Be able to upgrade PAN-OS in the correct order, keep HA peers on matching versions, fix time/NTP issues, and configure a virtual wire end to end. The single most important thing: verify both HA peers run the same PAN-OS version before expecting sync to succeed.
Start practicing
Device Management and Services — choose a session length
Free · No account required
Domain overview
This domain covers day-to-day firewall operations on PAN-OS: software upgrades, HA synchronization, time/NTP configuration, and interface modes such as virtual wire. Questions are scenario-based, asking you to diagnose a failed upgrade or sync, identify a misconfiguration from an exhibit, or select valid configuration steps.
Exam objectives
PAN-OS upgrade paths, base image installation, and HA active/passive sync requirements after upgrade
Virtual wire configuration: assigning interfaces, zones, and security policy for transparent traffic
NTP and timezone settings that keep logs, certificates, and HA timestamps consistent
Valid versus invalid methods for installing PAN-OS software and content updates
Upgrading the passive HA peer without matching the active peer's PAN-OS version, breaking config sync
Assuming any upload method installs PAN-OS; only supported paths like the web UI or SCP work
Forgetting that vwire interfaces need zones and policy before traffic passes, not just interface assignment
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security administrator notices that a user's traffic is being blocked unexpectedly. The user's IP is 10.1.1.100, and the traffic is destined to a web server at 192.168.2.10. The administrator has already verified that there are no security rules explicitly denying the traffic. Which Log Viewer query should the administrator use to quickly identify the cause?
2A company wants to deploy a new firewall with a management interface on a separate VLAN to ensure management traffic is isolated from production traffic. Which interface type should be used for management access?
3An administrator needs to generate a report showing all applications used by a specific user group over the past week. Which method is most efficient?
4A network engineer wants to configure a new VLAN interface on a Palo Alto Networks firewall. After creating the VLAN object and assigning it to an Ethernet interface, the VLAN interface remains down. What is the most likely cause?
5An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?
6A security analyst notices that a legitimate application is being incorrectly identified as a different application by the firewall. What is the best first step to resolve this issue?
7Which THREE of the following are valid steps when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?
8Refer to the exhibit. The firewall is experiencing performance issues and dropping sessions. Based on the exhibit, what is the most likely cause?
9A company has a PA-5250 firewall in an active/passive HA pair. During a maintenance window, the administrator upgrades the passive firewall from PAN-OS 10.0 to 10.1. After the upgrade, the passive firewall fails to synchronize with the active firewall. The active firewall remains at 10.0. What is the most likely cause?
10A company is deploying a PA-220 firewall in a branch office. The firewall will be managed by Panorama. Which THREE of the following are required to establish a successful connection between the firewall and Panorama?
11Drag and drop the steps to configure a GlobalProtect portal and gateway on a Palo Alto Networks firewall into the correct order.
12Drag and drop the steps to perform a factory reset on a Palo Alto Networks firewall into the correct order.
13Match each Palo Alto Networks feature to its category.
14A network admin needs to push a security policy change to firewall-01 and firewall-02. Both firewalls have different interface configurations but should share the same security rules. What is the best way to achieve this using Panorama?
15A company has two PA-220 firewalls in active/passive HA. They want to ensure that if the active firewall loses internet connectivity but its management interface remains up, a failover occurs. Which monitoring method should be configured?
16An organization needs to send threat logs to two different syslog servers: one for real-time alerts and one for long-term storage. They also need to send traffic logs to the long-term storage syslog only. They have configured two syslog server profiles. What is the correct approach?
17A firewall uses an external SMTP server for email alerts. The SMTP server is reachable via a specific virtual router and interface. What must be configured to ensure the firewall uses the correct path to reach the SMTP server?
18An administrator wants to schedule regular configuration backups to an external server. Which THREE methods are valid ways to achieve this? (Choose three.)
19Refer to the exhibit. A firewall administrator is reviewing a Panorama template configuration. What is the purpose of the 'profile' statement under the interface?
20Refer to the exhibit. A security analyst reviews a traffic log entry in JSON format. Which firewall feature is responsible for including the 'user' field in the log?
21A network administrator needs to restrict which source IP addresses can access the firewall's web management interface. Which feature should be configured?
22An administrator wants to synchronize the firewall's clock with a central NTP server. Where is this configured?
23A syslog server is only reachable through a specific interface on the firewall. To ensure syslog logs are sent via that interface, which configuration is required?
24After making configuration changes, an administrator clicks 'Commit' but the changes are not applied. What is the most likely cause?
25A company requires automatic daily backups of the firewall configuration. Which method should be used?
26An administrator wants to allow ping (ICMP) and SSH access on a data interface (e.g., ethernet1/1) for troubleshooting. Which configuration is required?
27During troubleshooting, an administrator needs to review firewall system events such as user logins, configuration changes, and commit failures. Which log type should be examined?
