Palo Alto Networks Certified Network Security Engineer (PCNSE) practice questions

207 free questions with answers and explanations.

Practice test
  1. 151.A network architect is explaining the Palo Alto Networks Single-Pass Parallel Processing (SP3) architecture to a new team member. The architect emphasizes that this architecture allows the firewall to perform multiple security functions simultaneously on a single packet. Which core benefit does SP3 provide compared to traditional multi-pass architectures?Core Concepts
  2. 152.A security engineer is investigating a sudden increase in CPU utilization on a Palo Alto Networks firewall, specifically observing high usage by the 'mp-packet-processing' process. The firewall is configured for decryption and has multiple security profiles enabled. Which component is primarily responsible for offloading computationally intensive tasks like decryption and threat inspection to improve performance?Core Concepts
  3. 153.A security administrator is configuring a new Palo Alto Networks firewall and needs to ensure that internal users can access external websites securely. The administrator has configured a security policy to allow web-browsing applications. To prevent users from accessing malicious or inappropriate websites, which security profile should be attached to this policy?Core Concepts
  4. 154.A network security administrator is configuring a new Palo Alto Networks firewall and wants to ensure that all traffic destined for the internet is routed through a specific external gateway. Which type of interface configuration would best support this requirement for the external-facing port?Core Concepts
  5. 155.A security administrator is reviewing the packet flow logic on a Palo Alto Networks firewall to understand how a specific connection is processed. After ingress stage and policy lookup, the packet undergoes Layer 7 inspection. Which component of the firewall's single-pass architecture is primarily responsible for performing this deep packet inspection and applying security profiles?Core Concepts
  6. 156.A large organization is deploying a Palo Alto Networks firewall at its edge to inspect all inbound and outbound traffic. The security team wants to ensure that all SSL/TLS encrypted traffic can be inspected for threats and compliance, regardless of the destination. Which decryption method is required for this comprehensive inspection of traffic where the firewall acts as a man-in-the-middle?Core Concepts
  7. 157.A company is implementing a new BYOD (Bring Your Own Device) policy and wants to ensure that all personal devices connecting to the corporate network via GlobalProtect are compliant with security posture requirements (e.g., up-to-date antivirus, operating system patches). Which GlobalProtect feature is critical for enforcing these security checks before granting full network access?Core Concepts
  8. 158.A network security administrator is troubleshooting an issue where users are unable to authenticate to a new external authentication server (RADIUS). The firewall's authentication profile is configured correctly, and the RADIUS server is reachable. However, authentication attempts consistently fail with a 'server timeout' message in the firewall's authentication logs. Which command on the Palo Alto Networks firewall would be most appropriate to diagnose the communication issue between the firewall and the RADIUS server?Troubleshoot
  9. 159.A network administrator is troubleshooting an issue where users are reporting slow performance when accessing certain external websites. The Palo Alto Networks firewall has SSL decryption enabled, and the 'Decryption Tunnel' interface is showing high CPU utilization. What is the most effective initial step to troubleshoot this performance degradation?Troubleshoot
  10. 160.A security engineer notices that the Panorama management server is unable to push configurations to a managed firewall. The firewall status in Panorama shows 'Disconnected'. Upon checking the firewall itself, it is online and accessible, and local commits are successful. What is the MOST likely reason for the 'Disconnected' status?Troubleshoot
  11. 161.A network administrator is troubleshooting an issue where users are unable to access internal resources when connected via GlobalProtect. The GlobalProtect client connects successfully, and the user authenticates, but traffic does not pass. The administrator suspects a routing issue. Which command on the Palo Alto Networks firewall would be most helpful to diagnose the routing path for traffic originating from the GlobalProtect tunnel interface?Troubleshoot
  12. 162.A security engineer is performing troubleshooting on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall unexpectedly transitions to a non-functional state, and the active firewall remains active, but it fails to synchronize session information to the passive unit. Upon investigation, the passive firewall shows 'link-state-monitoring' as 'down' for a critical interface. Which interface-specific setting is most likely misconfigured or missing on the passive firewall?Troubleshoot
