Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An administrator needs to block traffic from a specific internal IP address to the internet. Which object type should be used in the security policy source field?
Address object
An address object holds the specific internal IP as a host or range, so referencing it in the source field lets the policy match and block that traffic. It satisfies the requirement to identify a single internal IP precisely, unlike regions or application objects.
Tag
Address group
Region
A company has multiple branch offices that use overlapping private IP ranges (192.168.0.0/16). To avoid conflicts when these branches connect to the data center via IPsec, the administrator needs to translate branch source IPs to unique addresses. Which object type is best suited for this task?
NAT address pool
A NAT address pool supplies unique translated source addresses for outbound IPsec traffic, resolving overlapping 192.168.0.0/16 ranges between branches. It maps each branch's private source IPs to distinct pool addresses, preventing conflicts when connecting to the data centre.
External dynamic list
Service group
IPsec Crypto profile
During a security audit, an administrator notices that a security policy rule uses an address group that includes an FQDN object. The FQDN resolves to multiple IP addresses that change frequently. What is the best practice for ensuring the firewall uses the current resolved IPs without manual intervention?
Use a region object instead
Create a dynamic address group with a tag-based filter
Use an FQDN object in the address group; the firewall resolves it automatically
FQDN objects automatically resolve and update IPs.
Manually add all possible IP addresses to an address group
An administrator wants to allow only specific applications (e.g., web-browsing, ssl) from the internal network to the internet. Which object type should be used in the security policy application field?
Application object
Application objects identify traffic by application signatures rather than port or protocol, so the policy can permit web-browsing and ssl specifically. This satisfies the requirement to allow only those named applications from internal to internet.
Application filter
Application group
Service object
Which TWO statements about External Dynamic Lists (EDLs) are true?
EDLs can be used in security policy source and destination fields.
EDLs can be used as address objects in policies.
EDLs have a fixed refresh interval that cannot be changed.
EDLs must be manually updated by an administrator.
EDLs support both IP addresses and URLs.
EDLs can contain IPs, URLs, or domains.
EDLs allow the administrator to add individual IPs directly via the GUI.
Drag and drop the steps to configure a VLAN interface on a Palo Alto Networks firewall into the correct order.
Create VLAN object, then assign Layer 2 interfaces to VLAN, then configure IP address on VLAN interface, then create security policy, then commit
This is the correct order because you must first create the VLAN, then assign interfaces to it, then assign an IP to the VLAN interface, then create a security policy to permit traffic, and finally commit the changes.
Create VLAN object, then configure IP address on VLAN interface, then assign Layer 2 interfaces to VLAN, then create security policy, then commit
Create security policy, then create VLAN object, then assign Layer 2 interfaces to VLAN, then configure IP address on VLAN interface, then commit
Create VLAN object, then assign Layer 2 interfaces to VLAN, then configure IP address on VLAN interface, then commit, then create security policy
Want more Managing Objects practice?
Practice this domainA network engineer is troubleshooting a drop in traffic from a critical application. The traffic is allowed by the security policy, but the firewall is dropping the packets. The engineer views the session log and sees that the session is being terminated due to 'tcp-non-syn'. What is the most likely cause?
The TCP sequence numbers are out of order, causing the packets to be out of the expected window.
The NAT policy is misconfigured, causing the source IP to not be translated correctly.
The security policy uses an incorrect service object that doesn't match the application.
Asymmetric routing is causing packets to arrive at a firewall that did not see the initial SYN.
The firewall drops the session because it never observed the initial SYN handshake. With asymmetric routing, return or subsequent packets traverse a different firewall that lacks session state, so it treats them as non-SYN and terminates the session.
An organization wants to prevent data exfiltration via DNS tunneling. Which security profile should be applied to the outbound DNS traffic?
DNS Security profile
DNS tunnelling encodes stolen data within DNS queries and responses, which the DNS Security profile detects and blocks by inspecting DNS payloads for malicious patterns, including tunnelling signatures and anomalous query behaviour. Applying it to outbound DNS traffic directly satisfies the requirement to prevent exfiltration.
