Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
54real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
14% of exam · 6 sample questions below
A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?
Another rule earlier in the policy matches the traffic and allows it before reaching this rule.
PAN-OS evaluates rules top-down and stops at the first match, so an earlier allow rule for 10.1.0.0/16 permits the traffic before the logging rule is reached. Only the matched rule's log setting applies, hence no log entry appears.
The firewall is configured to not log interzone traffic.
The source address 10.1.0.0/16 is not part of the 10.0.0.0/8 subnet.
The logging profile is not applied to the rule.
A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?
allow
Permitting the session satisfies the requirement to admit inbound HTTPS from Untrust to the DMZ web server. A security policy action of allow passes matching traffic and applies the profile group, whereas deny or drop would block it. Since the destination is a specific server IP, this action forwards the connection to the web server.
reset-both
deny
drop
An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?
The source address 10.0.0.0/8 is not included in the source zone.
The destination address is set to 'any', which is not valid.
The traffic is intra-zone, not inter-zone.
A rule with a 'deny' action appears earlier in the security policy.
Palo Alto Networks evaluates security policy top-down and stops at the first matching rule. A deny rule positioned above the intended allow rule matches the traffic first, so the allow rule never appears in the log as a hit, explaining the observed denial.
Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?
Two physical or subinterfaces assigned to the vwire.
A vwire requires exactly two interfaces.
A management profile must be applied to the vwire.
A zone must be assigned to the vwire.
The interfaces must be of type 'aggregate'.
No IP addresses configured on the interfaces used in the vwire.
Interfaces in a vwire operate at layer 2 without IPs.
The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?
The VLAN ID is misconfigured as 20 instead of 10.
The sub-interface's VLAN tag must match the VLAN ID carried in the 802.1Q frame. Tagging it as VLAN 20 means frames arriving with VLAN 10 tags are dropped, so no traffic reaches the 192.168.10.1/24 gateway and routing fails.
The IP netmask is /24 but should be /16.
The zone is incorrectly named 'VLAN10'.
The virtual router is not correctly set.
The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?
The 'interface-address' option requires a specific translated address.
The rule is missing a 'from' zone specification.
Source NAT rules must include the source zone to determine when to translate.
The rule should be under 'destination-nat' instead of 'source-nat'.
The 'to-interface' should be 'any'.
Want more Deploy and Configure Firewalls practice?
Practice this domain7% of exam · 6 sample questions below
During a security audit, it is discovered that some HTTP traffic is being incorrectly identified as 'web-browsing' instead of 'ssl' even though the traffic uses HTTPS. The firewall is positioned as a transparent bridge and no SSL decryption is configured. What is the most likely cause?
SSL decryption must be enabled for the firewall to correctly identify SSL traffic.
The firewall is not seeing the full SSL handshake due to asymmetric routing.
A transparent bridge without decryption must infer the application from the TLS handshake. With asymmetric routing, return traffic bypasses the firewall, so it never observes the full handshake and falls back to classifying the flow as web-browsing on port 443 instead of ssl.
The default interzone rule is blocking the SSL identification packets.
The security policy allows 'web-browsing' before 'ssl' in the rule order.
A network administrator wants to allow only specific applications such as 'facebook-base' and 'youtube' while blocking all other applications. Which type of security rule should be used to achieve this?
Create a security rule with application conditions set to 'facebook-base' and 'youtube' and action set to 'allow'.
Application-based security rules match traffic by App-ID rather than port or IP, so specifying facebook-base and youtube with an allow action permits only those applications. An implicit deny then blocks all remaining applications, satisfying the allowlist requirement.
Create a security rule with destination port 80 and 443 and action set to 'allow'.
Create a security profile that blocks all applications not in the allow list.
Create a URL filtering rule to allow 'social-networking' and 'multimedia' categories.
A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?
The firewall must be rebooted for the custom App-ID to take effect.
An application override rule has not been configured to associate the traffic with the custom App-ID.
Application override is required to bypass signature-based identification and assign the custom App-ID.
The custom App-ID must be enabled in the 'Applications' section of the firewall settings.
The firewall cannot identify applications over UDP.
Which THREE of the following can cause App-ID to incorrectly identify traffic?
Multiple security rules are configured for the same traffic.
Asymmetric routing causes the firewall to see only one direction of traffic.
Asymmetric routing can prevent the firewall from seeing the full session, causing inaccurate identification.
SSL decryption is not enabled for the traffic.
Without decryption, App-ID cannot inspect encrypted payloads, leading to potential incorrect identification.
IP fragmentation occurs before the firewall.
Fragmentation can obscure application signatures, leading to misidentification.
Traffic is forwarded through an HTTP proxy.
Refer to the exhibit. A firewall administrator is troubleshooting why some applications are not being correctly identified. The firewall is running App-ID version 8000-7120. What does the 'appid packet buffer: 1024 KB' indicate?
