Step2Study
IT & TechnologyPCNSE100% Free

Palo Alto Networks Certified Network Security Engineer (PCNSE)

Practice bank
207 Qs
Real exam
75 Qs
Time limit
90 min
Passing
Pass/Fail

Exam blueprint

Plan and Design
16%
Deploy and Configure
23%
Manage and Operate
18%
Troubleshoot
23%
Core Concepts
20%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 108 min · pass 70% · 207 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Palo Alto Networks Certified Network Security Engineer (PCNSE) practice test questions

Sample questions from the 207-question bank, with answers and explanations.

All questions
  1. 1. A network security team needs to implement QoS on a Palo Alto Networks firewall to prioritize voice (SIP/RTP) and video conferencing traffic over general web browsing and bulk data transfers. The goal is to ensure real-time communication applications receive preferential treatment during network congestion. Which QoS configuration element is primarily responsible for classifying and marking traffic to be prioritized?

    Deploy and Configure

    • A. Traffic Shaping Policy
    • B. Egress Interface Buffer
    • C. QoS Profile
    • D. QoS Policy Rule
    Show answer

    D. QoS Policy Rule

    The QoS Policy Rule is where traffic classification and marking (e.g., setting DSCP values) occur. It identifies specific applications (like SIP/RTP) and applies the desired QoS actions, including marking the packets, which then influences how the traffic is treated by the QoS Profile applied to the egress interface.

  2. 2. A company is deploying a new web application and requires granular control over traffic based on the specific application being used, rather than just ports and protocols. They need to ensure only approved applications can access the web server. Which Palo Alto Networks firewall feature allows for this application-level control?

    Deploy and Configure

    • A. Zone-based security policy
    • B. Application-based security policy
    • C. Port-based security policy
    • D. Service-based security policy
    Show answer

    B. Application-based security policy

    Application-based security policy, utilizing App-ID, allows the firewall to identify and control applications regardless of the port or protocol they use, providing granular control.

  3. 3. A network engineer needs to configure a NAT policy on a Palo Alto Networks firewall to allow internal users to access external resources using a single public IP address. This type of NAT allows multiple internal IP addresses to be translated to a single public IP address. Which NAT type should be configured?

    Deploy and Configure

    • A. Dynamic IP and Port (DIPP)
    • B. Static NAT
    • C. Dynamic IP
    • D. U-turn NAT
    Show answer

    A. Dynamic IP and Port (DIPP)

    Dynamic IP and Port (DIPP) is the NAT type used to translate multiple internal private IP addresses to a single public IP address using port numbers, commonly known as PAT (Port Address Translation) or NAT Overload.

  4. 4. A network architect is designing a new branch office deployment that requires a secure, encrypted tunnel back to the corporate headquarters. Both sites use Palo Alto Networks firewalls. The branch office has a dynamic public IP address. Which type of site-to-site VPN configuration is best suited for this scenario?

    Deploy and Configure

    • A. Policy-based VPN
    • B. Route-based VPN with static VTI
    • C. Route-based VPN with a dynamic peer
    • D. SSL VPN
    Show answer

    C. Route-based VPN with a dynamic peer

    When one side of a site-to-site VPN has a dynamic public IP address, a route-based VPN configured with a dynamic peer (using a dynamic DNS hostname or a pre-shared key with 'any' peer ID) is the most appropriate solution. This allows the VPN tunnel to re-establish even if the branch office's public IP changes.

  5. 5. A company is migrating its network infrastructure to a new data center and requires a seamless transition for its critical applications. During this migration, they need to implement a security solution that can inspect traffic without requiring any changes to the existing network topology (IP addresses, routing). Which Palo Alto Networks interface configuration would best meet this requirement for transparent inspection?

    Deploy and Configure

    • A. Layer 3 interface with a virtual router
    • B. Virtual Wire (L2 transparent mode)
    • C. Tap interface for out-of-band monitoring
    • D. Layer 2 interface with a VLAN subinterface
    Show answer

    B. Virtual Wire (L2 transparent mode)

    A Virtual Wire (L2 transparent mode) configuration allows the Palo Alto Networks firewall to be inserted directly into a network segment between two devices (like a switch and a router) without requiring any changes to IP addressing or routing, functioning transparently.