Vulnerability Protection profile
URL Filtering profile
Anti-Spyware profile
A company has a firewall configured with multiple virtual routers. A user on a trusted network can ping the firewall's management IP but cannot reach an external server. The security policy allows the traffic. What is the most likely cause?
A zone protection profile is blocking ICMP packets.
The virtual router does not have a default route to the external network.
The management interface responds because it sits on the firewall itself, but forwarding to an external server requires the virtual router to hold a default route toward the untrusted next hop. Without it, the permitted traffic is dropped for lack of a route.
The decryption policy is blocking the traffic because it is not decrypted.
The NAT policy is missing for the outbound traffic.
An administrator needs to allow inbound SMTP traffic to a mail server located in the DMZ. The firewall has a public IP address on the external interface. Which configuration is necessary to ensure the mail server receives the traffic?
Configure a Source NAT rule to translate the mail server's IP to the public IP.
Configure a Destination NAT rule and a security policy rule allowing SMTP from external to DMZ.
The mail server holds a private DMZ address, so inbound SMTP to the firewall's public IP requires destination NAT to translate the public address to the server, plus a security policy permitting SMTP from the external zone to the DMZ zone.
Configure a security policy rule with source NAT to translate the public IP to the private IP.
Configure a security policy rule allowing SMTP from external to DMZ without NAT.
Which TWO actions should be taken to protect against DNS tunneling? (Choose two.)
Enable DNS Security on the outbound DNS traffic.
DNS Security detects tunneling attempts.
Configure DNS policies to block requests to unknown domains.
This restricts DNS to known domains only.
Allow all TCP traffic on port 53.
Enable logging on all DNS traffic for analysis.
Block all UDP traffic on port 53.
Which TWO are valid methods to decrypt SSL/TLS traffic on a Palo Alto Networks firewall? (Choose two.)
IPsec Decryption
SSH Proxy
SSL Inbound Inspection
SSL Inbound Inspection decrypts traffic destined to internal servers by installing the server's certificate and private key on the firewall, letting it terminate and inspect inbound TLS sessions. This satisfies the requirement for a valid decryption method alongside forward proxy inspection.
Decryption Mirror
SSL Forward Proxy
SSL Forward Proxy decrypts outbound client-initiated TLS sessions by presenting a firewall-generated certificate to internal clients, then re-encrypting to the external server. This is the standard method for inspecting traffic leaving the network, distinct from inbound decryption.
Want more Securing Traffic practice?
Practice this domain28% of exam · 6 sample questions below
A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?
The rule only allows traffic from Engineering to Servers zone, not DMZ.
Security rules match on both source and destination zones, so a rule permitting Engineering to Servers does not cover Engineering to DMZ. Traffic destined for the DMZ zone matches no allow rule and hits the default interzone deny, producing the observed denial.
The rule is configured as an intrazone rule.
The rule is disabled in the rulebase.
SSL decryption is blocking the traffic.
A network engineer needs to ensure that all traffic from the 'Guest' zone to the 'Internet' zone is inspected for malware, but also wants to allow high-bandwidth video conferencing traffic to bypass threat inspection for performance reasons. Which approach best achieves this?
Create two rules: one for general traffic with 'allow' action and a 'threat' profile, and a higher-priority rule for video conferencing traffic with 'allow' action and no threat profile.
Security policy is evaluated top-down, so a higher-priority rule matching video conferencing with no threat profile permits that traffic uninspected, while the lower general rule still applies the threat profile to all remaining Guest-to-Internet sessions.
Create a single rule with 'allow' action and no security profiles, and rely on the firewall's default behavior to inspect malware.
Create a single rule with 'allow' action and a 'threat' profile applied, and rely on the firewall's ability to skip inspection for video traffic automatically.
Use policy-based forwarding to route video traffic to a separate interface that has no security profiles.
A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?
The source IP is negated in the rule.
The rule is placed at the top of the rulebase and overridden by a later rule.
The rule is positioned below an allow rule that matches the same traffic.
Palo Alto Networks evaluates security rules top-down and stops at the first match, so a rule placed below an allow rule covering the same source, destination and application is never reached. The blocking rule must be moved above the matching allow rule to take effect.
