Palo Alto Networks Certified Network Security Engineer (PCNSE) practice questions
207 free questions with answers and explanations.
- 201.A company is designing a GlobalProtect deployment for its remote workforce. Users will connect from various locations with potentially unreliable internet connections. The design requires that users can always reach internal resources, even if a single GlobalProtect Gateway becomes unavailable. Which GlobalProtect component should be designed with redundancy to ensure continuous connectivity?Plan and Design
- 202.A company uses Panorama to manage multiple Palo Alto Networks firewalls. The security team needs to deploy a new security policy rule that allows specific applications for a new development environment. This rule should be located at the top of the rulebase for evaluation priority and apply only to firewalls associated with the 'Development' device group. How should the administrator configure this on Panorama?Manage and Operate
- 203.A network security engineer observes that after a recent content update, a critical internal application using a proprietary protocol on a non-standard port is being incorrectly identified by the firewall as 'unknown-tcp' and subsequently blocked. How should the engineer ensure this application is correctly identified and allowed without compromising security for other traffic?Manage and Operate
- 204.A network architect is designing a log collection solution for a large enterprise with 50 Palo Alto Networks firewalls distributed across 10 data centers globally. Each firewall generates approximately 500 logs per second. The design requires a minimum of 90 days of log retention for all log types (traffic, threat, URL, data, wildfire). The architect also needs to ensure high availability for log collection and centralized management. Which log collection solution best meets these requirements?Plan and Design
- 205.A network administrator needs to generate a report that shows all traffic sessions that were explicitly denied by security policy rules, including the rule name that blocked the traffic. Which log type and column in the Palo Alto Networks firewall should the administrator focus on?Manage and Operate
- 206.A network security administrator needs to ensure that all internal users attempting to access external websites are authenticated against the corporate Active Directory before being allowed internet access. Which User-ID feature should be configured to achieve this?Manage and Operate
- 207.A company is implementing a new external web server in their DMZ and needs to allow inbound HTTPS access from the internet. The external IP address of the web server is 203.0.113.10 and its internal IP is 10.0.0.10. The firewall must perform Destination NAT to translate the external IP to the internal IP. Which configuration is correct for the Destination NAT rule?Manage and Operate