Palo Alto Networks Certified Network Security Engineer (PCNSE) practice questions

207 free questions with answers and explanations.

Practice test
  1. 51.A network administrator is troubleshooting an issue where users are unable to access a newly deployed internal web application. The application server is located in the 'Internal-Server' zone, and users are in the 'Internal-User' zone. The security policy allowing this traffic is configured as Source: Internal-User, Destination: Internal-Server, Application: web-browsing, Service: application-default, Action: Allow. However, the firewall traffic logs show sessions being dropped with the 'incomplete' application. What is the most likely cause of this issue?Manage and Operate
  2. 52.A network engineer is configuring a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. The third-party device requires the use of Diffie-Hellman Group 14 for IKE Phase 1. Which configuration setting on the Palo Alto Networks firewall must be adjusted to ensure successful Phase 1 establishment?Manage and Operate
  3. 53.A network administrator needs to create a security policy rule that applies to all users located in the 'Internal-LAN' zone, regardless of their specific IP address. The rule should allow them to access external web services. Which object type should be used in the Source User field of the security policy rule to achieve this?Manage and Operate
  4. 54.A security auditor requires a weekly report of all applications categorized as 'high-risk' that have traversed the firewall, including source IP, destination IP, user, and session duration, for the last 7 days. This report needs to be automatically generated and emailed to the auditor every Monday morning. Which two Panorama features would you configure to meet this requirement?Manage and Operate
  5. 55.A network engineer is configuring a new High Availability (HA) active/passive pair of Palo Alto Networks firewalls. During the initial setup, the engineer notices that the HA state remains 'non-functional' on both devices, and messages like 'HA Link heartbeat failed' are observed. The HA control link is directly connected between the two firewalls. What is the most common and often overlooked configuration error that can cause this issue?Manage and Operate
  6. 56.A security auditor requires a daily report of all blocked connections originating from the 'Guest-WiFi' zone to any internal network resources. The report should include the source IP, destination IP, application, and the reason for blocking. Which Panorama reporting feature would best fulfill this requirement?Manage and Operate
  7. 57.A security analyst is investigating a suspected malware infection originating from an internal host. The analyst needs to quickly determine if the host has communicated with known malicious IP addresses or domains. Which type of external service integration would provide the most direct and real-time threat intelligence for this investigation within the Palo Alto Networks firewall?Manage and Operate
  8. 58.A network administrator is configuring a Palo Alto Networks firewall for High Availability (HA) in an active/passive configuration. The firewall has two data interfaces (ethernet1/1, ethernet1/2) and two HA interfaces (HA1, HA2). Which of the following statements accurately describes the recommended configuration for the HA2 link?Manage and Operate
  9. 59.A network administrator is implementing a new application on a server in the DMZ. The application uses a non-standard port 8443 for HTTPS communication and port 8080 for HTTP. The administrator needs to create an Application Override policy to ensure these applications are correctly identified and inspected by the Palo Alto Networks firewall, rather than being identified as 'web-browsing' or 'ssl'. What is the correct configuration approach for the Application Override policy?Manage and Operate
  10. 60.A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls globally. They have implemented a standard security policy that applies to most firewalls, defined in a Device Group. However, a specific branch office firewall requires two unique security rules that must always be evaluated *before* any of the standard rules from the Device Group. How should these unique rules be configured in Panorama to ensure they take precedence?Manage and Operate
  11. 61.A network administrator needs to ensure that only approved applications can traverse the firewall, regardless of the port or protocol they attempt to use. Which security policy action is most effective for achieving this goal while preventing unknown or unapproved applications?Manage and Operate
  12. 62.A company is integrating a new cloud-based HR application. The application developers require outbound access from their internal network to specific FQDNs for API calls and updates. The network security team needs to ensure that only traffic destined for these FQDNs is allowed, and no direct IP address access, as the cloud provider's IPs may change frequently. Which type of object should be used in the security policy to achieve this granular control?Manage and Operate
  13. 63.A security engineer is troubleshooting an issue where a new GlobalProtect gateway is not establishing VPN tunnels with remote users. The firewall's system logs show 'SSL handshake failed' messages. Upon checking the gateway configuration, the engineer notices that the server certificate configured for the GlobalProtect gateway is signed by an internal Certificate Authority (CA) that is not trusted by the remote user devices. What is the most probable cause of the SSL handshake failure?Manage and Operate