The rule is disabled in the rulebase.
A firewall administrator is tasked with implementing a policy that allows SSH access from the 'Admin' zone to the 'Core' zone only for specific administrators, and all other SSH attempts should be logged and dropped. The company has a large number of administrators. Which method is most efficient and scalable?
Create a single rule with source zone 'Admin', destination zone 'Core', application 'ssh', source user 'any', action 'allow' and enable logging.
Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', source user set to an LDAP group containing the administrators, action 'allow', and a second rule with same match criteria but action 'drop' and log at end.
User-ID integration allows scalable user-based policies.
Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', action 'allow', and rely on the firewall's default deny rule for others.
Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', source address list of all administrators' IPs, action 'allow', and a catch-all drop rule.
Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)
The position of the deny rule in the rulebase relative to allow rules.
A higher-priority allow rule might match before the deny rule.
Whether the deny rule is disabled.
A disabled rule does not affect traffic.
Whether the source/destination zones or addresses are correctly defined.
Misconfigured match criteria can cause unexpected blocking.
Whether logging is enabled on the rule.
Whether SSL decryption is enabled for the traffic.
A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?
Allow the traffic because rule 1 matches and allows all web traffic.
Allow the traffic because rule 3 allows all traffic.
Deny the traffic because no rule allows social-networking.
Deny the traffic because rule 2 matches and denies social-networking.
Palo Alto Networks evaluates security rules top-down and stops at the first match. Rule 2 matches the source zone, address and social-networking application, and its action is deny, so the firewall blocks the session before any later allow rule is evaluated.
Want more Policy Evaluation and Management practice?
Practice this domain22% of exam · 6 sample questions below
A security administrator notices that a user's traffic is being blocked unexpectedly. The user's IP is 10.1.1.100, and the traffic is destined to a web server at 192.168.2.10. The administrator has already verified that there are no security rules explicitly denying the traffic. Which Log Viewer query should the administrator use to quickly identify the cause?
Search Traffic logs with filters for source 10.1.1.100 and destination 192.168.2.10
Filtering Traffic logs by source 10.1.1.100 and destination 192.168.2.10 isolates the exact flow, revealing the implicit deny or policy match causing the block. Since no explicit deny rule exists, the session detail exposes which rule or default action dropped it.
Search Threat logs for the destination IP
Search Config logs for any rule changes
Search System logs for the user's IP
A company wants to deploy a new firewall with a management interface on a separate VLAN to ensure management traffic is isolated from production traffic. Which interface type should be used for management access?
HA1 interface
VLAN interface
Ethernet 1/1
MGT (Management) interface
The MGT interface carries management-plane traffic only, so placing it on a dedicated VLAN isolates administrative access from production data flows. This satisfies the stem's isolation requirement, unlike dataplane or HA interfaces that serve traffic forwarding.
An administrator needs to generate a report showing all applications used by a specific user group over the past week. Which method is most efficient?
Export Traffic logs to CSV and analyze in Excel
Use the Top Applications report in the Reports tab
Use the ACC (Application Command Center) and filter by user group and time range
The ACC aggregates application, user, and threat data with native filtering by user group and time range, delivering the report directly from existing logs. This avoids exporting raw traffic logs or building custom queries, making it the most efficient method for this specific reporting need.
Use the Monitor tab's Session Browser with a filter for the user group
A network engineer wants to configure a new VLAN interface on a Palo Alto Networks firewall. After creating the VLAN object and assigning it to an Ethernet interface, the VLAN interface remains down. What is the most likely cause?
The VLAN interface needs an IP address configured
The VLAN interface must be assigned to a virtual router
The firewall needs a commit to apply the changes
The Ethernet interface is not set to layer 2 mode or the VLAN tag is not allowed
A Palo Alto VLAN interface only comes up when its parent Ethernet interface is configured as layer 2 and the VLAN tag is permitted on that interface. Without layer 2 mode or an allowed tag, the VLAN object has no traffic path, leaving the interface down.
An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?