  13. 163.A network administrator is troubleshooting an issue where users on the internal network cannot access a newly deployed server in the DMZ. The server has a NAT policy configured to translate its internal IP to a public IP. Traffic logs show sessions being dropped with 'action: drop', 'rule: default-deny', and 'destination: translated IP'. What is the MOST likely cause?Troubleshoot
  14. 164.A network security team is implementing a new threat prevention profile. After applying the profile, users report intermittent connectivity issues and unexpected application behavior for a critical internal application. The threat logs show numerous 'vulnerability' alerts for the internal application's traffic, but the application developers confirm the traffic is legitimate and safe. Which action should the security team take FIRST to mitigate the immediate impact while investigating the false positives?Troubleshoot
  15. 165.A network engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish. The logs show 'IKE Phase 1 negotiation failed: No proposal chosen'. What is the most likely cause for this error?Troubleshoot
  16. 166.A network engineer is troubleshooting a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party device. IKE Phase 1 establishes successfully, but IKE Phase 2 consistently fails with 'No proposal chosen' in the logs. Which two parameters are most likely mismatched between the two VPN peers?Troubleshoot
  17. 167.A network administrator is troubleshooting an issue where users are unable to access internal resources after a recent firmware upgrade on a Palo Alto Networks firewall in an active/passive High Availability (HA) configuration. The passive firewall is showing as 'non-functional' in the HA status. Which of the following is the MOST likely cause for the passive firewall's state?Troubleshoot
  18. 168.A network administrator is troubleshooting an issue where users are unable to access internal resources using their domain credentials. The Palo Alto Networks firewall is configured to use an external RADIUS server for authentication. When testing the RADIUS server profile from the firewall, the test fails with a 'Connection Timeout' error. What is the MOST likely cause of this issue?Troubleshoot
  19. 169.A network security engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish. The logs show 'IKE phase-1 negotiation failed because of IPsec-VPN local ID mismatch'. Which configuration parameter is most likely incorrect?Troubleshoot
  20. 170.A company is using a Palo Alto Networks firewall with SSL decryption enabled. Users are reporting certificate warnings when accessing certain internal applications that use self-signed certificates. External websites are not presenting these warnings. What is the most appropriate action to resolve this specific issue for internal applications?Troubleshoot
  21. 171.A network administrator logs into Panorama and observes that the 'Managed Devices' tab shows a firewall as 'Disconnected'. The firewall itself is operational and users can access the internet. A ping from Panorama to the firewall's management interface is successful. Which of the following is the MOST likely reason for the 'Disconnected' status?Troubleshoot
  22. 172.A network administrator observes that logs from a Palo Alto Networks firewall are not being forwarded to the configured syslog server. The syslog server can be successfully pinged from the firewall's management interface, and a 'show logging-status' command on the firewall shows the syslog server as 'Connected' but '0' events forwarded. There are recent entries in the firewall's traffic and threat logs. What is the MOST likely reason for this issue?Troubleshoot
  23. 173.A network administrator is configuring a new GlobalProtect VPN portal and gateway. Users are able to connect to the portal and download the GlobalProtect client, but they are unable to establish a VPN tunnel to the gateway. The client logs show 'Failed to connect to gateway' and 'SSL negotiation failed'. Which of the following is the MOST likely cause?Troubleshoot
  24. 174.A network security engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish between a Palo Alto Networks firewall and a third-party device. The tunnel logs show 'No proposal chosen'. Which of the following is the MOST likely cause?Troubleshoot
  25. 175.A security engineer is troubleshooting a scenario where users are complaining about very slow application performance when accessing an internal web application. The Palo Alto Networks firewall is configured with Security policies that allow the traffic, and no threat logs are being generated for these sessions. However, the session browser on the firewall shows high 'pkt-proc-delay' values for the affected sessions. What does a high 'pkt-proc-delay' value typically indicate?Troubleshoot
  26. 176.A network administrator is troubleshooting an issue where a specific application, 'ExampleApp', is not being correctly identified by App-ID, leading to incorrect policy enforcement. The application uses non-standard ports, and the administrator suspects App-ID isn't recognizing it. What is the most effective way to teach the Palo Alto Networks firewall to correctly identify 'ExampleApp' when it uses non-standard ports?Troubleshoot
