Palo Alto Networks Certified Network Security Administrator (PCNSA) practice questions

205 free questions with answers and explanations.

Practice test
  1. 101.A network security engineer is tasked with optimizing the security policy rulebase for performance. The engineer identifies several rules that allow traffic for common applications like 'web-browsing' and 'ssl' to various destinations, but these rules do not apply any security profiles. Which best practice should the engineer follow to improve performance without compromising security for this type of traffic?Security Policy Configuration
  2. 102.A company is implementing a new policy to restrict access to certain web applications based on the user's department. For instance, only the HR department should access HR-related SaaS applications, and the Finance department should access financial SaaS applications. Which Palo Alto Networks feature is primarily used in security policies to enforce this type of user-based access control?Security Policy Configuration
  3. 103.A security technician observes that internal users are frequently downloading executable files (.exe) from legitimate cloud storage services, posing a potential malware risk. The company wants to prevent the download of executable files from the internet while still allowing access to the cloud storage services. Which security profile should be configured and applied to enforce this policy?Security Policy Configuration
  4. 104.A company is deploying a new internal web application that uses a custom TCP port 8080. Internal users need to access this application, but a penetration test revealed that the default 'allow-all-internal' rule historically used for internal traffic is too broad. The security team wants to create a specific security policy rule for this application, ensuring it's only accessible via its intended application and port, and that all security profiles are applied. Which combination of 'Application' and 'Service' objects should be used in the new security policy rule?Security Policy Configuration
  5. 105.A security engineer has configured a security policy rule to allow SSH access to internal servers from a jump box. However, the engineer also wants to prevent any other applications from using the SSH port (TCP 22) to bypass the firewall. What is the most effective way to achieve this using App-ID and service objects?Security Policy Configuration
  6. 106.A network administrator is troubleshooting an issue where a newly deployed internal server, accessible via its private IP 10.0.0.5, needs to be reached from external networks using a public IP 203.0.113.10. The administrator has configured a Destination NAT (D-NAT) rule to translate 203.0.113.10 to 10.0.0.5. However, external users are still unable to connect. What critical additional configuration is most likely missing for external users to successfully reach the server?Security Policy Configuration
  7. 107.A company requires that all outbound web traffic from the internal network to the internet must be inspected for threats. Due to compliance regulations, only traffic that uses standard HTTP (port 80) and HTTPS (port 443) should be allowed. Traffic on other ports, even if it's web-related, should be blocked. Which service object should be configured in the security policy rule to meet this requirement?Security Policy Configuration
  8. 108.A network security engineer observes a sudden spike in 'spyware' detections in the Threat Logs. To investigate further, they need to identify the specific applications involved in these spyware events. Which field in the Threat Logs provides this application information?Monitoring and Reporting
  9. 109.A network administrator wants to quickly identify applications consuming the most bandwidth on their Palo Alto Networks firewall. Which feature provides a real-time, interactive view of network traffic, applications, and threats?Monitoring and Reporting
  10. 110.A security auditor requests a weekly report detailing all successful and failed authentication attempts for all users. Which type of log should be primarily used to generate this custom report?Monitoring and Reporting
  11. 111.A security auditor requires that all HTTP traffic to specific high-risk URL categories (e.g., gambling, adult) must be blocked, and users attempting to access these sites should receive a customizable block page. Additionally, all HTTPS traffic to these same categories must be reset-server. Which security profile needs to be configured and applied to achieve this granular control?Security Policy Configuration
  12. 112.A network security engineer has configured a new security policy rule to allow specific internal users (identified by User-ID) to access a critical internal application. However, users are reporting that access is still being denied. Upon reviewing the traffic logs, the engineer notices that the 'Source User' field for the denied sessions is showing 'unknown'. What is the most probable cause for this issue?Security Policy Configuration
  13. 113.A company policy dictates that all outbound web traffic (HTTP/HTTPS) from the internal network to the internet must be inspected for malware, spyware, and vulnerability exploits. Which security profile should be applied to the outbound security policy rule to enforce this requirement comprehensively?Security Policy Configuration
  14. 114.A network security engineer is configuring a new security policy rule on a Palo Alto Networks firewall. The requirement is to allow internal users to access an external web application that uses a non-standard TCP port 8443 for HTTPS traffic. Which service object should be used in the security policy rule to ensure proper application identification and security profile enforcement for this traffic?Security Policy Configuration
  15. 115.A network administrator has configured a custom report to run weekly, summarizing all high-severity threats detected. The report is configured to save as a PDF to the firewall's local disk. The administrator needs to verify that the report is being generated and saved successfully. Where on the firewall can the administrator find the generated PDF files?Monitoring and Reporting
  16. 116.A security analyst is investigating a potential data exfiltration incident. They need to review all outbound traffic from a specific internal subnet (10.1.1.0/24) that used the 'ftp' application over the last 24 hours and was allowed by the firewall. Which log type and filter combination would be most effective for this purpose?Monitoring and Reporting