  6. 6. A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that the firewall itself can resolve DNS queries for internal and external resources. Which configuration setting is required on the firewall?

    Deploy and Configure

    • A. DNS Proxy Object
    • B. Virtual Router DNS Proxy
    • C. Static DNS Servers
    • D. Service Route Configuration
    Show answer

    C. Static DNS Servers

    To allow the firewall itself to resolve DNS queries (e.g., for FQDN objects, URL categories, or updates), you must configure static DNS servers under Device > Setup > Services > DNS. This tells the firewall where to send its own DNS requests.

  7. 7. A network security engineer is deploying a new Palo Alto Networks firewall and needs to integrate it into an existing network that uses OSPF for dynamic routing. The firewall must advertise its connected networks to the OSPF domain and learn routes from other OSPF routers. Which configuration step is essential to enable OSPF routing on the firewall?

    Deploy and Configure

    • A. Configure a Static Route for each connected network.
    • B. Enable Redistribution of connected routes into OSPF.
    • C. Create a Policy-Based Forwarding rule for OSPF traffic.
    • D. Assign the interface to a Virtual Router and enable OSPF.
    Show answer

    D. Assign the interface to a Virtual Router and enable OSPF.

    To enable OSPF routing, interfaces participating in OSPF must be assigned to a Virtual Router, and then OSPF itself must be enabled and configured within that Virtual Router. This allows the firewall to exchange OSPF routing information with neighbors.

  8. 8. A network security administrator needs to configure a NAT policy to allow internal users to access an external web server using a specific public IP address that is different from the firewall's egress interface IP. Which type of NAT configuration is required?

    Deploy and Configure

    • A. Static IP NAT
    • B. Destination NAT (DNAT)
    • C. Source NAT (SNAT)
    • D. Dynamic IP and Port (DIPP) NAT
    Show answer

    A. Static IP NAT

    When internal users need to appear to originate from a specific, consistent public IP address (not necessarily the egress interface IP or a pool) when accessing external resources, Static IP NAT for the source is used. This maps internal source IPs to a consistent external public IP.

  9. 9. A security architect is designing a high-performance network where multiple firewalls need to share the load of processing traffic for a large number of users. The design requires that both firewalls actively process traffic simultaneously to maximize throughput. Which HA mode would best meet this requirement?

    Deploy and Configure

    • A. Active/Active with Layer 3 deployment
    • B. Active/Active with Layer 2 deployment
    • C. Active/Passive with session synchronization
    • D. Active/Passive with Virtual Wire deployment
    Show answer

    A. Active/Active with Layer 3 deployment

    Active/Active HA allows both firewalls to process traffic simultaneously, sharing the load. Layer 3 deployment is the most common and flexible method to achieve this, using virtual routers and routing protocols to distribute traffic.

  10. 10. A company is implementing a new wireless network and requires all wireless clients to be placed into a separate security zone, distinct from the wired LAN. This new zone needs its own security policies to control access to internal resources. Which type of interface configuration is best suited for connecting the wireless access points to the Palo Alto Networks firewall while maintaining logical separation?

    Deploy and Configure

    • A. Tap Interface
    • B. Virtual Wire Interface
    • C. Layer 2 Interface
    • D. Subinterface (VLAN)
    Show answer

    D. Subinterface (VLAN)

    Subinterfaces, specifically VLAN subinterfaces, are ideal for this scenario. They allow a single physical interface to be logically segmented into multiple virtual interfaces, each associated with a different VLAN ID. Each subinterface can then be assigned to a different security zone (e.g., 'wireless' and 'internal'), allowing for distinct security policies.

  11. 11. A network security engineer is deploying a new Palo Alto Networks firewall and needs to ensure that all management traffic (SSH, HTTPS, SNMP) to the firewall itself is restricted to a specific management network. Which configuration element should be applied to the interface designated for management access?

    Deploy and Configure

    • A. Zone Protection Profile
    • B. Management Profile
    • C. Virtual Router
    • D. Security Policy Rule
    Show answer

    B. Management Profile

    Management Profiles are used to control access to the firewall's management interfaces, specifying allowed services and source IP addresses. This ensures only authorized traffic can reach the firewall's control plane.

