Palo Alto Networks Certified Network Security Administrator (PCNSA) practice questions
205 free questions with answers and explanations.
- 151.A technician is configuring a security policy rule to allow access to a new internal web application. The application uses a non-standard TCP port 8080. When configuring the security policy, the technician sets the 'Application' to 'web-browsing' and the 'Service' to 'application-default'. After committing the configuration, users report they cannot access the application. What is the most likely reason for this failure?Security Policy Configuration
- 152.A security administrator is implementing a new policy to prevent the exfiltration of sensitive company documents. The policy requires that all PDF and Microsoft Office documents containing specific keywords (e.g., 'CONFIDENTIAL', 'INTERNAL ONLY') should be blocked from being uploaded to external cloud storage services. Which combination of security profiles is BEST suited to enforce this policy?Security Policy Configuration
- 153.A network engineer wants to configure an alert that triggers whenever the number of critical severity threat logs exceeds 50 within a 5-minute period. Where would this alert be configured in the Palo Alto Networks firewall GUI?Monitoring and Reporting
- 154.A security analyst is reviewing firewall logs and needs to quickly identify all sessions that were denied due to a security policy rule. Which log type should the analyst primarily examine?Monitoring and Reporting
- 155.A company policy mandates that all internal users must be able to securely access external financial web services, but direct access to streaming video platforms is strictly prohibited. The security administrator has already configured App-ID and URL filtering. Which action should be configured in the URL Filtering profile applied to the outbound security policy rule for streaming video categories?Security Policy Configuration
- 156.A network security administrator needs to quickly identify if any users are consuming excessive bandwidth by streaming video from unapproved sources. Which dashboard widget in the ACC (Application Command Center) would provide the most immediate and relevant information for this task?Monitoring and Reporting
- 157.A security administrator is configuring a decryption policy on a Palo Alto Networks firewall. The company policy states that traffic to financial institutions and healthcare providers must NOT be decrypted due to privacy regulations, while all other outbound internet traffic SHOULD be decrypted and inspected. Which decryption type should be configured for the policy rule targeting financial/healthcare traffic?Security Policy Configuration
- 158.A network security engineer wants to monitor the total number of sessions currently active on the firewall and quickly identify the top applications consuming these sessions. Which feature in the Palo Alto Networks firewall GUI provides this capability?Monitoring and Reporting
- 159.A security engineer is configuring a NAT policy on a Palo Alto Networks firewall to allow internal users to access external resources using a pool of public IP addresses. The requirement specifies that outbound connections should use any available IP address from the pool, and subsequent return traffic should correctly map back to the original internal user. Which NAT type and translation method should be configured?Security Policy Configuration
- 160.A network administrator needs to optimize the security policy rulebase for performance. They notice several security policy rules that allow common web applications (e.g., facebook-base, youtube-base, google-search) for internal users to the internet. These rules contain a 'service' object of 'application-default' and are configured with various security profiles. Which best practice should the administrator follow to consolidate and optimize these rules without compromising security?Security Policy Configuration
- 161.A network administrator wants to review a summary of all security policy rule hits over the last month, specifically focusing on which rules are being used most frequently and which are not being hit at all. Which section of the Palo Alto Networks firewall GUI provides this information?Monitoring and Reporting
- 162.An organization relies on scheduled reports to provide daily summaries of critical security events to management. These reports are configured to be sent via email. Recently, management reported not receiving these daily emails. Which configuration profile should the administrator check first to troubleshoot the email delivery issue?Monitoring and Reporting
- 163.A security engineer is configuring a security policy rule to allow outbound HTTP/HTTPS traffic from the internal network to the internet. The company requires that all traffic matching this rule be logged at the start and end of each session for auditing purposes. Which logging option should be selected in the security policy rule configuration?Security Policy Configuration
- 164.A security team needs to monitor attempts to access known malicious websites categorized as 'phishing' or 'malware' by the firewall's URL filtering. They want to see the source IP, destination URL, and the user involved. Which log type should they analyze?Monitoring and Reporting
- 165.A network administrator needs to create a security policy rule to allow ping (ICMP echo request/reply) from the internal network to a specific server in the DMZ. However, the administrator wants to prevent any other ICMP types, such as timestamp requests or unreachable messages, from being permitted by this rule. Which application and service configuration should be used in the security policy rule?Security Policy Configuration
- 166.A network administrator is configuring a new Palo Alto Networks firewall. The requirement is to allow internal users to access external web servers on standard HTTP/HTTPS ports, but block all other outbound traffic. Which of the following security policy rule configurations would achieve this with the principle of least privilege?Security Policy Configuration
