Exam SSE-Engineer Topic 3 Question 29 Discussion

Actual exam question for Palo Alto Networks's SSE-Engineer exam
Question #: 29
Topic #: 3
An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?

Suggested Answer: D Vote an answer

Security policy evaluation in Strata Cloud Manager follows a hierarchical precedence based on configuration scope, and rules placed in a broader or higher-level scope are evaluated before rules placed in a more specific, lower-level folder such as Mobile Users or a particular connection type. If the new Web Security rule restricting the user group was created within a lower-level, more specific scope, it will not be reached at all whenever traffic first matches a broader, higher-level allow rule earlier in the evaluation order - the higher- level rule effectively wins by virtue of being processed first, and policy lookup stops at the first match. That is exactly the behavior described in the scenario: blocked applications continue to be reachable because a rule elsewhere in the hierarchy, evaluated ahead of the newly created restriction, is already permitting the traffic.
This makes option D the accurate description of the root cause. Option C describes the reverse relationship and does not match how rule hierarchy actually influences precedence in this platform. Improper threat management settings (option A) would affect logging or blocking behavior for identified threats, not whether the URL/application access rule is evaluated at all, so it does not explain complete rule bypass. Option B is a plausible but unsubstantiated guess about scope targeting; the scenario gives no indication the rule was misapplied to a connection type rather than a hierarchy level, whereas rule-order precedence is the classic, most common cause of " rule appears configured correctly but has no effect. " Reference:Strata Cloud Manager - Security Policy Rule Order and Configuration Scope Precedence.

by Phil at Sep 05, 2026, 09:05 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10