  12. 12. A company is upgrading its data center and is consolidating several physical firewalls into a single Palo Alto Networks firewall pair in an Active/Passive HA configuration. The network team needs to ensure that if the active firewall fails, the passive firewall takes over seamlessly with minimal disruption to existing TCP sessions. Which HA sync option is critical for achieving this requirement?

    Deploy and Configure

    • A. Session Synchronization
    • B. ARP Load-Sharing
    • C. Configuration Synchronization
    • D. Heartbeat Backup
    Show answer

    A. Session Synchronization

    Session Synchronization (session-sync) is critical for maintaining existing TCP sessions during a failover in an Active/Passive HA pair. It ensures that the passive firewall has a synchronized copy of the active firewall's session table, allowing it to seamlessly take over and continue active connections without interruption.

  13. 13. A network administrator is configuring a new Palo Alto Networks firewall. The internal network uses 192.168.1.0/24, and the DMZ uses 172.16.10.0/24. The administrator needs to define a logical segment that groups interfaces with similar security requirements and allows traffic to flow between these interfaces based on security policies. Which configuration element should be used for this purpose?

    Deploy and Configure

    • A. Security Zone
    • B. Service Route
    • C. Interface Management Profile
    • D. Virtual Router
    Show answer

    A. Security Zone

    Security Zones are fundamental to Palo Alto Networks firewalls, logically grouping interfaces with similar security requirements and acting as the source and destination for security policy rules.

  14. 14. A network administrator is configuring a Palo Alto Networks firewall for a new branch office. The branch needs to use a full mesh VPN topology with other branch offices, but the public IP addresses of some branches are dynamic. Which GlobalProtect component is specifically designed to handle dynamic IP addresses for VPN tunnels?

    Deploy and Configure

    • A. GlobalProtect Gateway
    • B. External Gateway
    • C. GlobalProtect Portal
    • D. Satellite Gateway
    Show answer

    D. Satellite Gateway

    The GlobalProtect Satellite Gateway is specifically designed for site-to-site VPN connectivity where one or both endpoints have dynamic IP addresses. Satellites register with a GlobalProtect Portal, allowing them to establish VPN tunnels to other GlobalProtect devices (including other Satellites or Gateways) even without a static public IP.

  15. 15. A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party device. The third-party device requires the use of IKEv2 with AES256-GCM for encryption and SHA384 for authentication in Phase 2. Which IKE Crypto Profile and IPsec Crypto Profile settings are required?

    Deploy and Configure

    • A. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14.
    • B. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14 (PFS).
    • C. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, No PFS.
    • D. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 16 (PFS).
    Show answer

    B. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14 (PFS).

    The question specifies AES256-GCM for encryption and SHA384 for authentication in Phase 2, which corresponds to the IPsec Crypto Profile. GCM modes inherently include authentication, so SHA384 is redundant but must be configured if the peer requires it. The IKE Crypto Profile typically uses algorithms for key exchange (DH Group), encryption (AES), and authentication (SHA) for Phase 1. For Phase 2, if PFS (Perfect Forward Secrecy) is required, a DH Group must be selected; otherwise, 'No PFS' is used. The IKE Crypto Profile is usually configured with 256-bit encryption and SHA256 for integrity, and matching the DH Group (e.g., 14) from the IPsec profile or a stronger one (e.g., 14 or higher) is common. The key is matching the Phase 2 requirements for AES256-GCM and SHA384, and the inclusion of a DH Group for PFS in the IPsec Crypto Profile.

  16. 16. A network architect is designing a new data center and needs to ensure that critical applications receive preferential bandwidth during periods of congestion. Which QoS configuration element directly applies prioritization to specific traffic types?

    Deploy and Configure

    • A. QoS Policy Rule
    • B. DSCP Marking Profile
    • C. Interface QoS Profile
    • D. Traffic Shaping Profile
    Show answer

    A. QoS Policy Rule

    A QoS Policy Rule on a Palo Alto Networks firewall is used to classify and mark traffic based on various criteria (application, user, zone, etc.) and then assign a QoS class or DSCP value, which is then acted upon by an Interface QoS Profile.

