Palo Alto Networks Certified Network Security Engineer (PCNSE) practice questions
207 free questions with answers and explanations.
- 1.A network security team needs to implement QoS on a Palo Alto Networks firewall to prioritize voice (SIP/RTP) and video conferencing traffic over general web browsing and bulk data transfers. The goal is to ensure real-time communication applications receive preferential treatment during network congestion. Which QoS configuration element is primarily responsible for classifying and marking traffic to be prioritized?Deploy and Configure
- 2.A large enterprise is integrating Palo Alto Networks firewalls with their existing Splunk SIEM for centralized log analysis. They need to ensure that all traffic, threat, and system logs are reliably sent to Splunk. Which component on the Palo Alto Networks firewall is responsible for sending these logs to an external syslog server?Deploy and Configure
- 3.A network architect is designing a new branch office deployment that requires a secure, encrypted tunnel back to the corporate headquarters. Both sites use Palo Alto Networks firewalls. The branch office has a dynamic public IP address. Which type of site-to-site VPN configuration is best suited for this scenario?Deploy and Configure
- 4.A company is deploying a new web application and requires granular control over traffic based on the specific application being used, rather than just ports and protocols. They need to ensure only approved applications can access the web server. Which Palo Alto Networks firewall feature allows for this application-level control?Deploy and Configure
- 5.A company is upgrading its data center and is consolidating several physical firewalls into a single Palo Alto Networks firewall pair in an Active/Passive HA configuration. The network team needs to ensure that if the active firewall fails, the passive firewall takes over seamlessly with minimal disruption to existing TCP sessions. Which HA sync option is critical for achieving this requirement?Deploy and Configure
- 6.A network security engineer is deploying a new Palo Alto Networks firewall and needs to integrate it into an existing network that uses OSPF for dynamic routing. The firewall must advertise its connected networks to the OSPF domain and learn routes from other OSPF routers. Which configuration step is essential to enable OSPF routing on the firewall?Deploy and Configure
- 7.A network security administrator needs to configure a NAT policy to allow internal users to access an external web server using a specific public IP address that is different from the firewall's egress interface IP. Which type of NAT configuration is required?Deploy and Configure
- 8.A security architect is designing a high-performance network where multiple firewalls need to share the load of processing traffic for a large number of users. The design requires that both firewalls actively process traffic simultaneously to maximize throughput. Which HA mode would best meet this requirement?Deploy and Configure
- 9.A company is implementing a new wireless network and requires all wireless clients to be placed into a separate security zone, distinct from the wired LAN. This new zone needs its own security policies to control access to internal resources. Which type of interface configuration is best suited for connecting the wireless access points to the Palo Alto Networks firewall while maintaining logical separation?Deploy and Configure
- 10.A company is migrating its network infrastructure to a new data center and requires a seamless transition for its critical applications. During this migration, they need to implement a security solution that can inspect traffic without requiring any changes to the existing network topology (IP addresses, routing). Which Palo Alto Networks interface configuration would best meet this requirement for transparent inspection?Deploy and Configure
- 11.A company is implementing GlobalProtect for remote users and requires that all users authenticate against their existing Active Directory infrastructure. Which configuration element is essential for this requirement?Deploy and Configure
- 12.A network administrator is configuring a new Palo Alto Networks firewall. The internal network uses 192.168.1.0/24, and the DMZ uses 172.16.10.0/24. The administrator needs to define a logical segment that groups interfaces with similar security requirements and allows traffic to flow between these interfaces based on security policies. Which configuration element should be used for this purpose?Deploy and Configure
- 13.A network administrator is configuring a Palo Alto Networks firewall for a new branch office. The branch needs to use a full mesh VPN topology with other branch offices, but the public IP addresses of some branches are dynamic. Which GlobalProtect component is specifically designed to handle dynamic IP addresses for VPN tunnels?Deploy and Configure
- 14.A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party device. The third-party device requires the use of IKEv2 with AES256-GCM for encryption and SHA384 for authentication in Phase 2. Which IKE Crypto Profile and IPsec Crypto Profile settings are required?Deploy and Configure
- 15.A network architect is designing a new data center and needs to ensure that critical applications receive preferential bandwidth during periods of congestion. Which QoS configuration element directly applies prioritization to specific traffic types?Deploy and Configure
- 16.A network administrator is configuring a new Palo Alto Networks firewall and observes that the dataplane CPU utilization is consistently high, even under moderate traffic load. Upon inspection, it's discovered that the firewall is performing decryption on all traffic, including streaming video and large file transfers, which are not security-sensitive but consume significant resources. Which decryption policy rule modification would most effectively reduce dataplane CPU utilization without compromising security for critical applications?Deploy and Configure