  14. 64.A network security administrator is configuring a new firewall for a data center. The data center hosts multiple critical servers, and the security policy requires that all servers in the 'DMZ' zone can initiate connections to servers in the 'Internal_Prod' zone on specific ports, but 'Internal_Prod' servers should never initiate connections back to the 'DMZ'. Additionally, 'Internal_Prod' servers must not initiate connections to each other, except for specific database replication traffic. How should the administrator design the security policy rules to enforce these requirements with the principle of least privilege?Manage and Operate
  15. 65.A network security engineer is tasked with configuring a Palo Alto Networks firewall to allow only specific applications to access the internet, while blocking all other traffic. The security policy currently contains a broad 'allow-all-outbound' rule at the bottom. Which of the following actions should the engineer take to ensure only the approved applications are permitted?Manage and Operate
  16. 66.A company policy dictates that all outbound HTTPS traffic must be decrypted for inspection, except for connections to financial institutions. The security engineer has created a Decryption Profile and a Decryption Policy rule to decrypt traffic. To exclude financial institutions, which component should be used in the Decryption Policy rule and how should it be configured?Manage and Operate
  17. 67.A security administrator observes that after a recent content update, a critical internal application (Application-X) is no longer matching its specific security policy rule and is instead being caught by a broader 'deny-all' rule. Upon investigation, it's found that Application-X is now being identified as 'web-browsing' instead of its unique application ID. What is the most likely cause for this behavior?Manage and Operate
  18. 68.A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall can accurately identify users from a Microsoft Active Directory domain. Which User-ID agent type should be configured to integrate directly with Active Directory domain controllers to collect user-to-IP address mappings?Manage and Operate
  19. 69.A company is implementing a new network segment for IoT devices. The security policy dictates that these devices should only be allowed to communicate with a specific MQTT broker server located in the DMZ, and no other internal or external resources. The IoT devices are in the 'IoT-Zone' and the MQTT broker is in the 'DMZ-Zone'. Which combination of security policy rules and settings would best enforce this requirement?Manage and Operate
  20. 70.A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls globally. A new security compliance requirement mandates that all firewalls log sessions to a central syslog server, regardless of whether the traffic is allowed or denied. The syslog server configuration is identical for all firewalls. Which Panorama object should the administrator configure to efficiently push this syslog server setting to all managed devices, ensuring consistent logging behavior?Manage and Operate
  21. 71.A company is upgrading its Palo Alto Networks firewalls and needs to manage multiple devices from a central location. They plan to use Panorama for centralized management. The security team wants to ensure that all firewalls consistently apply a base set of security policies and network configurations, while also allowing some unique settings for specific firewalls. Which Panorama feature should be primarily leveraged to achieve this balance?Manage and Operate
  22. 72.A network administrator needs to troubleshoot an issue where users are reporting slow access to an external SaaS application. The firewall's traffic logs show sessions to the SaaS application, but the 'Action' column indicates 'deny' for some connections, while others show 'allow'. The security policy contains multiple rules that could potentially match this traffic based on source, destination, and application. What is the most effective first step to identify which specific security policy rule is responsible for denying the traffic?Manage and Operate
  23. 73.A network administrator needs to generate a report detailing all successful and failed user authentications to the firewall's management interface (via SSH, HTTPS, or console) over the last 24 hours. Which log type should the administrator query to gather this specific information?Manage and Operate
  24. 74.A company is implementing a new GlobalProtect VPN solution for their remote users. They require that internal resources are only accessible if the user's endpoint meets specific security requirements, such as having up-to-date antivirus software and a firewall enabled. Which GlobalProtect component is primarily responsible for enforcing these endpoint security checks before allowing full network access?Manage and Operate
  25. 75.A company is implementing High Availability (HA) for their critical Palo Alto Networks firewalls in an Active/Passive configuration. The network team observes that during a failover event, there is a brief interruption in network traffic, even though the passive firewall successfully takes over. They want to minimize this traffic interruption as much as possible. Which HA synchronization setting, when properly configured, is designed to reduce traffic loss during a failover by ensuring session and configuration consistency?Manage and Operate