  17. 17. A network administrator is configuring a new Palo Alto Networks firewall and observes that the dataplane CPU utilization is consistently high, even under moderate traffic load. Upon inspection, it's discovered that the firewall is performing decryption on all traffic, including streaming video and large file transfers, which are not security-sensitive but consume significant resources. Which decryption policy rule modification would most effectively reduce dataplane CPU utilization without compromising security for critical applications?

    Deploy and Configure

    • A. Change the decryption type from 'SSL Forward Proxy' to 'SSL Inbound Inspection'.
    • B. Disable decryption entirely on the firewall.
    • C. Set the decryption profile to 'no-decrypt' for all traffic.
    • D. Create a 'no-decrypt' rule for streaming video and large file transfer applications, placed above other decryption rules.
    Show answer

    D. Create a 'no-decrypt' rule for streaming video and large file transfer applications, placed above other decryption rules.

    To reduce CPU utilization from decryption while maintaining security for critical applications, it's best to selectively decrypt. Creating a 'no-decrypt' rule for high-bandwidth, non-security-sensitive applications like streaming video and large file transfers, and placing it higher in the policy order, ensures these specific traffic types bypass decryption, saving resources. Other traffic can still be decrypted by subsequent rules.

  18. 18. A network administrator is troubleshooting an issue where internal users are unable to access a specific external web service. Packet captures on the firewall show that the initial SYN packet from the internal user is leaving the firewall, but no SYN-ACK is being received. Upon checking the security policy, the administrator confirms that an 'allow' rule exists for the application and source/destination zones. What is the MOST likely root cause of this connectivity issue, assuming external reachability is confirmed?

    Deploy and Configure

    • A. The external web service is blocking the connection or its return traffic.
    • B. The firewall's virtual router is missing a route to the external web service.
    • C. The NAT policy is incorrectly configured or missing, preventing the external service from responding to the internal IP.
    • D. The security policy is missing a specific service (port) for the application.
    Show answer

    C. The NAT policy is incorrectly configured or missing, preventing the external service from responding to the internal IP.

    If the SYN packet leaves the firewall but no SYN-ACK returns, and external reachability is confirmed, an incorrect or missing NAT policy is a common culprit. The external service might receive the internal IP (if NAT is missing) or an incorrect public IP (if NAT is misconfigured), leading it to either drop the packet or send the SYN-ACK to an unreachable address.

  19. 19. A network security team is configuring Quality of Service (QoS) on a Palo Alto Networks firewall to prioritize voice over IP (VoIP) traffic over standard web browsing. They need to ensure that VoIP packets receive preferential treatment throughout the network. Which QoS mechanism can be used on the firewall to mark VoIP traffic so that downstream devices also recognize and prioritize it?

    Deploy and Configure

    • A. DSCP marking
    • B. Traffic shaping
    • C. Bandwidth reservation
    • D. Packet policing
    Show answer

    A. DSCP marking

    DSCP (Differentiated Services Code Point) marking is a QoS mechanism that allows the firewall to mark traffic in the IP header. Downstream network devices (routers, switches) can then read these DSCP values and apply appropriate prioritization based on their own QoS policies.

  20. 20. An organization uses Panorama to manage multiple Palo Alto Networks firewalls across different geographical locations. They need to ensure that all firewalls log to a central SIEM system using syslog. Which Panorama object should be configured and pushed to the firewalls to achieve this?

    Deploy and Configure

    • A. Device Group Log Settings
    • B. Log Forwarding Profile
    • C. Managed Collector Group
    • D. Log Collector Group
    Show answer

    B. Log Forwarding Profile

    A Log Forwarding Profile defines where logs (e.g., traffic, threat, system) are sent, including external syslog servers. This profile can be created on Panorama and then pushed to managed firewalls.

  21. 21. A network administrator is troubleshooting an issue where external users cannot access a web server located in the DMZ (172.16.1.10) from the internet. The internet-facing interface IP is 203.0.113.5. A Security policy rule is already in place to allow the traffic. Which NAT policy configuration is required to allow external users to reach the web server?