- 17.A network administrator is troubleshooting an issue where internal users are unable to access a specific external web service. Packet captures on the firewall show that the initial SYN packet from the internal user is leaving the firewall, but no SYN-ACK is being received. Upon checking the security policy, the administrator confirms that an 'allow' rule exists for the application and source/destination zones. What is the MOST likely root cause of this connectivity issue, assuming external reachability is confirmed?Deploy and Configure
- 18.A network security team is configuring Quality of Service (QoS) on a Palo Alto Networks firewall to prioritize voice over IP (VoIP) traffic over standard web browsing. They need to ensure that VoIP packets receive preferential treatment throughout the network. Which QoS mechanism can be used on the firewall to mark VoIP traffic so that downstream devices also recognize and prioritize it?Deploy and Configure
- 19.An organization uses Panorama to manage multiple Palo Alto Networks firewalls across different geographical locations. They need to ensure that all firewalls log to a central SIEM system using syslog. Which Panorama object should be configured and pushed to the firewalls to achieve this?Deploy and Configure
- 20.A network administrator is troubleshooting an issue where external users cannot access a web server located in the DMZ (172.16.1.10) from the internet. The internet-facing interface IP is 203.0.113.5. A Security policy rule is already in place to allow the traffic. Which NAT policy configuration is required to allow external users to reach the web server?Deploy and Configure
- 21.A company is integrating their Palo Alto Networks firewall with an existing Active Directory infrastructure to provide user-based security policies for internal users. They need to ensure that the firewall can query Active Directory for user and group information. Which authentication profile type is primarily used for this integration to retrieve user identity information?Deploy and Configure
- 22.A network security engineer is deploying a new Palo Alto Networks firewall and needs to ensure that all management traffic (SSH, HTTPS, SNMP) to the firewall itself is restricted to a specific management network. Which configuration element should be applied to the interface designated for management access?Deploy and Configure
- 23.A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall itself can resolve DNS queries for internal and external resources. Which configuration setting is required on the firewall?Deploy and Configure
- 24.A network engineer needs to configure a NAT policy on a Palo Alto Networks firewall to allow internal users to access external resources using a single public IP address. This type of NAT allows multiple internal IP addresses to be translated to a single public IP address. Which NAT type should be configured?Deploy and Configure
- 25.A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN device. The engineer needs to define the encryption, authentication, and Diffie-Hellman group for both IKE Phase 1 and IKE Phase 2. Which configuration objects are used for this purpose?Deploy and Configure
- 26.A network administrator needs to configure a Palo Alto Networks firewall to prevent unauthorized access to the management interface from untrusted networks. Which type of rule should be configured?Deploy and Configure
- 27.An organization is deploying a new web application server in a DMZ, which must be accessible from the internet. The security team requires that all inbound connections to this server on port 443 be translated to a specific internal IP address while preserving the source IP of the client for logging purposes. Which NAT type should be configured on the Palo Alto Networks firewall?Deploy and Configure
- 28.A security auditor discovers that a critical web server in the DMZ is still accessible via HTTP (port 80) despite a security policy intending to restrict access to HTTPS (port 443) only. Upon inspection, the security policy is configured as follows: Source Zone: Any, Destination Zone: DMZ, Application: web-browsing, Service: application-default, Action: Allow. What is the most likely reason for HTTP traffic still being allowed?Deploy and Configure
- 29.A network security team needs to implement a High Availability (HA) solution for two Palo Alto Networks firewalls. They decide to configure Active/Passive HA. Which of the following is a key characteristic of an Active/Passive HA configuration?Deploy and Configure
- 30.A company is implementing User-ID on their Palo Alto Networks firewall to provide user-based security policies. After configuring the User-ID agent to monitor their Active Directory domain controllers, the administrator notices that user-to-IP mappings are not being populated on the firewall. Which of the following is a common reason for this issue?Deploy and Configure
- 31.A company is deploying a new application server in their DMZ and needs to ensure that only specific applications, such as HTTPS and SSH for management, are allowed to access it from the untrusted (Internet) zone. Which security policy configuration element should be used to precisely define the allowed applications?Deploy and Configure
- 32.A global enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls across different regions. A new set of security policies and network objects needs to be deployed to all firewalls in the EMEA region exclusively, without affecting firewalls in other regions. Which Panorama concept should the administrator leverage to achieve this targeted deployment?Deploy and Configure
- 33.A data center migration project requires replacing an older firewall with a new Palo Alto Networks firewall. The existing network infrastructure uses VLANs extensively, and the new firewall must integrate seamlessly without altering the Layer 2 network topology. The firewall will perform security inspection between different VLANs within the same physical interface. Which interface type is most appropriate for this scenario?Deploy and Configure