  26. 76.A network administrator is troubleshooting an issue where users are experiencing very slow loading times for certain web pages that contain a significant amount of encrypted traffic (HTTPS). Decryption is enabled on the Palo Alto Networks firewall for outbound traffic. The firewall's data plane CPU utilization is consistently high, and the session table shows a large number of sessions with 'decrypt-mirror' or 'decrypt-forward' flags. What is the MOST likely cause of the slow loading times?Troubleshoot
  27. 77.A company is experiencing issues with User-ID where some users are not being correctly mapped to their IP addresses, leading to incorrect policy enforcement. The Palo Alto Networks firewall is configured to use the Windows User-ID agent. What is the MOST effective troubleshooting step to verify if the User-ID agent is correctly collecting and sending user-to-IP mappings to the firewall?Troubleshoot
  28. 78.A network security administrator is troubleshooting a Panorama deployment. When attempting to push configuration from Panorama to a managed firewall, the push fails with an error indicating a 'commit lock' on the firewall. What is the MOST appropriate initial action to resolve this issue?Troubleshoot
  29. 79.A network administrator is troubleshooting an issue where users on the internal network are unable to access a specific external web service. Packet captures on the Palo Alto Networks firewall show traffic leaving the internal interface towards the internet, but no return traffic is observed. Security policies are in place allowing the outbound traffic. Which of the following is the MOST likely cause of this issue?Troubleshoot
  30. 80.A network administrator is investigating a report of intermittent application failures for a critical internal web application. The Palo Alto Networks firewall is configured with a security policy allowing the application, and initial checks show traffic hitting the policy. However, logs indicate some sessions are being reset by the firewall. The administrator suspects a threat prevention profile might be aggressively blocking legitimate traffic. Which type of security profile is MOST likely causing the legitimate application traffic to be reset?Troubleshoot
  31. 81.A network engineer is investigating an issue where users are unable to authenticate to a new external RADIUS server configured on a Palo Alto Networks firewall. The firewall's authentication server profile for RADIUS is correctly configured with the server IP, shared secret, and port. The authentication profile is referencing this server profile. However, when users attempt to authenticate, the firewall logs show 'authentication failed for user <username> via RADIUS server, reason: server not responding'. What is the MOST likely cause?Troubleshoot
  32. 82.A network administrator has configured a new GlobalProtect gateway and portal. Users can successfully connect to the GlobalProtect portal and authenticate, but when they attempt to connect to the gateway, the connection fails. The GlobalProtect gateway logs show 'Failed to find a suitable tunnel interface'. What is the MOST likely cause of this issue?Troubleshoot
  33. 83.A network security engineer is troubleshooting a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN gateway. Phase 1 of IKE is failing to establish. The firewall logs indicate 'Phase 1 negotiation failed due to no acceptable proposal'. Which configuration parameter is MOST likely mismatched between the two VPN peers?Troubleshoot
  34. 84.A network administrator is troubleshooting an issue where a specific application, 'ExampleApp', is consistently being identified as 'incomplete' by the Palo Alto Networks firewall, despite users reporting that the application functions correctly. This leads to inconsistent policy enforcement. The administrator suspects the application's unique traffic pattern might be causing the misidentification. Which troubleshooting command would provide the MOST relevant information to understand how the firewall is classifying the 'ExampleApp' traffic?Troubleshoot
  35. 85.A security engineer is performing routine maintenance on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. After performing a 'suspend local' command on the active firewall, the passive firewall fails to transition to the active state. Investigation reveals that the passive firewall's HA state is 'non-functional'. What is the MOST likely reason for the passive firewall being in a 'non-functional' state?Troubleshoot
  36. 86.A technician is troubleshooting a network connectivity issue on a Palo Alto Networks firewall. After making a configuration change, a specific internal host can no longer reach an external server. The technician suspects a routing issue. Which CLI command would the technician use to verify the effective routing path for traffic originating from the internal host's IP address to the external server's IP address, including any policy-based forwarding or NAT effects?Troubleshoot
  37. 87.A security engineer is troubleshooting an issue where users are intermittently experiencing slow application performance when accessing an internal web server protected by a Palo Alto Networks firewall. The firewall logs show a high number of 'deny' actions for 'incomplete' and 'aged-out' sessions originating from the user subnet to the web server. What is the MOST likely cause of these symptoms?Troubleshoot
  38. 88.A web server administrator reports that users are unable to access a newly deployed web application hosted on an internal server. The Palo Alto Networks firewall is configured with a Destination NAT policy to translate the public IP address to the internal web server's private IP. Security policies are in place to allow the traffic. Using the 'test security-policy-match' command on the firewall, the administrator observes that the traffic is hitting the correct security policy, but the 'action' shown is 'deny' even though the policy is configured to 'allow'. What is the MOST likely reason for this discrepancy?Troubleshoot