    Deploy and Configure

    • A. Source NAT (Dynamic IP) from DMZ to Untrust, translating source IP 172.16.1.10 to 203.0.113.5.
    • B. Source NAT (Static IP) from Untrust to DMZ, translating source IP to 203.0.113.5.
    • C. Destination NAT (Static IP) from Untrust to DMZ, translating destination IP 203.0.113.5 to 172.16.1.10.
    • D. Dynamic IP and Port (DIPP) NAT from Untrust to DMZ, translating source IP to 203.0.113.5.
    Show answer

    C. Destination NAT (Static IP) from Untrust to DMZ, translating destination IP 203.0.113.5 to 172.16.1.10.

    To allow external users to access an internal server, Destination NAT (DNAT) is required. The public IP (203.0.113.5) that external users connect to must be translated to the private IP of the web server (172.16.1.10).

  22. 22. A company is integrating their Palo Alto Networks firewall with an existing Active Directory infrastructure to provide user-based security policies for internal users. They need to ensure that the firewall can query Active Directory for user and group information. Which authentication profile type is primarily used for this integration to retrieve user identity information?

    Deploy and Configure

    • A. SAML
    • B. LDAP
    • C. RADIUS
    • D. TACACS+
    Show answer

    B. LDAP

    LDAP (Lightweight Directory Access Protocol) is the standard protocol used by Palo Alto Networks firewalls to query Active Directory for user and group information, enabling user-based security policies.

  23. 23. A security auditor requires that all changes made to the firewall configuration, including who made them and when, are logged and immutable. Which feature on the Palo Alto Networks firewall ensures the integrity and auditability of configuration changes?

    Deploy and Configure

    • A. Commit History
    • B. Audit Comment
    • C. Admin Activity Log
    • D. Config Log
    Show answer

    D. Config Log

    The Config Log (or Configuration Log) specifically records every configuration change made to the firewall, including the administrator, timestamp, and the exact change. This log is immutable and provides a clear audit trail, directly addressing the auditor's requirement for integrity and auditability.

  24. 24. A large enterprise is integrating Palo Alto Networks firewalls with their existing Splunk SIEM for centralized log analysis. They need to ensure that all traffic, threat, and system logs are reliably sent to Splunk. Which component on the Palo Alto Networks firewall is responsible for sending these logs to an external syslog server?

    Deploy and Configure

    • A. Log Forwarding Profile
    • B. Log Monitor
    • C. Log Collector
    • D. Data Plane Processor
    Show answer

    A. Log Forwarding Profile

    The Log Forwarding Profile is the specific configuration object on a Palo Alto Networks firewall that defines which types of logs to send, to which external destinations (like syslog servers or Panorama), and under what conditions.

  25. 25. A company is implementing GlobalProtect for remote users and requires that all users authenticate against their existing Active Directory infrastructure. Which configuration element is essential for this requirement?

    Deploy and Configure

    • A. RADIUS Server Profile
    • B. Kerberos Authentication Profile
    • C. LDAP Authentication Profile
    • D. SAML Identity Provider
    Show answer

    C. LDAP Authentication Profile

    Active Directory primarily uses LDAP (Lightweight Directory Access Protocol) for directory services and authentication. Therefore, an LDAP Authentication Profile is required to integrate GlobalProtect with Active Directory.

Palo Alto Networks Certified Network Security Engineer (PCNSE) flashcards

Tap a card to flip it. 160 flashcards in the full deck.

  • Palo Alto Networks QoS Policy Rule

    Flip card

    A QoS Policy Rule on a Palo Alto Networks firewall classifies traffic based on application, user, and other criteria, and applies QoS actions such as marking DSCP values or assigning to a QoS class.

    • Similar to security policies in structure and evaluation order.
    • Determines which traffic gets prioritized.
    • Works in conjunction with QoS Profiles applied to interfaces.
    Study this card →
  • App-ID

    Flip card

    A Palo Alto Networks technology that identifies applications traversing the firewall, regardless of port, protocol, or evasive tactics.

    • Enables application-based security policies.
    • Uses multiple classification mechanisms (signatures, decryption, heuristics).
    • Provides granular control over application usage.
    Study this card →
  • Dynamic IP and Port (DIPP) NAT

    Flip card

    A NAT type that translates multiple private IP addresses to a single public IP address by using different source port numbers for each connection, also known as Port Address Translation (PAT).