App-ID can only handle 1024 KB of packet data per session.
The firewall can buffer up to 1024 KB of packet data for App-ID analysis.
The packet buffer figure defines how much packet payload the App-ID engine can hold in memory while matching signatures across multiple packets. Exceeding this 1024 KB limit truncates analysis, causing applications needing deeper inspection to be misidentified.
The firewall logs the first 1024 KB of every session for App-ID.
The firewall offloads App-ID processing to a dedicated buffer of 1024 KB.
A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?
Create a custom App-ID for custom-db-sync using the Application Object and define the appropriate signatures.
Creating a custom App-ID with signatures is the only way App-ID can recognise a proprietary protocol; no built-in decoder exists for it. Because the rule currently permits any application on TCP 4444, the firewall cannot classify the session, so defining the signature in the Application Object satisfies the identification constraint.
Enable unknown application identification in the security rule.
Use the default application override for port 4444 to allow traffic.
Change the security rule to use 'application-default' as the service to rely on port-based identification.
Want more Securing Traffic and App-ID practice?
Practice this domain7% of exam · 6 sample questions below
An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?
Disable decryption globally and create a custom URL category for the financial domains to enable decryption only for those.
Create two Decryption Policy rules: one with 'ssl-decrypt' action for the general category and a second rule with 'no-decrypt' action for the financial domains.
Ordering matters: the no-decrypt rule must sit above the ssl-decrypt rule, because PAN-OS evaluates decryption policy top-down and stops at the first match. This satisfies the stem's constraint that financial services domains retain end-to-end encryption while all other external HTTPS traffic is decrypted.
Upload the server certificates for the financial domains to the firewall and enable 'no-decrypt' on the Decryption Profile.
Configure a single Decryption Policy rule with a 'decrypt' action and add the financial domains to the 'Exclude Certificate' list.
A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?
Configure the SSL/TLS Service Profile to bypass decryption for the domain.
Configure a Decryption Profile to exclude the domain.
Create a Decryption Policy rule matching the traffic and set the action to 'No Decrypt'.
A Decryption Policy rule with the action set to 'No Decrypt' bypasses SSL Forward Proxy decryption for traffic matching *.bank.com, satisfying the compliance constraint that financial sites remain encrypted. The firewall still permits the session, forwarding the encrypted traffic untouched, so no certificate is presented to the client and no inspection occurs.
Enable certificate revocation checking for the decryption zone.
Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?
Decryption is applied globally to all traffic; selective decryption is not possible.
The firewall can decrypt all TLS sessions regardless of client certificate authentication.
When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.
SSL Forward Proxy requires the firewall to present a forged certificate to the client, signed by a trusted Forward Trust CA, so it can decrypt and inspect traffic before re-encrypting. This per-session certificate generation is intrinsic to the proxy mechanism, satisfying the design consideration that the firewall impersonates the destination server for every decrypted session.
Traffic using Server Name Indication (SNI) in TLS must be decrypted at the firewall or it will be dropped.
The firewall uses a decryption policy to determine which traffic to decrypt.
A decryption policy governs SSL Forward Proxy by matching traffic against defined rules, so only sessions meeting your criteria are intercepted and decrypted. This directly satisfies the design consideration of selective decryption, letting you exclude sensitive categories such as finance or healthcare, and so balance inspection coverage against privacy, performance and legal compliance.
Order the steps to configure a static route on a Palo Alto Networks firewall.
Navigate to the virtual router, add a static route, configure destination and next-hop, then commit.
This is the correct order because you must first select the virtual router, then create a new static route entry, define its parameters, and finally commit the changes.
Navigate to the virtual router, configure destination and next-hop, add the static route, then commit.
Navigate to the virtual router, add a static route, commit, then configure destination and next-hop.
Add a static route, navigate to the virtual router, configure destination and next-hop, then commit.
A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?
Configure decryption settings per interface to distribute load.
Disable SSL decryption entirely to avoid performance issues.
Create decryption exclusion rules for traffic that is known to be low-risk and high-volume.
Excluding low-risk, high-volume traffic from decryption directly reduces the CPU load on the firewall's dataplane, since each TLS session otherwise consumes processing for handshake and inspection. This satisfies the stem's constraint of minimising SSL decryption performance impact while preserving decryption for genuinely risky traffic.
Enable decryption on all traffic to ensure complete visibility.
What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?
Mask the original source IP address for privacy.
Inspect encrypted traffic for malware, exploits, and data leakage.
SSL decryption terminates encrypted sessions so App-ID, Content-ID threat prevention, URL filtering and file blocking can examine the plaintext payload. Without it, malware, exploits and data exfiltration hidden inside TLS remain invisible to the security policy.