28What is the purpose of the 'Telemetry' feature in PAN-OS?
29Refer to the exhibit. What is the default gateway of the firewall?
30Which two authentication methods can be used for administrative access to the firewall's web interface? (Choose two.)
31Which three of the following services are commonly permitted on the management interface? (Choose three.)
32An administrator needs to access the firewall's CLI via SSH, but the default SSH port (22) is blocked by the corporate firewall. Which configuration allows SSH on a non-standard port?
33A company uses Panorama to manage multiple firewalls. After pushing a template change, one firewall fails to commit with error 'invalid certificate path'. What is the most likely cause?
34A firewall is configured with multiple Virtual Systems (vsys). An admin wants to assign a custom admin role that can manage only specific vsys. Which role type supports this?
35Which license is required for the firewall to use URL filtering?
36Which THREE log types can be forwarded to a syslog server?
37Which TWO management methods allow CLI access to a Palo Alto Networks firewall?
38An administrator notices that the firewall's time is incorrect. Based on the exhibit, what is the most likely cause?
39An administrator modifies a security policy but the change does not take effect. What must the administrator do?
40A company is deploying a Palo Alto firewall in a high-availability (HA) pair. They want to ensure that when a failover occurs, session information is preserved to maintain active connections. Which feature must be enabled?
41Which of the following is NOT a valid method for upgrading PAN-OS software on a Palo Alto firewall?
42An administrator wants to ensure that a specific security policy rule is applied before all other rules. What should be configured?
43A company is deploying multiple Palo Alto firewalls and wants to manage them centrally. Which method should be used?
44An organization is implementing a high availability pair of Palo Alto firewalls in active/passive mode. Which three actions are necessary for proper failover functionality? (Choose three.)
45Refer to the exhibit. What is the effect of this configuration?
46A company needs to receive email alerts for critical system events. What is the recommended method to configure email notifications on a Palo Alto Networks firewall?
47An administrator configures SNMP monitoring on a firewall but receives no data from the SNMP manager. Which check should be performed first?
48A company uses Panorama to manage multiple device groups. They want to push a set of global security policies to all firewalls. Where should the administrator configure these policies in Panorama?
49Which TWO methods are valid for managing a Palo Alto Networks firewall? (Select two)
50Which THREE are required for Panorama to manage a firewall? (Select three)
51Which TWO are best practices for securing management access to a Palo Alto firewall? (Select two)
52A security analyst wants to send firewall logs to an external syslog server for long-term storage. Which three configuration steps are necessary?
53An administrator notices that the firewall's web interface is accessible via HTTPS but shows an expired certificate warning. The firewall's management certificate was issued by an internal CA and has a validity of two years. The administrator checks the certificate and sees it expired yesterday. The administrator generates a new self-signed certificate through the firewall's GUI. After generating, the administrator assigns the new certificate to the HTTPS management interface. Despite this, the firewall still presents the old expired certificate when accessed. What is the most likely cause?
54After a firewall upgrade, the system clock shows a time that is five minutes behind the actual time, even though NTP is synchronized. What is the most likely cause?
55An administrator needs to restrict access to the firewall's web management interface to only the IT department subnet 10.0.0.0/24. The firewall's management interface is in the 'Management' zone. Which configuration step is required to enforce this restriction?
56A security administrator at a branch office needs to allow a remote vendor to access the firewall's web management interface only from IP address 203.0.113.50. The firewall's management interface is in the Management zone. Which Palo Alto Networks feature should the administrator use to restrict access?
57A network administrator wants to ensure that the firewall sends SNMP traps to a monitoring server at 192.168.1.50. The administrator has already configured the SNMP community string and added the trap destination under Device > Setup > Services. However, traps are not being received. What is the most likely missing configuration?
58An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The firewall has two virtual routers: VR1 for the internal network and VR2 for the internet. The syslog server is reachable only through VR1. Which configuration setting must be applied to ensure syslog messages are sent via VR1?
59A security administrator needs to restrict access to the firewall's web management interface to only the IP address 10.1.1.100. The administrator logs into the firewall and navigates to Device > Setup > Management. Which configuration should be modified?
60A network security administrator needs to ensure that a Palo Alto Networks firewall sends SNMP traps to a monitoring server at 10.1.1.50 using the MGT interface. The administrator has already added the SNMP community string and trap destination under Device > Setup > Services > SNMP. However, no traps are being received. Which additional configuration is required to ensure traps are sent from the MGT interface?
61A network security engineer is configuring a Palo Alto Networks firewall to send SNMP traps to a management server. The engineer has already configured the SNMP community string and the trap destination IP. However, the management server is not receiving any traps. Which additional configuration is required to allow SNMP traps to be sent?
62An administrator is configuring a Palo Alto Networks firewall to send email alerts for critical system events. The administrator has configured an SMTP server under Device > Setup > Services > Email. However, test emails are not being delivered. Which additional step is required to allow the firewall to send email alerts?