- 167.A security analyst needs to create a custom report that shows all blocked traffic from external IP addresses to internal servers over the last 30 days, grouped by destination IP. Which log type should be used as the basis for this report?Monitoring and Reporting
- 168.A financial institution has a strict compliance requirement to prevent the accidental or malicious exfiltration of sensitive customer data (e.g., credit card numbers, social security numbers) over any outbound application. Which Content-ID feature within a security profile should be configured to address this requirement most effectively?Security Policy Configuration
- 169.A company is deploying a new internal web application that uses a custom TCP port 4443. The security team needs to ensure that all outbound connections from this application to external services are decrypted for inspection, but other internal applications using standard SSL/TLS (port 443) should not be decrypted due to privacy concerns. Which decryption policy rule configuration will achieve this specific requirement?Security Policy Configuration
- 170.A security auditor requires that all HTTP/HTTPS traffic to known malicious or high-risk URL categories must be blocked, and all other uncategorized URLs must be allowed but logged for review. Which URL Filtering profile action should be configured for 'malware' and 'phishing' categories, and for 'uncategorized' URLs, respectively?Security Policy Configuration
- 171.A security technician is troubleshooting an issue where users are unable to access an external cloud-based application, even though a security policy rule is configured to allow 'web-browsing' and 'ssl' applications from the internal network to the 'any' zone. The firewall logs show that the traffic is being allowed by the rule, but the application remains inaccessible. Upon further inspection, the application's unique App-ID is 'cloud-app-X'. What is the MOST likely reason for the application being inaccessible?Security Policy Configuration
- 172.A company policy requires that all outbound web traffic from the internal network must be decrypted and inspected for threats, except for traffic destined for financial institutions. The Palo Alto Networks firewall is configured with a Decryption Policy. Which two decryption policy rules, in the correct order, would satisfy this requirement?Security Policy Configuration
- 173.A security engineer is configuring administrative access to a new Palo Alto Networks firewall. The company policy dictates that all administrative logins must use a centralized authentication system and secure protocols. Which combination of settings should the engineer configure on the firewall to meet these requirements?Initial Configuration and Management
- 174.A network administrator is performing the initial setup of a Palo Alto Networks firewall. The firewall will be managed via its management interface. Which of the following is a mandatory step to ensure the firewall can communicate with external services like DNS servers and NTP servers for management plane operations?Initial Configuration and Management
- 175.A network engineer is configuring a new Palo Alto Networks firewall in a data center. The firewall will be deployed in Layer 3 mode and needs to connect to multiple VLANs, each requiring its own IP address and routing capabilities. Which interface type is most appropriate for this scenario to efficiently manage traffic for each VLAN?Initial Configuration and Management
- 176.A network security architect is designing a high-availability (HA) solution for a pair of Palo Alto Networks firewalls. The requirement is to minimize network disruption during a failover event, ensuring that active sessions are maintained. Which HA mode and feature combination should the architect choose?Initial Configuration and Management
- 177.A network engineer is configuring a new Palo Alto Networks firewall that will operate in a network segment where both Layer 2 and Layer 3 traffic forwarding are required on the same physical interface. Specifically, the firewall needs to perform Layer 2 switching for some VLANs and Layer 3 routing for others, all through a single physical port. Which advanced interface configuration allows this mixed mode operation?Initial Configuration and Management
- 178.A network engineer is preparing to install a PAN-OS software update on a Palo Alto Networks firewall. Before initiating the installation, the engineer needs to ensure that the firewall has sufficient resources and is in a healthy state. Which of the following pre-installation checks is considered a best practice?Initial Configuration and Management
- 179.A company is implementing a new Palo Alto Networks firewall and requires a robust method for centralized management, policy deployment, and log collection across multiple firewalls globally. Which Palo Alto Networks product is designed specifically for this purpose?Initial Configuration and Management
- 180.A network technician is performing initial setup on a new Palo Alto Networks firewall. The firewall needs to obtain licenses and dynamic updates (Antivirus, Applications and Threats) from Palo Alto Networks' update servers. Which unique identifier is required for the firewall to register and authenticate with the Palo Alto Networks licensing and update infrastructure?Initial Configuration and Management
- 181.A network administrator is setting up a new Palo Alto Networks firewall and needs to configure the management interface to allow only specific administrative services from a defined management subnet. Which feature should be used to restrict access to the management interface?Initial Configuration and Management
- 182.A network administrator needs to ensure that the Palo Alto Networks firewall's clock is accurately synchronized with a reliable time source. This is critical for accurate logging, certificate validation, and security policy enforcement. Which protocol should be configured on the firewall for this purpose?Initial Configuration and Management
- 183.A network security engineer is setting up a new Palo Alto Networks firewall. To ensure that the firewall can correctly resolve domain names for services like WildFire, URL filtering, and software updates, which of the following steps is crucial for DNS configuration?Initial Configuration and Management
