Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
Start practicing
Troubleshoot — choose a session length
Free · No account required
Domain overview
The Troubleshoot domain (11%) covers diagnosing PAN-OS and Panorama issues: traffic flow failures, GlobalProtect connectivity, decryption problems, and commit or HA errors. The exam presents scenario-based questions asking you to identify the root cause from CLI output, logs, or GUI state, then select the correct diagnostic command or fix.
Exam objectives
Reading 'show session all filter' and 'test security-policy-match' output to trace dropped traffic
Using 'show system logdb-quota' and log forwarding to isolate logging pipeline failures
Diagnosing GlobalProtect tunnel failures via 'show global-protect-gateway statistics' and gateway logs
Interpreting HA state with 'show high-availability state' and resolving split-brain or suspended peers
Assuming a commit succeeded without checking 'show jobs all' for partial or failed commits on managed firewalls
Confusing flow ownership in active/active HA, so session lookups run on the wrong peer and show no data
Blaming the firewall for app failures when the real cause is a decryption profile or SSL forward proxy exclusion
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is experiencing intermittent connectivity issues between two branch offices connected via an IPSec tunnel. Users report that they can access resources for a few minutes, then lose connectivity, and after a short time it comes back. Which troubleshooting step should be taken first?
2A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?
3A user reports that they cannot access a specific website. The firewall security policy allows web traffic. The administrator checks the traffic log and sees that the session is being denied due to a 'URL Filtering' block. What should the administrator do to allow access?
4An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?
5Which THREE components should be verified when troubleshooting a site-to-site IPSec VPN that is not coming up?
6Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?
7Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?
8A company has two Palo Alto Networks firewalls in an active/passive high availability pair. The firewalls are configured with a virtual IP (VIP) for the internal network. Recently, the passive firewall was upgraded to a new PAN-OS version. After the upgrade, the active firewall is still running the old version. The administrator wants to perform a failover to make the upgraded firewall active. However, when the administrator attempts to manually failover, the new passive firewall does not become active. The HA synchronization status shows 'synchronized' but the preemption is disabled. The administrator checks the HA configuration and finds that the peer's version is not compatible. What should the administrator do to successfully failover to the upgraded firewall?
9A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?
10A firewall administrator is troubleshooting a scenario where users cannot reach an internal web server. The security policy allows the traffic, and the server is reachable from other networks. What should the administrator check first?
11A network engineer needs to verify that a specific security rule is being hit by traffic. Which firewall log should be examined?
12Which TWO are valid methods to troubleshoot a firewall not passing traffic? (Choose two.)
13Which THREE are required for a successful firewall-to-firewall IPSec VPN tunnel? (Choose three.)
14A network administrator wants to verify if a specific internal IP address (10.1.1.100) is being translated to a public IP when accessing the internet. Which CLI command should be used?
15Refer to the exhibit. A user at 10.1.1.10 is trying to connect to a web server at 203.0.113.5 on port 443. The session shows 'State: DROP' with reason 'policy-deny'. However, the administrator has a security policy rule that allows SSL traffic from the source zone to the destination zone. What is the most likely cause of the drop?
16Refer to the exhibit. A firewall system log contains a critical license expiration entry for URL Filtering. What will happen to URL Filtering functionality?
17A network engineer notices that traffic from a specific subnet is being dropped by the firewall. The traffic log shows 'drop' with reason 'policy deny'. The engineer checks the security policy and confirms there is an allow rule for that subnet. What should be checked next?
18During a troubleshooting session, a user reports that they cannot access an internal web server through the firewall's public IP. The firewall is configured with destination NAT. The engineer checks the NAT policy and sees the rule is active. What should be the next step to verify the NAT is functioning correctly?
19An administrator is troubleshooting VPN tunnel flapping. The logs show multiple Phase 2 rekeys. The tunnel uses IKEv2 with pre-shared key. What is the most likely cause?
20A network engineer is troubleshooting why a Palo Alto Networks firewall is not generating any traffic logs for sessions that match a security policy rule set to allow. The engineer confirms that the rule is hit and traffic passes successfully. Which of the following is the most likely reason for the absence of logs?
21A network engineer is troubleshooting why a Palo Alto Networks firewall is not decrypting SSH traffic even though an SSL Forward Proxy decryption policy is configured for the internal zone. The engineer confirms that the SSH traffic matches the decryption policy and that the forward trust and untrust certificates are installed and valid. What is the most likely reason the SSH traffic is not being decrypted?
22A security administrator is investigating why a session was terminated with the flag 'tcp-rst-from-server' in the traffic logs. The administrator has confirmed that the server is reachable and responding to pings. Which of the following is the most likely cause for this session termination?
23A firewall administrator is troubleshooting an issue where users behind a PA-3220 cannot access a public web server. The security policy allows the traffic. The administrator runs 'show session all filter source 10.1.1.50 destination 203.0.113.10' and sees a session with application 'incomplete' and no packets received from the server. Which tool should the administrator use to determine why the firewall is not receiving a response from the server?
24A Palo Alto Networks firewall administrator is troubleshooting why a session was terminated with the flag 'tcp-rst-from-client'. The administrator wants to identify possible causes for this termination flag. Which two factors can cause a session to be terminated with 'tcp-rst-from-client'? (Choose two.)
25A network administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions in real-time to identify which application is consuming the most bandwidth. Which command should the administrator use?
26A network security engineer is troubleshooting why a user's session to a SaaS application is being decrypted by SSL Forward Proxy but then immediately reset. The engineer checks the session details and sees the session end reason as 'tcp-rst-from-server'. Packet capture on the firewall shows that the server is sending a TCP RST after the client sends a TLS Client Hello. The firewall's decryption profile is configured to block sessions with untrusted issuers. What is the most likely cause of the reset?
27A security administrator is troubleshooting why a user cannot access an internal server at 192.168.1.50 from the trust zone. The firewall is a PA-5220 running PAN-OS 10.2. The administrator checks the traffic log and sees that the session is allowed by a security policy rule. However, the user still cannot connect. The administrator runs 'show session all filter source 10.1.1.10 destination 192.168.1.50' and sees the session state as 'ACTIVE' but with 'tcp-rst-from-server' flag. What is the most likely cause?
28A firewall administrator is troubleshooting why a user is unable to access a website. The administrator checks the traffic logs and sees that the session was allowed by the security policy, but the application is identified as 'ssl' instead of 'web-browsing'. The website uses HTTPS on port 443. What is the most likely reason for the application being identified as 'ssl'?
29A firewall administrator is troubleshooting an issue where a PA-3260 is experiencing high dataplane CPU utilization. The administrator runs 'show running resource-monitor' and sees that the CPU is consistently above 90%. Which command should the administrator use to identify the top applications contributing to the high CPU usage?
30A SOC analyst reports that a critical security policy rule denying traffic from the 'Untrust' zone to the 'DMZ' zone is not generating any traffic logs, even though the analyst sees a high volume of denied traffic in other tools. The administrator confirms that the rule is correctly configured to deny and that logging is enabled at the rule level. What is the most likely reason for the missing logs?
31A firewall administrator is troubleshooting a connectivity issue where users cannot reach a web server. The administrator checks the traffic log and sees that the session is being denied by a security policy rule. The administrator verifies that the rule is correctly configured to deny the traffic. However, the administrator wants to see which rule is blocking the traffic. Which action should the administrator take?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
The Courseiva PCNSE question bank contains 31 questions in the Troubleshoot domain, covering the 11% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Troubleshoot domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included