  17. 117.A security administrator needs to configure a security policy rule that allows internal users to access web servers, but only if they belong to the 'IT-Admins' Active Directory group. The firewall is integrated with Active Directory using User-ID. Which security policy configuration parameter is essential for enforcing this group-based access control?Security Policy Configuration
  18. 118.A security technician needs to configure a security policy rule that allows internal users to access an external web server using a specific custom application that runs on TCP port 9000. However, the application is not identified by any existing App-ID signature. To ensure the firewall still identifies this as a unique application and applies specific security profiles, what is the most appropriate step?Security Policy Configuration
  19. 119.A company policy requires that any download of an executable file (.exe) from the internet must be recorded in a specific report, along with the user who initiated the download and the source URL. Which Palo Alto Networks logging feature, when properly configured with a Security Profile, enables this specific type of granular logging?Monitoring and Reporting
  20. 120.A security engineer is configuring a new security policy rule to allow outbound web traffic for internal users. The policy mandates that all web traffic (HTTP/HTTPS) must be subject to a standard set of security profiles including antivirus, anti-spyware, vulnerability protection, and URL filtering. To simplify management and ensure consistency, how should these profiles be applied to the security policy rule?Security Policy Configuration
  21. 121.A company is concerned about employees accidentally or maliciously uploading sensitive customer data (e.g., credit card numbers, social security numbers) to unapproved cloud storage services. Which security profile, when applied to a security policy, can detect and prevent the transfer of such specific patterns of sensitive information?Security Policy Configuration
  22. 122.A company is migrating its internal mail server from a private IP address (10.0.0.10) to a new public IP address (203.0.113.5). External users need to access this mail server using the public IP. The Palo Alto Networks firewall must perform a static NAT to translate the public IP to the private IP. Which NAT policy configuration is correct?Security Policy Configuration
  23. 123.A security technician needs to configure a security policy rule that allows internal users to access web applications hosted on servers in the DMZ. The policy must ensure that the source IP address of the internal users is preserved when reaching the DMZ servers for logging and auditing purposes on the servers. Which type of NAT policy should be associated with this security policy rule?Security Policy Configuration
  24. 124.A network administrator is configuring a new security policy rule on a Palo Alto Networks firewall. The requirement is to allow internal users to access a newly deployed internal web server, but only from specific source IP addresses within the internal network. Which of the following elements should be configured in the security policy rule to meet this requirement?Security Policy Configuration
  25. 125.A security administrator needs to configure a security policy rule that allows internal users to access web-browsing applications (HTTP/HTTPS) and SSH, while enforcing strict threat prevention measures including antivirus, anti-spyware, and vulnerability protection. To simplify management, these threat prevention profiles should be applied consistently to all allowed traffic within this rule. Which configuration approach BEST achieves this?Security Policy Configuration
  26. 126.A network administrator is creating a custom report to show all sessions where the 'bytes_sent' value exceeds 1 GB for any single session within the last week. The report needs to display the source IP, destination IP, application, and the total bytes sent for these large sessions. Which attribute should be used in the filter criteria for this custom report?Monitoring and Reporting
  27. 127.A company is integrating its Palo Alto Networks firewall with Active Directory to enforce user-based security policies. After initial setup, the administrator notices that policies configured with 'Source User' criteria are not matching correctly, and traffic logs show 'unknown' for the user. The User-ID agent is confirmed to be running on the domain controller. What is the next logical step to troubleshoot why user-to-IP mappings are not being correctly acquired by the firewall?Security Policy Configuration
  28. 128.A network administrator needs to ensure that internal users can only access specific SaaS applications (e.g., Salesforce, Office 365) and block all other cloud applications. The firewall is configured for App-ID. Which approach to security policy configuration is most effective and adheres to the principle of least privilege?Security Policy Configuration
  29. 129.A security engineer is troubleshooting an issue where users are unable to access a newly deployed internal web application hosted on a server with a private IP address (192.168.10.50). The application is accessed via a public IP address (203.0.113.10) configured on the firewall. Users from the internet are reporting a connection timeout. Which type of NAT policy is most likely misconfigured or missing?Security Policy Configuration
  30. 130.A security engineer is configuring a decryption policy on a Palo Alto Networks firewall. The company policy states that all traffic to financial institutions (identified by a custom URL category 'Financial-Sites') must NOT be decrypted due to privacy and compliance regulations. All other internet-bound HTTPS traffic should be decrypted. In which order should the decryption policy rules be arranged?Security Policy Configuration
  31. 131.A security analyst observes that users are downloading executable files from a cloud storage service, which is a known vector for malware. The company policy dictates that all executable file downloads from unknown or unapproved cloud storage services must be blocked. Which Content-ID component on the Palo Alto Networks firewall should be configured to enforce this policy?Security Policy Configuration
  32. 132.A company has implemented a new policy requiring all internal users to only use the corporate-sanctioned version of Microsoft Teams, and block all other versions or personal accounts. Which feature of Palo Alto Networks firewalls should the administrator leverage to enforce this granular control?Security Policy Configuration