- 184.A network administrator is performing the initial setup of a new Palo Alto Networks firewall. After connecting to the console, they need to manually configure the management interface with a static IP address, netmask, and default gateway to allow GUI access. Which command-line interface (CLI) command set is used for this purpose?Initial Configuration and Management
- 185.A network technician is performing a PAN-OS software upgrade on a Palo Alto Networks firewall. After downloading the new PAN-OS image, what is the next critical step before initiating the installation process to ensure a smooth and successful upgrade?Initial Configuration and Management
- 186.A network security architect is designing a high-availability (HA) solution for a pair of Palo Alto Networks firewalls. They aim for seamless failover of traffic and session synchronization. Which of the following is a critical prerequisite for successful HA session synchronization between the two firewalls?Initial Configuration and Management
- 187.A company is integrating a new Palo Alto Networks firewall into their existing network infrastructure. The firewall needs to obtain its IP address and other network configuration details dynamically from a DHCP server during initial setup. Which configuration method should the network administrator choose for the interface?Initial Configuration and Management
- 188.A network engineer is configuring a new Palo Alto Networks firewall and needs to enable IPv6 connectivity on a Layer 3 interface. After assigning an IPv6 address, the engineer attempts to ping an IPv6 host on a different subnet but fails. All security policies are temporarily set to 'allow any'. What is a common missing configuration for IPv6 routing on Layer 3 interfaces that might cause this issue?Initial Configuration and Management
- 189.A network administrator needs to verify the current software version, content version, and license status of a Palo Alto Networks firewall. From which location in the WebUI can this information be most efficiently accessed?Initial Configuration and Management
- 190.A security auditor is reviewing the administrative access configuration on a Palo Alto Networks firewall. They observe that multiple administrators are using a shared local 'admin' account with a generic password. To improve security and accountability, which administrative access method should be implemented to ensure unique user authentication and centralized management of credentials?Initial Configuration and Management
- 191.A network administrator is performing the initial setup of a new Palo Alto Networks firewall. They have configured the management interface and basic network settings. To ensure that the firewall can communicate with external services for updates, WildFire, and DNS, which type of route must be configured on the firewall if it's not directly connected to the internet?Initial Configuration and Management
- 192.A company is integrating a new Palo Alto Networks firewall into their existing network infrastructure. The firewall's management interface needs to dynamically obtain an IP address, subnet mask, and default gateway from an upstream network device. Which network configuration mode should be selected for the management interface to achieve this?Initial Configuration and Management
- 193.A network administrator needs to verify the current software version, content version, and license status of a Palo Alto Networks firewall to troubleshoot a content update issue. Which CLI command provides this comprehensive device information?Initial Configuration and Management
- 194.A network security administrator needs to ensure that the Palo Alto Networks firewall's clock is synchronized with a reliable external time source. This is crucial for accurate logging, certificate validation, and security policy enforcement. Which setting should be configured to achieve this?Initial Configuration and Management
- 195.A network administrator is performing the initial setup of a new Palo Alto Networks firewall. They need to configure the management interface to use a static IP address, subnet mask, and default gateway. Which of the following is the correct sequence of steps to achieve this using the command-line interface (CLI)?Initial Configuration and Management
- 196.A network engineer is configuring a Palo Alto Networks firewall in a network segment where the firewall needs to perform both Layer 2 switching and Layer 3 routing functions for different traffic types on the same physical interface. Which interface type allows this mixed functionality?Initial Configuration and Management
- 197.A network administrator is setting up a new Palo Alto Networks firewall and needs to configure a default route for all outbound traffic from the firewall itself, such as for accessing external services like DNS, NTP, and software updates. Which of the following interface types is typically used to define this default route?Initial Configuration and Management
- 198.A hospital network needs to implement robust security measures to protect patient health information (PHI) and critical medical devices. They are concerned about both external attacks and insider threats. Which security architecture philosophy emphasizes continuous verification and assumes that no user, device, or application should be trusted by default, regardless of its location?Cybersecurity Fundamentals
- 199.A security analyst is investigating a series of unauthorized access attempts originating from a compromised internal workstation. The attacker appears to be attempting to move laterally within the network to gain access to a critical database server. Which stage of the Cyber Attack Kill Chain does this activity most closely represent?Cybersecurity Fundamentals
- 200.A company is developing a new cloud-native application that will handle sensitive customer data. The development team wants to ensure that security is integrated throughout the entire software development lifecycle (SDLC), rather than being an afterthought. Which cybersecurity best practice aligns with this approach?Cybersecurity Fundamentals