- 34.A security auditor requires that all encrypted web traffic (SSL/TLS) passing through the Palo Alto Networks firewall must be inspected for threats and vulnerabilities. Users complain about certificate warnings when accessing certain websites after decryption is enabled. Which aspect of decryption configuration is MOST likely causing these user complaints?Deploy and Configure
- 35.A global enterprise needs to manage hundreds of Palo Alto Networks firewalls deployed across different geographical locations from a centralized platform. They require consistent security policies, shared objects, and centralized logging and reporting. Which Palo Alto Networks product is designed to meet these requirements?Deploy and Configure
- 36.A security engineer is configuring a new Palo Alto Networks firewall and needs to ensure that it operates in a high-availability active/passive configuration. Which component must be configured to synchronize the session state between the two firewalls?Deploy and Configure
- 37.A network administrator is configuring a new Palo Alto Networks firewall. The firewall needs to be able to route traffic between multiple VLANs and connect to the internet. Which interface type should be configured on the firewall to allow it to participate in routing protocols and forward traffic between different subnets?Deploy and Configure
- 38.A company is implementing a new voice-over-IP (VoIP) system and requires that all SIP (Session Initiation Protocol) and RTP (Real-time Transport Protocol) traffic be prioritized over general web browsing traffic. Which Quality of Service (QoS) configuration element should be used to achieve this prioritization?Deploy and Configure
- 39.A security auditor requires that all HTTP/HTTPS traffic from the internal network to the internet must be inspected for malware and blocked if threats are detected. However, traffic to a specific financial institution's website must bypass SSL decryption due to compliance reasons. Which decryption configuration is required to meet these requirements?Deploy and Configure
- 40.A network security team needs to implement decryption for outbound HTTPS traffic to inspect for malware and prevent data exfiltration. However, financial and healthcare website traffic must remain undecrypted due to compliance requirements. Which decryption deployment method should be used?Deploy and Configure
- 41.A company is implementing GlobalProtect for remote users to securely access internal resources. The security team wants to ensure that users are authenticated against their existing Microsoft Active Directory infrastructure. Which external authentication method should be configured on the Palo Alto Networks firewall for GlobalProtect portals and gateways?Deploy and Configure
- 42.A security operations center (SOC) needs to integrate the Palo Alto Networks firewall logs with their existing Splunk Enterprise SIEM for real-time analysis and alerting. The Splunk instance is configured to receive logs via syslog over UDP on port 514. Which log forwarding method should be configured on the Palo Alto Networks firewall to ensure logs are sent to Splunk?Deploy and Configure
- 43.A security engineer is configuring a site-to-site VPN between two Palo Alto Networks firewalls. The goal is to ensure that only authenticated and authorized devices can establish the VPN tunnel. Which authentication method is commonly used and recommended for establishing secure IPsec VPN tunnels between firewalls?Deploy and Configure
- 44.A network security engineer needs to configure a Palo Alto Networks firewall to prevent unauthorized access to the management interface from the internet. Which security zone type should be assigned to the interface connected to the internet to achieve this, while allowing legitimate traffic through other zones?Deploy and Configure
- 45.A global organization uses multiple Palo Alto Networks firewalls deployed across different regions. The security team needs a centralized platform to manage, monitor, and deploy consistent security policies across all firewalls. Which Palo Alto Networks product is designed to fulfill this requirement?Deploy and Configure
- 46.A security auditor requires that all changes made to the firewall configuration, including who made them and when, are logged and immutable. Which feature on the Palo Alto Networks firewall ensures the integrity and auditability of configuration changes?Deploy and Configure
- 47.A company policy mandates that all outbound HTTPS traffic from the 'Internal-User' zone to the 'Untrust' zone must be decrypted for inspection, except for traffic destined to financial websites and healthcare providers. How should this decryption policy be configured to balance security inspection with privacy and compliance requirements?Manage and Operate
- 48.A network administrator is configuring a Palo Alto Networks firewall for High Availability (HA) in an active/passive configuration. The firewall has two data interfaces (ethernet1/1, ethernet1/2) and two HA interfaces (HA1, HA2). Which of the following statements accurately describes the recommended configuration for the HA2 link?Manage and Operate
- 49.A network engineer is configuring a new High Availability (HA) active/passive pair of Palo Alto Networks firewalls. During the initial setup, the engineer notices that the HA state remains 'non-functional' on both devices, and messages like 'HA Link heartbeat failed' are observed. The HA control link is directly connected between the two firewalls. What is the most common and often overlooked configuration error that can cause this issue?Manage and Operate
- 50.A network administrator needs to create a security policy rule that applies to all users located in the 'Internal-LAN' zone, regardless of their specific IP address. The rule should allow them to access external web services. Which object type should be used in the Source User field of the security policy rule to achieve this?Manage and Operate