Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementEasy

A network security engineer is setting up a new Palo Alto Networks firewall. To ensure that the firewall can correctly resolve domain names for services like WildFire, URL filtering, and software updates, which of the following steps is crucial for DNS configuration?

  1. AConfigure DNS proxy settings under Network > DNS Proxy.
  2. BDefine primary and secondary DNS servers under Device > Setup > Services > DNS.
  3. CSet up a DNS sinkhole profile under Objects > Security Profiles > DNS Sinkhole.
  4. DEnable DNS inspection within security policies.
Show answer & explanation

Correct answer: B. Define primary and secondary DNS servers under Device > Setup > Services > DNS.

For the firewall itself to resolve domain names for its own services (like WildFire, updates, etc.), the primary and secondary DNS servers must be configured under Device > Setup > Services > DNS. This allows the firewall to query external DNS servers.

Why the other options are wrong

  • A. DNS proxy is for clients to use the firewall as their DNS server, not for the firewall itself to resolve names.
  • C. DNS sinkhole is a security feature to redirect malicious DNS requests, not for the firewall's own legitimate DNS queries.
  • D. DNS inspection is a security feature to analyze DNS traffic, not to configure the firewall's own DNS resolution.

Firewall System DNS

Configuration of DNS servers that the Palo Alto Networks firewall uses for its internal services and operations.

  • Located under Device > Setup > Services > DNS.
  • Essential for WildFire, URL filtering, software updates, etc.
  • Allows the firewall to resolve external domain names.

Memory trick: For the firewall to 'know' the internet, its 'brain' (Device > Setup > Services) needs its own 'phonebook' (DNS servers).

More Initial Configuration and Management questions