Configure HA1 and HA2 interfaces with appropriate IPs
Enable Config Sync on the HA General tab
Enable Session Setup and State Synchronization under HA configuration
Enabling Session Setup and State Synchronization under HA configuration replicates session tables and state between peers, so established flows survive failover without re-establishment. Without it, the passive firewall lacks session context and drops active connections during transition.
Configure Path Monitoring to detect link failures
A security analyst notices that a legitimate application is being incorrectly identified as a different application by the firewall. What is the best first step to resolve this issue?
Reboot the firewall to refresh the application cache
Disable the application override and use port-based rules
Verify the application signature in the App-ID database and submit a false-positive report if needed
App-ID misidentification stems from signature or decoder mismatches, so verifying the application signature in the App-ID database confirms whether the firewall's identification is genuinely wrong. Submitting a false-positive report then lets Palo Alto Networks correct the signature, addressing the root cause rather than applying workarounds.
Create a custom App-ID to override the incorrect identification
Want more Device Management and Services practice?
Practice this domain10% of exam · 6 sample questions below
A company uses App-ID to control cloud storage applications. Users report that uploads to Google Drive are blocked even though a rule allows 'google-drive-base'. What is the most likely cause?
The firewall is not connected to the cloud for App-ID updates.
The rule allows only 'google-drive-base' but the uploads use 'google-drive-upload'.
Google Drive uploads traverse a distinct App-ID signature, 'google-drive-upload', separate from 'google-drive-base'. Since the security rule permits only the base application, the upload session matches no allow rule and is denied by the implicit interzone default. App-ID identifies each function independently, so both signatures must be permitted for full access.
Decryption is not enabled for Google Drive traffic.
An application override is configured for Google Drive.
A security team notices that custom application 'myapp' is not being identified by App-ID even though the correct application override is in place. What should they verify first?
Ensure the application uses a standard port.
Ensure SSL decryption is enabled for the application.
Check if the application override is applied to the correct rule.
Verify that the traffic reaches the firewall and is allowed by a security policy rule that has App-ID enabled.
App-ID requires the session to be permitted by a security policy rule with application identification enabled; otherwise traffic is dropped before inspection. Verifying the packet reaches the firewall and matches such a rule is the prerequisite for any App-ID override to take effect.
A security administrator wants to block all traffic using the BitTorrent protocol regardless of port. Which method should they use?
Use URL Filtering to block BitTorrent.
Create a security rule with Application set to 'bittorrent' and Action set to 'Deny'.
Palo Alto Networks App-ID identifies BitTorrent by its traffic characteristics rather than port, so a security rule matching the bittorrent application with a Deny action blocks the protocol even when it uses non-standard or randomised ports.
Use Data Filtering to block BitTorrent traffic.
Block the commonly used ports for BitTorrent.
After a security policy change, users complain that they cannot upload files to a custom web application. The rule allows the custom application 'webapp' and Content-ID is enabled. What is the most likely cause?
The application 'webapp' is not allowed due to an application override.
SSL decryption is not enabled.
A file blocking profile is blocking the upload.
With Content-ID enabled, the firewall inspects the upload and a file blocking profile applied to the matching rule drops the transfer if the file type is blocked. The application itself is permitted, so the file blocking profile is the likely cause.
App-ID is not identifying the application correctly.
What is the primary benefit of using Content-ID in a security policy?
It blocks malicious URLs.
It prioritizes traffic for specific applications.
It enables threat prevention and file blocking on allowed applications.
Content-ID inspects permitted traffic for threats and files, satisfying the stem's requirement to identify the primary benefit. Unlike App-ID, which classifies applications, Content-ID operates after the application is allowed, applying antivirus, anti-spyware and file-blocking profiles. This layered inspection prevents malicious content traversing sanctioned applications.
It identifies applications regardless of port.
Which TWO of the following are true about App-ID? (Choose two.)
App-ID cannot identify custom applications.
App-ID identifies applications regardless of port.
App-ID decouples identification from TCP/UDP port numbers, so applications are recognised by their actual traffic characteristics rather than the port they happen to use. This satisfies the requirement that identification holds true even when applications run on non-standard or evasive ports.
App-ID uses signatures, protocol decoding, and behavioral analysis to identify applications.