    • Enables many-to-one IP address translation.
    • Conserves public IP addresses.
    • Commonly used for outbound internet access from internal networks.
    Study this card →
  • Dynamic Peer VPN

    Flip card

    A dynamic peer VPN configuration allows one or both VPN endpoints to have a dynamic public IP address, typically using a FQDN or a 'any' peer ID for identification.

    • Essential for branch offices with dynamic IPs.
    • Often uses a Dynamic DNS service to update the FQDN.
    • Requires specific IKE Gateway configuration for dynamic peers.
    Study this card →
  • Virtual Wire Interface

    Flip card

    A Palo Alto Networks firewall interface type that operates in a transparent Layer 2 mode, allowing the firewall to be inserted into a network segment without requiring changes to the existing network topology.

    • Acts as a 'bump-in-the-wire'.
    • Does not have an IP address on the data plane.
    • Forwards traffic based on MAC addresses.
    Study this card →
  • Static DNS Servers (Firewall)

    Flip card

    Static DNS Servers configured on a Palo Alto Networks firewall (under Device > Setup > Services > DNS) are used by the firewall itself to resolve hostnames for updates, FQDN objects, and other internal operations.

    • Used by the firewall for its own DNS queries.
    • Essential for FQDN objects and dynamic updates.
    • Configured under Device > Setup > Services > DNS.
    Study this card →
  • Palo Alto Networks Virtual Router

    Flip card

    A Virtual Router on a Palo Alto Networks firewall is a logical routing instance that maintains its own routing table and participates in dynamic routing protocols like OSPF or BGP.

    • Interfaces are assigned to a Virtual Router to participate in routing.
    • Can run multiple routing protocols simultaneously.
    • Default 'VR-Default' is always present.
    Study this card →
  • Static IP NAT (Source)

    Flip card

    Static IP NAT (Source) on a Palo Alto Networks firewall maps one or more internal source IP addresses to a consistent, specific public IP address for outbound connections, ensuring a predictable external identity.

    • Maps internal IP to a single public IP.
    • Used for outbound connections.
    • Ensures consistent external IP for internal hosts.
    Study this card →
  • Active/Active HA (Palo Alto)

    Flip card

    A High Availability configuration where both firewalls actively process traffic concurrently, typically for load sharing and increased throughput.

    • Both firewalls are active and forward traffic.
    • Requires traffic distribution mechanisms (e.g., ECMP, link aggregation).
    • Can be deployed in Layer 2 or Layer 3 modes.
    Study this card →
  • VLAN Subinterface

    Flip card

    A VLAN subinterface on a Palo Alto Networks firewall allows a single physical interface to be logically partitioned into multiple interfaces, each handling traffic for a specific VLAN ID and assignable to its own security zone.

    • Logical partitioning of a physical interface.
    • Each subinterface associated with a VLAN ID.
    • Enables distinct security zones and policies per VLAN.
    Study this card →
  • Management Profile

    Flip card

    A configuration object in Palo Alto Networks firewalls that defines which administrative services (like SSH, HTTPS, SNMP) are allowed on a specific interface and from which source IP addresses.

    • Controls access TO the firewall's management plane.
    • Applied to specific interfaces (e.g., Management, Ethernet interfaces).
    • Includes services like SSH, HTTPS, Ping, SNMP, User-ID agent.
    Study this card →
  • HA Session Synchronization

    Flip card

    Session Synchronization in Palo Alto Networks HA ensures that active session states are replicated from the primary to the secondary firewall, allowing for seamless failover of existing connections.

    • Crucial for maintaining TCP sessions during failover.
    • Uses dedicated HA data link for replication.
    • Requires specific configuration and monitoring.
    Study this card →
  • Security Zone

    Flip card

    A logical grouping of one or more interfaces on a Palo Alto Networks firewall that share common security requirements. Security policies are applied between zones to control traffic flow.

    • Fundamental for firewall security policy enforcement.
    • Can contain Layer 2, Layer 3, Virtual Wire, or Tap interfaces.
    • Traffic between interfaces in the SAME zone is typically allowed by default (inter-zone blocking).
    Study this card →
  • GlobalProtect Satellite Gateway

    Flip card

    A GlobalProtect Satellite Gateway is a Palo Alto Networks firewall deployed at a remote site with a dynamic public IP address, which registers with a GlobalProtect Portal to enable site-to-site VPN connectivity with other GlobalProtect devices.

