Be able to build a working policy set: define zones and interfaces, write security and NAT rules that match real traffic, attach URL Filtering profiles, and design HA or redundant egress. The single most important thing is getting zone, address, and NAT matching correct so traffic is actually allowed and translated.
Start practicing
Deploy and Configure Firewalls — choose a session length
Free · No account required
Domain overview
This domain covers initial firewall deployment and day-to-day configuration on PAN-OS: zones, interfaces, virtual routers, security and NAT policy, URL filtering, and redundancy. Questions present real topologies (DMZ web server, branch office, outbound internet) and ask you to choose the correct policy, interface mode, or high-availability design to satisfy the stated requirement.
Exam objectives
Security policy rule order and zone-based matching from Untrust to DMZ
NAT policy for inbound destination translation and outbound source translation
Interface types and modes: L3, L2, virtual wire, tap, and subinterfaces
High availability, virtual router redundancy, and policy-based forwarding for outbound redundancy
Assuming a security policy alone permits inbound traffic; the matching NAT rule and destination zone must also be correct.
Forgetting that URL filtering requires the traffic to match a security policy with a URL Filtering profile attached.
Confusing active/passive HA with active/active, or missing that redundant paths need separate virtual routers or PBF.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?
2A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?
3An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?
4Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?
5The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?
6The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?
7A company needs to provide internet access to 500 internal users using a single public IP address. Which NAT method should be configured?
8A security administrator notices that traffic to a specific website is being denied. The traffic log shows that the application is 'ssl' and the action is 'deny' with the rule being 'Allow-SSL'. What is the most likely cause?
9By default, what is the action on traffic between two different zones without any security rule?
10An administrator adds a new security rule to allow outbound 'web-browsing' and 'ssl' traffic. After committing, users report that some HTTPS sites are still blocked. Traffic logs show that the traffic matches the new rule but is denied. What is the most likely cause?
11In an Active/Passive HA pair, which statement is true regarding configuration synchronization?
12A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?
13An administrator wants to ensure that all traffic from the 'Trust' zone to the 'Untrust' zone is inspected by WildFire. Which configuration is required?
14Which THREE of the following are mandatory components for GlobalProtect client connectivity?
15A company uses User-ID to map users to IPs. Some users report that their traffic is being blocked even though they are in the correct user group for access. The security policy uses user-based conditions. What is a likely cause?
16A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?
17A firewall receives traffic with IP options enabled. How does the firewall handle this traffic by default?
18An organization has a firewall in HA active-passive mode. After a failover, the new active firewall does not have the latest session table. What should be configured to ensure session synchronization?
19Which TWO factors can cause a firewall to not show any User-ID mapping for a user who is actively logged in?
20Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?
21Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?
22Refer to the exhibit. An administrator has configured this decryption policy but users in the 10.1.1.0/24 subnet receive certificate warnings when accessing HTTPS sites. What is the most likely cause?
23Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)
24A medium-sized enterprise recently deployed a PA-5250 firewall in a data center as the primary internet gateway. The network team configured the security policies to allow all outbound web traffic (HTTP/HTTPS) from the internal trust zone to the untrust zone, with URL filtering and threat prevention enabled. After the deployment, users complain that some legitimate websites, such as banking and healthcare portals, are being blocked. The team checks the URL filtering logs and sees that these sites are categorized as 'web-hosting' or 'dynamic-dns', which are in the block list. The company's compliance requires that all web traffic be inspected. What should the network engineer do to resolve the issue without reducing security?
25Refer to the exhibit. A user in the 10.0.0.0/8 network is unable to access a web server at 172.16.1.10 which is in the DMZ zone. The firewall's security policy is shown: source zone trust, destination zone untrust, application web-browsing, action allow. What is the most likely reason for the failure?
26A security administrator is deploying a PA-5220 firewall with a single external zone and several internal zones. The requirement is to allow DNS queries to any external DNS server while ensuring that responses are permitted only when they match an existing session. Which security policy configuration meets this requirement?
27An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?
28A network administrator is deploying a new Palo Alto Networks firewall and needs to configure the data-plane interfaces. The firewall will be placed between the internal network and the internet. The internal network uses private IP addresses and must be translated to a public IP address for outbound traffic. Which type of NAT should the administrator configure on the firewall?
29An administrator is configuring a Palo Alto Networks firewall to enforce security policies based on user identity. The environment uses Active Directory, and the administrator plans to deploy User-ID. Which TWO actions are required to enable User-ID to map IP addresses to usernames? (Choose two.)
30An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?
31An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?
32A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?
33A security administrator is configuring a Palo Alto Networks firewall to perform DNS sinkholing to detect and block malware callbacks. The firewall is deployed with a default route to the internet. The administrator wants to ensure that when an internal host attempts to resolve a known malicious domain, the firewall returns a sinkhole IP address (10.10.10.10) and logs the event. Which configuration is required to achieve this?
34A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?
35A security administrator is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for a specific user group. The administrator creates a decryption policy with source user group 'Finance', destination any, and action 'ssl-forward-proxy'. However, after committing, users in the Finance group report that they can still access HTTPS sites without any certificate warnings, and the firewall logs show no decryption. The administrator verifies that the decryption policy is placed correctly and that the forward trust certificate is installed and trusted by the clients. What is the most likely reason decryption is not occurring?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to build a working policy set: define zones and interfaces, write security and NAT rules that match real traffic, attach URL Filtering profiles, and design HA or redundant egress. The single most important thing is getting zone, address, and NAT matching correct so traffic is actually allowed and translated.
The Courseiva PCNSE question bank contains 35 questions in the Deploy and Configure Firewalls domain, covering the 14% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Deploy and Configure Firewalls domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included