Allow only inbound SSL traffic to be inspected.
Improve network performance by reducing encryption overhead.
Want more Decryption and SSL Inspection practice?
Practice this domain6% of exam · 6 sample questions below
After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?
The IdP does not support IdP-initiated SAML flow
The user mapping agent is not configured
The firewall and IdP system clocks are out of sync
Clock skew between the firewall and IdP invalidates the assertion's NotBefore/NotOnOrAfter conditions, so signature validation fails despite successful IdP authentication. The portal rejects the assertion as invalid because its timestamp falls outside the permitted window, satisfying the stem's 'invalid saml assertion' constraint. Synchronising both systems via NTP resolves the repeated credential prompts.
The SAML identity provider certificate is expired
An organization has deployed GlobalProtect with certificate authentication. Users on macOS report that after updating their client, they cannot connect and see error 'Certificate validation failed: The certificate hash does not match.' What is the most likely cause?
The certificate pinning configuration on the gateway has a hash mismatch
Certificate pinning enforces specific hash; client update may change the hash.
The root CA certificate is not trusted on the client
The CRL is not reachable
The GlobalProtect gateway certificate is expired
Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?
LDAP
Local Database
Kerberos
Kerberos uses ticket-granting tickets issued by a domain controller, so a user who has already authenticated to the domain presents a service ticket to the firewall transparently. This delivers SSO because the firewall trusts the KDC's tickets instead of prompting for credentials again.
RADIUS
SAML
SAML is a browser-based federation standard, so the firewall can redirect users to an external identity provider and accept signed assertions, granting SSO without re-prompting for credentials. This satisfies the SSO requirement by federating authentication rather than validating credentials directly against a local user database.
Which THREE factors should be considered when designing an authentication policy for a multi-zone environment with varied security requirements? (Choose THREE.)
Source zone
Source zone is a key condition in authentication policies.
User-ID
Schedule
Schedule can be used to apply different authentication rules based on time.
Application ID
Destination zone
Destination zone can be used to differentiate authentication requirements.
Arrange the steps to deploy a new Panorama template to a managed firewall.
Create template, then add configuration objects, then assign template to device group, then commit template
This is the correct order because you must first create the template, then populate it with configuration, assign it to the target devices, and finally commit the changes to apply them.
Add configuration objects, then create template, then assign template to device group, then commit template
Create template, then assign template to device group, then add configuration objects, then commit template
Create template, then add configuration objects, then commit template, then assign template to device group
Match each security profile type to its purpose.
Antivirus: Scans for malware and viruses in files.
Antivirus is correctly defined as scanning for malware and viruses.
Anti-Spyware: Protects against spyware and grayware.
Anti-Spyware correctly protects against spyware and grayware.
Vulnerability Protection: Prevents exploitation of known vulnerabilities.
Vulnerability Protection correctly prevents exploitation of vulnerabilities.
URL Filtering: Blocks files based on type and direction.
File Blocking: Categorizes URLs and controls access based on categories.
Want more Securing Users and Applications with Authentication practice?
Practice this domain11% of exam · 6 sample questions below
A network engineer is troubleshooting an HA pair where both firewalls show as 'active' in the HA state. What is this condition called?
Link failure
Active/Active
Passive/Passive
Split brain
Both peers believing they are active defines split brain, caused by loss of the HA heartbeat link while dataplane traffic still flows. Each firewall independently assumes the active role, producing duplicate sessions and conflicting state. The stem's symptom of two simultaneous 'active' states is precisely this condition.
During an HA failover, the new active firewall's session table is empty, causing all existing connections to be dropped. Which configuration change would prevent this?
Configure HA3 for stateful inspection.
Increase HA1 keepalive timer.
Enable config sync on HA1.
Enable session sync on HA2.
Session sync replicates the active firewall's session table to the passive peer over the HA2 link, so after failover existing flows are already known and continue without re-establishment. Without HA2 session synchronisation, the newly active device has no state and drops all established connections.
Based on the exhibit, what caused the last failover?
The HA2 link went down.
A preemption event occurred.
The peer firewall was rebooted.
The HA1 keepalive from the peer was lost.
The HA1 keepalive carries the heartbeat between peers; its loss makes the firewall conclude the peer is down, triggering failover. The exhibit shows HA1 link failure, so the peer's keepalive never arrived, which is the direct cause of the last failover.
Arrange the steps to enable and configure GlobalProtect on a Palo Alto Networks firewall.
First configure the GlobalProtect portal, then configure the GlobalProtect gateway, then configure the GlobalProtect agent (client configuration), and finally configure security policies.
This is the correct order because the portal must be set up first to define authentication and client settings, followed by the gateway to handle connections, then the agent configuration to push settings to clients, and finally security policies to allow traffic.