  27. 177.A network administrator is troubleshooting an issue where users are intermittently experiencing slow access to a web application hosted in a data center protected by a Palo Alto Networks firewall. The firewall logs show occasional 'deny' actions for the web application's traffic, indicating that not all traffic is being allowed consistently. The Security policy rule allowing the traffic has a 'service' configured as 'application-default'. Which action should the administrator take FIRST to diagnose the intermittent denials?Troubleshoot
  28. 178.A network administrator is troubleshooting an issue where users are unable to access an internal web application that is behind a Palo Alto Networks firewall. The firewall has a security policy allowing the traffic, but packet captures on the server show that the source IP address of the incoming connection is the firewall's egress interface IP, not the original client's IP. What type of NAT is most likely misconfigured or unexpectedly applied?Troubleshoot
  29. 179.A network administrator is troubleshooting an issue where logs from a Palo Alto Networks firewall are not being received by a configured syslog server. The firewall is sending other logs (e.g., traffic logs) successfully to Panorama, but specifically, threat logs are not appearing on the syslog server. The syslog server is reachable from the firewall, and a packet capture on the firewall's egress interface shows no UDP 514 traffic destined for the syslog server when a threat event occurs. Which configuration element is most likely misconfigured on the firewall?Troubleshoot
  30. 180.A network administrator logs into Panorama and observes that the 'Managed Devices' tab shows a firewall in a 'Disconnected' state. The firewall itself is operational, passing traffic, and the management interface is reachable from Panorama. No recent configuration changes were made on either Panorama or the firewall. What is the most likely cause for the 'Disconnected' state in Panorama?Troubleshoot
  31. 181.A network administrator is troubleshooting an issue where users are reporting slow performance and intermittent connection drops when accessing websites that use SSL/TLS, even though SSL decryption is enabled on the Palo Alto Networks firewall. The firewall's resource monitor shows high CPU utilization on the data plane, particularly related to SSL processes. Which action would be most effective in immediately alleviating the performance bottleneck while further investigation takes place?Troubleshoot
  32. 182.A company is experiencing issues with User-ID where some users are not being correctly mapped to their IP addresses, leading to incorrect policy enforcement. The domain controller logs show successful authentication, but the firewall's User-ID logs are inconsistent. The administrator wants to verify if the User-ID agent is receiving all necessary security event logs from the domain controller. Which type of log should the administrator specifically look for on the domain controller to confirm the agent's access to user authentication events?Troubleshoot
  33. 183.A network security administrator is troubleshooting Panorama. When attempting to push a configuration to a managed firewall, the task fails with an error indicating 'connection refused'. The Panorama server can ping the firewall's management interface, and there are no network firewalls between them. What is the most likely cause for the 'connection refused' error during a Panorama push?Troubleshoot
  34. 184.A technician is troubleshooting an issue where users are unable to access internal web servers after a new Security policy rule was implemented. The rule is intended to allow HTTP and HTTPS traffic from the 'Internal-Zone' to the 'DMZ-Zone'. After checking the traffic logs, the technician sees entries with (action: drop) and (rule: default-deny). What is the MOST likely cause?Troubleshoot
  35. 185.A security engineer is investigating why certain web applications are not being blocked by a security policy configured with an 'application-default' service. The application logs show traffic hitting the firewall, but the policy is not enforcing the block. The security policy is configured to block 'web-browsing' and 'ssl' applications. Which command would be most useful to determine if the firewall is correctly identifying the applications for this traffic?Troubleshoot
  36. 186.A network administrator is troubleshooting an issue where users are intermittently unable to access a critical internal application hosted on a server in the 'Server-Zone'. The application uses a non-standard port. Security policy rules are in place to allow the traffic. After reviewing traffic logs, the administrator sometimes sees 'application: unknown-tcp' and other times 'application: incomplete'. What is the MOST likely cause?Troubleshoot