    • Enables site-to-site VPN for dynamic IP branches.
    • Registers with a GlobalProtect Portal.
    • Part of a GlobalProtect full mesh or hub-and-spoke VPN solution.
    Study this card →
  • IKE/IPsec Crypto Profiles

    Flip card

    IKE and IPsec Crypto Profiles define the cryptographic algorithms and parameters used for establishing and securing VPN tunnels in Phase 1 (IKE) and Phase 2 (IPsec) respectively.

    • IKE Profile: Defines Phase 1 (key exchange, authentication, encryption, DH group).
    • IPsec Profile: Defines Phase 2 (data encryption, authentication, PFS DH group).
    • Parameters must match between peers for tunnel establishment.
    Study this card →
  • QoS Policy Rule

    Flip card

    A QoS Policy Rule on a Palo Alto Networks firewall classifies traffic based on defined criteria and assigns it a specific QoS class or DSCP value, which is then used by interface QoS profiles for prioritization and bandwidth management.

    • Classifies traffic based on various attributes.
    • Assigns a QoS class or DSCP value.
    • Works in conjunction with Interface QoS Profiles.
    Study this card →
  • Selective Decryption

    Flip card

    Selective decryption involves configuring decryption policies to only decrypt traffic that requires security inspection, thereby optimizing firewall performance and resource utilization.

    • Use 'no-decrypt' rules for non-sensitive, high-bandwidth traffic.
    • Policy order is crucial for decryption rules.
    • Helps manage CPU load and maintain privacy for certain traffic.
    Study this card →
  • NAT Policy Troubleshooting (Outbound)

    Flip card

    Diagnosing issues where internal hosts cannot reach external resources due to incorrect or missing Network Address Translation (NAT) configurations on the firewall.

    • Initial SYN leaves firewall, but no SYN-ACK returns.
    • Security policy allows traffic.
    • External reachability to destination is verified.
    Study this card →
  • DSCP Marking (QoS)

    Flip card

    A Quality of Service mechanism that modifies the Differentiated Services Code Point field in the IP header to classify and prioritize network traffic.

    • Provides a standard way to classify traffic.
    • Allows for end-to-end QoS across different network devices.
    • Different DSCP values correspond to different per-hop behaviors (PHBs).
    Study this card →
  • Log Forwarding Profile

    Flip card

    A Log Forwarding Profile on a Palo Alto Networks firewall or Panorama defines the destinations (e.g., syslog server, SNMP trap, email) for different types of logs generated by the firewall.

    • Specifies external log destinations.
    • Can be configured per log type (traffic, threat, system).
    • Centralized management via Panorama.
    Study this card →
  • Destination NAT (DNAT)

    Flip card

    A type of Network Address Translation (NAT) that translates the destination IP address of incoming traffic. It is used to allow external users to access internal servers that have private IP addresses by mapping a public IP to a private one.

    • Translates the destination IP of a packet.
    • Used for inbound connections from external networks to internal servers.
    • Requires a public IP address (or interface IP) to be mapped to a private server IP.
    Study this card →
  • LDAP Authentication Profile

    Flip card

    An authentication profile in Palo Alto Networks firewalls that uses the Lightweight Directory Access Protocol (LDAP) to query directory services like Active Directory for user and group information, enabling user-based security policies.

    • Used for retrieving user and group memberships from Active Directory.
    • Enables User-ID for policy enforcement.
    • Can also be used for authentication (e.g., GlobalProtect, admin login).
    Study this card →
  • Config Log (Configuration Log)

    Flip card

    The Config Log on a Palo Alto Networks firewall is an immutable log that records every configuration change, including the administrator who made the change, the timestamp, and the specific parameters that were modified, providing a critical audit trail.

    • Records all configuration changes.
    • Includes admin, timestamp, and exact changes.
    • Immutable and essential for auditability.
    Study this card →
  • Interface Management Profile

    Flip card

    An Interface Management Profile on a Palo Alto Networks firewall controls which services (e.g., SSH, HTTPS) are allowed to access the firewall's management plane from specific zones.

    • Applied to interfaces or zones.
    • Restricts management access services.
    • Enhances firewall security.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.