63An administrator wants to ensure that only the firewall administrator's workstation at 203.0.113.45 can reach the web management interface on a PA-3220 running PAN-OS 10.2. The workstation is on the trust zone, and management access is currently allowed from any address on the management interface. Which configuration object should the administrator create and apply to the management interface?
64An administrator manages a PA-3220 running PAN-OS 10.2 with two virtual routers: VR-A for the internal network and VR-B for the internet. The firewall must send SNMP traps, syslog, and email alerts to servers reachable only through VR-B. Which setting directly controls which virtual router the firewall uses to egress that management-plane traffic?
65An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable via a specific interface and virtual router. Which two configurations are required to ensure that syslog messages are sent from the correct source interface? (Choose two.)
66A security administrator is configuring a Palo Alto Networks firewall to send syslog messages to an external syslog server at 203.0.113.10. The syslog server is reachable only through the ethernet1/1 interface, which is in the untrust zone. The administrator has configured the syslog server under Device > Server Profiles > Syslog and attached it to a log forwarding profile. However, syslog messages are not being received by the server. What is the most likely cause?
67A network administrator needs to configure SNMPv3 on a Palo Alto Networks firewall to allow a monitoring server to query interface statistics. The administrator wants to ensure that SNMP queries are authenticated and encrypted. Which SNMPv3 configuration is required to meet these requirements?
68A network security administrator needs to back up the firewall configuration before making changes. The administrator wants to store the backup on an external SCP server at 198.51.100.10 using the account 'backupuser'. Which sequence of steps should the administrator take in the web interface?
69An administrator at a branch office with a PA-440 needs to allow the firewall itself to resolve external hostnames and to forward DNS queries from internal clients to public resolvers. The administrator wants to configure a DNS proxy on the firewall so clients use the firewall's interface IP as their DNS server. Which configuration step is required to enable this behavior?
70A firewall administrator needs to ensure that the firewall can resolve domain names for security policy rules that use FQDN objects. The firewall is deployed in a network where DNS servers are reachable only through the dataplane interface ethernet1/2, which is in the untrust zone. The management interface cannot reach any DNS server. Which configuration should the administrator use to allow the firewall to resolve FQDNs?
71An administrator is configuring a Palo Alto Networks firewall to use an external LDAP server for administrator authentication. The administrator wants to ensure that only members of the 'NetworkAdmins' group can log in with read-write privileges. Which configuration steps are required?
72An administrator is configuring a new PA-3220 firewall and needs to allow DNS queries from the internal network to an external DNS server. The internal network is in the Trust zone, and the external DNS server is reachable via the Untrust zone. Which type of security policy rule should be created to permit this traffic?
73A network security engineer is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable only through the untrust zone via the ethernet1/2 interface, which is in the untrust zone and uses the default virtual router. The engineer wants to ensure that syslog traffic egresses via ethernet1/2 and uses the correct source IP address. Which configuration should the engineer perform?
74An administrator needs to allow administrators to authenticate to the firewall's web interface using an external LDAP directory at ldap.corp.example.com, while still allowing a local break-glass account. The directory uses a bind DN of cn=svc-bind,ou=service,dc=corp,dc=example,dc=com. After configuring the LDAP server profile under Device > Server Profiles > LDAP, authentication still fails for directory users. Which additional step is required?
75An administrator is configuring a Palo Alto Networks firewall to send SNMP traps to a monitoring server at 10.1.1.50. The administrator has already configured the SNMP community string under Device > Setup > Operations > SNMP Setup. Which two additional configurations are required to ensure traps are sent successfully? (Choose two.)
76A network security administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable only via a specific interface in the 'untrust' zone. The administrator creates a syslog server profile and a log forwarding profile. Which additional configuration is required to ensure that syslog messages are sent from the firewall's interface in the 'untrust' zone?
77A security administrator at a company with a PA-5220 running PAN-OS 10.2 must ensure that configuration backups can be restored to a replacement firewall of the same model. The administrator plans to use scheduled configuration exports and also wants to retain a copy of the running configuration before a major change. Which TWO actions will satisfy these requirements? (Choose two.)
78A security engineer is deploying a PA-5220 firewall in a high-availability active/passive pair. The engineer wants to ensure that the management interface of the passive firewall is reachable for out-of-band management. The firewalls are configured with HA1 and HA2 links. Which statement accurately describes the management interface behavior in this HA configuration?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to upgrade PAN-OS in the correct order, keep HA peers on matching versions, fix time/NTP issues, and configure a virtual wire end to end. The single most important thing: verify both HA peers run the same PAN-OS version before expecting sync to succeed.
The Courseiva PCNSA question bank contains 78 questions in the Device Management and Services domain, covering the 22% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Device Management and Services domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included