  39. 89.A company is planning to deploy GlobalProtect for remote users, requiring full tunnel VPN connectivity and user-based policy enforcement. The design specifies that all remote user traffic must be inspected by the corporate firewall, regardless of destination. Which GlobalProtect gateway configuration type ensures this requirement is met?Plan and Design
  40. 90.A network architect is designing a security policy for a web application hosted on a server in the 'DMZ' zone. The application needs to access a specific database server in the 'DB' zone. The policy must strictly adhere to the principle of least privilege, allowing only the necessary application and port. Which security policy configuration best embodies the principle of least privilege for this communication?Plan and Design
  41. 91.An organization is migrating its data center and needs to implement a new network design that ensures traffic from the client-facing web servers in the 'Web-DMZ' zone can only access the backend application servers in the 'App-DMZ' zone, and only on specific application ports. No direct internet access should be allowed from 'App-DMZ' servers. Which of the following security zone design principles is primarily being applied?Plan and Design
  42. 92.A network architect is designing a NAT policy for a new segment of IoT devices. These devices need to access external cloud services using a single public IP address, and their internal IP addresses must be hidden from the internet. The design requires that outbound connections initiate from the IoT devices to the cloud services. Which NAT type is most appropriate for this scenario?Plan and Design
  43. 93.A network security architect is designing a high-availability (HA) solution for a pair of Palo Alto Networks firewalls. The requirement is to minimize downtime during a firewall failure, with the active firewall handling all traffic and the passive firewall taking over immediately upon failure. Which HA mode should be configured to meet this requirement?Plan and Design
  44. 94.A network architect is designing a redundant external service solution for DNS and NTP servers, which are critical for firewall operations. The design requires that if the primary external DNS or NTP server becomes unreachable, the firewall automatically switches to a secondary server without manual intervention. Which configuration element ensures this automatic failover for external services?Plan and Design
  45. 95.A network security engineer is designing a new security policy for a critical application server that processes highly sensitive financial data. The server must only allow inbound connections on TCP port 443 from a specific set of public IP addresses provided by a third-party payment gateway. All other inbound and outbound traffic must be denied. Which two elements are most critical to define in the security policy rule to meet these requirements with the highest level of granularity?Plan and Design
  46. 96.A global organization is deploying Panorama to manage 200 Palo Alto Networks firewalls across various regions. The security team needs to ensure that administrators in each region can only manage firewalls within their respective region and have read-only access to firewall logs from other regions. Which Panorama design feature is essential for implementing this granular access control?Plan and Design
  47. 97.An organization is deploying a Palo Alto Networks firewall to protect a demilitarized zone (DMZ) containing web servers and application servers. The security policy design requires that specific web applications (e.g., 'web-browsing', 'ssl') are allowed from the internet to the web servers, but only 'ms-rdp' and 'ssh' are allowed from a jump host in the management zone to the application servers. All other traffic should be denied. What is the most effective approach to structure these security policies?Plan and Design
  48. 98.A network security architect is designing a decryption policy for an organization that has strict privacy requirements, prohibiting the decryption of traffic to financial and healthcare websites. All other outbound web traffic must be decrypted for threat inspection. Which decryption policy rule type should be used to ensure that sensitive categories are never decrypted, while allowing decryption for all other relevant traffic?Plan and Design
  49. 99.A large enterprise with multiple geographically dispersed data centers needs to consolidate their log management and reporting for all Palo Alto Networks firewalls. Each data center has 50 firewalls, and there are 5 data centers in total. The security team requires at least 90 days of log retention for all log types (traffic, threat, URL, data, wildfire, system, config) and expects a daily average log rate of 10,000 logs/second across the entire deployment. Which Panorama log collector group design would be most appropriate and cost-effective?Plan and Design
  50. 100.A network administrator needs to design a NAT policy for a segment of internal servers that must initiate connections to the internet. These servers have private IP addresses and require their source IP addresses to be translated to a single public IP address from a pool for outbound connections. What type of NAT should be configured on the Palo Alto Networks firewall?Plan and Design