App-ID combines multiple detection techniques: signature matching, protocol decoding and behavioural analysis. This layered approach satisfies the need to identify applications accurately, including those using encryption or evasive tactics that any single method alone would miss.
App-ID can only identify applications on standard ports.
Want more App-ID and Content-ID practice?
Practice this domain10% of exam · 6 sample questions below
A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?
The decryption policy uses 'No Decrypt' for the internal application's URL category.
The decryption policy is set to 'Decrypt' for all traffic, causing performance bottlenecks.
The firewall's CA certificate is not installed in the trusted root store on user endpoints.
SSL Forward Proxy presents a certificate signed by the firewall's CA to endpoints. If that CA certificate is absent from endpoints' trusted root stores, certificate validation fails and internal applications relying on TLS cannot load, matching the reported failures.
The firewall is configured to decrypt traffic from the internal zone, but not the external zone.
An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?
Create a decryption rule with action 'Decrypt' and destination zone 'Untrust'.
Create a decryption rule with action 'No Decrypt' for the URL category 'Financial Services'.
A decryption rule matching the Financial Services URL category with action 'No Decrypt' exempts that traffic from SSL Forward Proxy inspection, satisfying the compliance constraint that financial sites remain encrypted. Rule order matters: it must precede any broader decrypt rule.
Create a decryption rule with action 'No Decrypt' for all traffic, then a rule above it to decrypt all other traffic.
Create a decryption rule with action 'Decrypt' for the URL category 'Financial Services'.
A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?
The firewall logs a critical system alert.
Users receive certificate warnings when accessing HTTPS sites.
SSL Forward Proxy presents the firewall's signing certificate to clients in place of the real server certificate. Once that certificate expires, clients cannot validate the chain, so browsers display certificate warnings and users must manually bypass them before HTTPS pages load.
Decryption stops working and all SSL traffic is blocked.
The firewall automatically renews the certificate from the CA.
Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)
Use a self-signed certificate for decryption.
Decrypt all internal traffic including server-to-server.
Exclude traffic to financial and healthcare sites from decryption.
Forward proxy decryption breaks the end-to-end trust model and exposes sensitive content, so regulatory and privacy obligations make financial and healthcare categories poor candidates for inspection. Excluding them from decryption preserves compliance and avoids legal exposure while still decrypting other traffic.
Decrypt all outbound traffic regardless of destination.
Install the firewall's CA certificate on all client devices.
Forward proxy decryption requires clients to trust the firewall's signing CA; otherwise every re-signed certificate triggers a browser warning. Distributing the firewall's CA certificate to all client trust stores via group policy or MDM establishes that chain of trust and enables transparent decryption.
Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)
No Decrypt
No Decrypt leaves matching traffic encrypted, so the firewall forwards it without inspection. This satisfies the scenario's requirement to exempt traffic that cannot legally be decrypted, such as financial or healthcare sessions, while still enforcing the decryption policy rule's action set alongside Decrypt and No Decrypt with decryption profile options.
Forward Untrust Certificate
Forward Untrust Certificate is a valid decryption policy action: it presents an untrusted certificate to the client, prompting a browser warning, rather than decrypting traffic. This satisfies the scenario's requirement for a rule action that blocks or warns on sessions without performing decryption, alongside No Decrypt and Decrypt options.
Block
Forward
Decrypt
Decrypt is a valid action within a decryption policy rule, instructing the firewall to terminate the session's encryption and inspect the plaintext payload. The other rule actions are no-decrypt and bypass, so this satisfies the question's requirement.
Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?
Error due to rule conflict
Block
No Decrypt (bypass decryption)
No Decrypt satisfies the financial-services category constraint: the firewall matches the URL category and applies a decryption bypass policy, so the HTTPS session passes through encrypted. Traffic still undergoes App-ID and security profile inspection, but the firewall cannot inspect payload contents, preserving privacy for banking sessions.
Decrypt
Want more Decryption and Monitoring practice?
Practice this domainThe PCNSA exam has 80 questions and must be completed in 80 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Managing Objects, Securing Traffic, Policy Evaluation and Management, Device Management and Services, App-ID and Content-ID, Decryption and Monitoring. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks PCNSA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.