access?
- A. Blocking traffic from Russia, China, and North Korea only
- B. Blocking connections from specific countries
- C. Rate-limiting connections originating from specific countries
- D. Allowing traffic only from specific countries
正解:B
解説:
Embargo rules are a purpose-built, pre-defined Security policy rule construct in Prisma Access that lets an organization block inbound connection attempts - most commonly authentication attempts against the GlobalProtect portal, Explicit Proxy, or Remote Networks entry points - that originate from specific countries or regions, using Palo Alto Networks ' geolocation-based source address matching. Their defining behavior is unconditional blocking (a Drop action) of the specified source countries, which makes option C the accurate general description of their purpose; they exist to reduce attack surface against brute-force and credential-stuffing attempts by preventing connection attempts before normal identity-based Security policy would even be evaluated, since embargo rules are enforced as top-of-stack pre-rules using the reserved tag PA_predefined_embargo_rule. Option A is incorrect because embargo rules are a binary block mechanism, not a rate-limiting or throttling control - there is no partial-restriction behavior involved. Option B inverts the logic entirely; embargo rules are not an allow-list mechanism restricting traffic to only a permitted set of countries, they are a deny-list mechanism for specific countries while leaving all other geographies unaffected. Option D is too narrow and factually incorrect as a generalization: embargo rules are configurable for any country or region the organization chooses to specify, and are frequently used for the broader set of countries subject to export or sanctions restrictions, not a fixed three-country list.
Reference:Prisma Access - Block Incoming Connections from Specific Countries (Embargo Rules).
質問 # 55
An engineer is troubleshooting split-tunneling on a Palo Alto Networks VPN client. The local LAN interface is on the 192.168.1.0/24 network, and the Prisma Access Mobile User IP Pool is configured as 172.16.72.0/23 in Strata Cloud Manager (SCM). Based on the image below, which statement regarding the split-tunneling configuration for the VPN client is valid?
- A. 172.16.73.1/32 has been explicitly configured as an exclude route.
- B. 192.168.5.95/32 has been explicitly configured as an exclude route.
- C. 10.10.10.10/32 has been explicitly configured as an include route.
- D. 9.9.9.9/32 has been explicitly configured as an include route.
正解:D
解説:
Interpreting a client-side split-tunnel routing table requires distinguishing three categories of entries: the broad, tunnel-wide default or pool-derived routes automatically installed by the GlobalProtect connection itself, host routes that fall naturally within the local LAN subnet and therefore route locally regardless of tunnel configuration, and host routes that fall entirely outside both the local LAN subnet (192.168.1.0/24) and the mobile user IP pool (172.16.72.0/23) - the latter category is the tell-tale signature of a deliberately, explicitly configured split-tunnel include route, since GlobalProtect would have no other reason to install a specific /32 host route for an address that belongs to neither the local network nor the assigned tunnel pool unless an administrator had explicitly added it as an include access route. A host address such as 9.9.9.9/32 falls squarely outside both of those ranges, so its presence as a specific /32 entry pointing into the tunnel interface is explained only by an explicit administrator-configured include route, which is exactly the conclusion in option A. By contrast, an address like 192.168.5.95 sits inside the broader local LAN addressing scheme referenced in the scenario and would be explained by local network routing behavior rather than a deliberate tunnel exclude configuration, and an address like 172.16.73.1 falls within the 172.16.72.0/23 mobile user pool itself, meaning its routing behavior is already accounted for by the pool ' s own default tunnel-inclusion behavior rather than representing a distinct, explicitly configured exclude entry.
Reference:GlobalProtect - Split Tunnel Access Route Verification via Client Routing Table.
質問 # 56
How can an engineer use risk score customization in SaaS Security Inline to limit the use of unsanctioned SaaS applications by employees within a Security policy?
- A. Lower the risk score of sanctioned applications and increase the risk score for unsanctioned applications.
- B. Increase the risk score for all SaaS applications to automatically block unwanted applications.
- C. Build an application filter using unsanctioned SaaS as the characteristic.
- D. Build an application filter using unsanctioned SaaS as the category.
正解:A
解説:
SaaS Security Inline ' s risk-score customization capability exists specifically so an organization ' s own sanctioning decisions can be reflected in the numeric risk value that downstream Security policy rules evaluate, rather than relying purely on the platform ' s generic, vendor-assigned default risk ratings, which may not align with a specific organization ' s governance decisions about which applications are approved. By deliberately lowering the risk score assigned to applications the organization has sanctioned and raising the risk score assigned to applications it considers unsanctioned, an administrator can then build a single, risk- threshold-based Security policy rule (for example, blocking any SaaS traffic above a defined risk score) that automatically and consistently restricts unsanctioned application usage without needing to individually enumerate every unsanctioned application by name - a much more maintainable, scalable control as the SaaS application landscape grows. This makes option A the intended, documented use of the risk- customization feature. Uniformly increasing the risk score for all SaaS applications (option B) would defeat the purpose of differentiated governance entirely, since it would fail to distinguish sanctioned from unsanctioned traffic and could block legitimate business applications alongside unwanted ones. Options C and D both describe building an application filter based on an " unsanctioned SaaS " category or characteristic, which is a legitimate alternative policy construction technique in its own right, but it is a distinct mechanism from risk score customization - the question specifically asks how risk score customization is used, and neither C nor D actually involves adjusting risk scores at all.
Reference:SaaS Security Inline - Risk Score Customization for Sanctioned and Unsanctioned Applications.
質問 # 57
Where are tags applied to control access to Generative AI when implementing AI Access Security?
- A. To user devices for identifying and controlling which Generative AI applications they can access
- B. To Generative AI URL categories for classifying trusted and untrusted Generative AI websites
- C. To security rules for defining which types of Generative AI applications are allowed or blocked
- D. To Generative AI applications for identifying sanctioned, tolerated, or unsanctioned applications
正解:D
解説:
When implementingAI Access Security,tagsare applied toGenerative AI applicationsto classify them as sanctioned, tolerated, or unsanctioned. This allows organizations to enforcepolicy-based access control over AI tools, ensuring that onlyapproved applicationsare accessible while restricting or monitoring usage of untrusted or high-risk AI platforms. This classification helps security teamsmanage AI-related risks and complianceeffectively.
質問 # 58
......
検証済み材料を使うならまずSSE-Engineerテストエンジンを試そう:https://jp.fast2test.com/SSE-Engineer-premium-file.html