  37. 187.A network administrator is troubleshooting an issue where users are experiencing intermittent access to a critical web application hosted behind a Palo Alto Networks firewall. The application uses a custom port. The administrator has verified that the Security policy allows the custom port, and the App-ID shows 'web-browsing'. However, sometimes the application still fails. What is a common troubleshooting step to ensure App-ID is not interfering with custom applications?Troubleshoot
  38. 188.A network engineer is troubleshooting a newly configured Layer 3 subinterface on a Palo Alto Networks firewall. The subinterface has been assigned an IP address, placed in a security zone, and connected to a switch. However, devices connected to the switch cannot use the firewall as their default gateway, and pinging the subinterface IP from the switch fails. The switch port is configured as a trunk port allowing the corresponding VLAN. Which command would be most effective on the Palo Alto Networks firewall to quickly diagnose the issue?Troubleshoot
  39. 189.A network security administrator is troubleshooting a GlobalProtect VPN connection issue. Users are unable to connect to the GlobalProtect portal, and the portal logs show 'User authentication failed'. The authentication profile on the firewall uses RADIUS. The RADIUS server logs show no authentication attempts from the firewall. Pinging the RADIUS server from the firewall's management interface is successful. What is the MOST likely cause?Troubleshoot
  40. 190.A network administrator is troubleshooting an issue where users are unable to access a newly deployed web server that resides in a DMZ zone behind a Palo Alto Networks firewall. The security policy allowing access has been created, and a NAT policy exists for the public IP. Packet captures on the firewall show traffic arriving on the external interface but no return traffic. What is the most likely misconfiguration?Troubleshoot
  41. 191.A large enterprise uses Panorama to manage hundreds of Palo Alto Networks firewalls across its global network. They need to ensure that a consistent set of security policies and objects are applied to all firewalls in a specific region, while also allowing some local customization for individual firewalls. Which Panorama concept allows this hierarchical management?Core Concepts
  42. 192.A security auditor is reviewing the logging configuration of a Palo Alto Networks firewall and notes that sessions are being dropped due to application-default not being allowed. Which action should the administrator take to allow traffic for applications that rely on standard ports while enforcing Application-ID?Core Concepts
  43. 193.A company is integrating its Active Directory with a Palo Alto Networks firewall to enforce user-based security policies. Which component is primarily responsible for mapping IP addresses to usernames?Core Concepts
  44. 194.A network security engineer is configuring a Palo Alto Networks firewall to allow users to access web applications while blocking known malicious sites. Which security profile should be applied to the security policy to achieve this?Core Concepts
  45. 195.A network administrator needs to inspect encrypted traffic for threats without requiring client-side certificate installation. Which decryption method should be configured on the Palo Alto Networks firewall?Core Concepts
  46. 196.A network engineer is configuring a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. During Phase 1 negotiation, the connection fails. The logs indicate a mismatch in the encryption algorithm. Which IKE Crypto Profile parameter should the engineer verify?Core Concepts
  47. 197.A network architect is designing a new security infrastructure and wants to understand how Palo Alto Networks firewalls achieve high throughput and low latency by performing security functions in a single pass. Which core concept describes this capability?Core Concepts
  48. 198.A network administrator is troubleshooting an issue where users are intermittently experiencing slow access to an external web application. The firewall logs show a high number of 'deny' actions for the application due to 'Application-not-detected'. However, the application uses standard HTTPS on port 443. Which configuration change is most likely to resolve this issue?Manage and Operate
  49. 199.A network security engineer is designing a new security policy for a critical application server that hosts sensitive customer data. The application requires access only from a specific internal subnet and a limited set of administrative hosts. Additionally, the application communicates with a backend database server on a non-standard port. Which design principle should the engineer prioritize to ensure the strongest security posture for this application?Plan and Design
  50. 200.A security engineer is configuring a new GlobalProtect VPN portal and gateway. The company policy requires that all users connecting to GlobalProtect must use two-factor authentication (2FA) provided by a RADIUS server. Which two components are essential to configure on the Palo Alto Networks firewall to meet this requirement?Manage and Operate