  33. 133.A security operations center (SOC) needs to integrate Palo Alto Networks firewall logs with their existing Security Information and Event Management (SIEM) system. Which configuration setting on the firewall is primarily used to forward logs to an external SIEM?Monitoring and Reporting
  34. 134.A network security administrator is configuring a new security policy rule to allow internal users to access a newly deployed internal web application. The application uses a non-standard TCP port 8080. Which service object should the administrator use in the security policy rule to ensure only this specific application traffic is permitted?Security Policy Configuration
  35. 135.A security operations center (SOC) team requires real-time notifications for specific critical events, such as a high-severity threat being detected or an administrator login from an unusual geographic location. Which Palo Alto Networks feature is best suited for configuring these immediate alerts?Monitoring and Reporting
  36. 136.A network security analyst is reviewing the system logs to identify any recent changes made to the firewall configuration. They need to quickly find entries related to configuration commits and the administrator who performed them. Which filter should be applied to the system logs?Monitoring and Reporting
  37. 137.A network security engineer is tasked with ensuring all critical firewall logs, including traffic, threat, and system logs, are consistently forwarded to an external Syslog server for long-term archival and SIEM integration. Which configuration object is used to define the destination server and the log types to be sent?Monitoring and Reporting
  38. 138.A company is implementing decryption for outbound SSL/TLS traffic. After enabling decryption, users report certificate warnings and trust errors on their web browsers when accessing various websites. Which of the following is the most likely cause for these errors?Security Policy Configuration
  39. 139.A company requires that all outbound traffic from its internal network must be subject to threat prevention, including antivirus, anti-spyware, and vulnerability protection. Additionally, WildFire analysis should be performed on all executable files. Which security profile group should be created and applied to achieve this comprehensive threat prevention?Security Policy Configuration
  40. 140.An organization has configured several custom reports to run weekly and monthly. They need to ensure these reports are automatically emailed to specific recipients. Where is the email sender profile configured for these scheduled reports?Monitoring and Reporting
  41. 141.A network security analyst is troubleshooting why a specific custom report is not generating data. They have confirmed the report query is correct and the time range covers relevant events. What is a common reason for a custom report to show no data even with a correct query and time range?Monitoring and Reporting
  42. 142.A company policy dictates that all attempts to access gambling websites must be blocked and logged. A security analyst needs to verify that the URL Filtering profile is correctly blocking these sites and that the corresponding log entries are being generated. Which log type would the analyst review to confirm this policy enforcement?Monitoring and Reporting
  43. 143.A network administrator is troubleshooting an issue where a newly deployed custom report is not generating any data, even though there should be relevant log entries. The administrator suspects an issue with the report's filter criteria. Which method is most effective for validating the filter criteria against existing logs to ensure it will capture the intended data?Monitoring and Reporting
  44. 144.A cybersecurity incident response team is investigating a potential malware outbreak. They need to quickly determine if any files submitted to WildFire from the internal network (192.168.1.0/24) were identified as malicious and, if so, which users initiated the connections. Which log type should the team focus on for this investigation?Monitoring and Reporting
  45. 145.A company is implementing a new policy to restrict access to certain web applications based on user groups. For example, only users in the 'Marketing' group should access 'Facebook' and 'Twitter', while 'Engineering' users should access 'GitHub' and 'Jira'. All other users should be blocked from these applications. Which feature on the Palo Alto Networks firewall is essential for enforcing such user-group-specific access controls in security policies?Security Policy Configuration
  46. 146.A company has recently deployed a new internal application server. Due to compliance requirements, all traffic to and from this server must be logged extensively, including URL information and threat details, even if the traffic is allowed. Which security policy rule setting should be configured to ensure comprehensive logging for this specific server's traffic?Security Policy Configuration
  47. 147.A security auditor requires that all outbound HTTP/HTTPS traffic from the internal network must be inspected for malware, spyware, and command-and-control (C2) activity. Additionally, the auditor wants to ensure that no sensitive data leaves the network in these connections. Which security profile combination should be applied to the relevant security policy rule to meet these requirements?Security Policy Configuration
  48. 148.A network security administrator needs to ensure that all outbound HTTP/HTTPS traffic from the internal network to the internet is protected against known malware and exploits. Additionally, the company policy dictates that users should be prevented from accessing websites categorized as 'Gambling' or 'Malware'. Which security profiles should be applied to the outbound security policy rule to meet these requirements?Security Policy Configuration
  49. 149.A cybersecurity incident response team needs a daily report of all files submitted to WildFire for analysis, including their verdict and the user who submitted them. Where would the custom report pull this information from?Monitoring and Reporting
  50. 150.A network administrator needs to generate a report showing the top 10 applications by session count that were blocked by the firewall in the last 7 days. Which log type should be used as the basis for this custom report?Monitoring and Reporting