First configure the GlobalProtect gateway, then configure the GlobalProtect portal, then configure the GlobalProtect agent, and finally configure security policies.
First configure the GlobalProtect agent, then configure the GlobalProtect portal, then configure the GlobalProtect gateway, and finally configure security policies.
First configure security policies, then configure the GlobalProtect portal, then configure the GlobalProtect gateway, and finally configure the GlobalProtect agent.
An HA pair is configured with Active/Passive mode. The passive firewall fails to become active after the active firewall's management interface goes down. What is the most likely cause?
HA1 keepalive failure is not detected
Management interface failure is not a monitored condition by default
Management interface down does not trigger HA failover unless explicitly configured under device HA.
HA2 link monitoring is not enabled
Session synchronization is not complete
When configuring High Availability on a Palo Alto Networks firewall, which of the following is a best practice for the HA1 control link?
Use the management interface (MGT) for HA1
Configure HA1 as a subinterface on the HA2 link
Configure HA1 over a VLAN on a data interface to save ports
Use a dedicated physical interface for HA1, not shared with data traffic
HA1 carries heartbeat and synchronisation control traffic between peers. Sharing it with data traffic lets a saturated data path delay or drop heartbeats, causing false failover; a dedicated physical interface isolates control-plane traffic and satisfies the HA1 best-practise requirement.
Want more Managing Troubleshooting and High Availability practice?
Practice this domain15% of exam · 6 sample questions below
A security engineer needs to deploy a Palo Alto Networks firewall in a high-availability (HA) pair with active/passive mode. The firewall will inspect traffic for multiple tenants, each requiring separate routing and policy configuration. Which feature should be used to isolate tenant configurations while using a single pair of firewalls?
Create separate virtual systems (VSYS) for each tenant on the same firewall.
Separate VSYS instances partition a single firewall into independent logical firewalls, each with its own routing table, zones, policies and administrator roles. This satisfies the multi-tenant isolation requirement while retaining one active/passive HA pair, since VSYS share the underlying hardware and failover state.
Deploy multiple VM-Series firewalls as separate instances on the same hypervisor.
Use active/active HA mode to assign each tenant to a different firewall.
Configure multiple virtual routers (VRFs) within the same virtual system.
A firewall administrator notices that traffic from a specific subnet is being unexpectedly dropped. The firewall log shows a 'flow_drop' reason of 'packet too long for interface MTU'. The interface MTU is set to 1500, and the packets are 1500 bytes. What is the most likely cause?
The route lookup for the destination requires a larger MTU.
The firewall is not performing TCP MSS clamping on the traffic.
The firewall is using jumbo frames on the internal interface.
The packet is being encapsulated (e.g., IPsec) after routing, increasing its size beyond 1500 bytes.
IPsec encapsulation adds outer headers after the original packet is routed, pushing a 1500-byte frame past the interface MTU and triggering the drop. This matches the logged reason exactly, since the original packet size alone equals the MTU.
During a traffic spike, the firewall CPU utilization remains below 30% but the dataplane packet buffer usage is consistently above 90%. What is the most likely impact on firewall performance?
Reduced new session setup rate.
Reduced committed information rate (CIR) on QoS policies.
Increased latency for management access.
Increased packet drops due to buffer exhaustion.
Sustained dataplane buffer usage above 90% means the firewall cannot queue bursts fast enough, so new packets are discarded before processing. CPU headroom is irrelevant here: buffer exhaustion, not processing capacity, is the binding constraint, producing packet drops and retransmissions during the spike.
A network engineer is configuring App-ID for a custom application that uses a proprietary protocol over TCP port 12345. The application's traffic is not being identified as expected. Which configuration change should the engineer make to ensure the firewall correctly identifies this application?
Create a security policy rule with an application override to match the port.
Define a custom application with the appropriate protocol, port, and optionally a signature.
App-ID identifies applications by signature and protocol behaviour, not port alone. Since the proprietary protocol runs on a non-standard TCP port, a custom application object must be defined with the correct protocol, port and, where possible, a signature so the firewall can match and classify the traffic correctly.
Enable SSL decryption on the traffic to inspect encrypted payloads.
Add the port to the default application's 'port' field in the application object.
Which Panorama deployment mode allows centralized management of firewalls while storing logs locally on each firewall instead of sending them to the Panorama log collector?
Panorama with Dedicated Log Collectors
Panorama with Log Collectors
Panorama without Log Collectors
Panorama deployed without Log Collectors manages policies and device configuration centrally while each managed firewall retains its own logs in local storage. This satisfies the stem's requirement that logs stay on the firewall rather than being forwarded to Panorama.
Panorama in High Availability mode
A security engineer is troubleshooting a traffic drop issue on a Palo Alto Networks firewall. The traffic is allowed by the security policy, but the session is being terminated. Which two features could cause this behavior? (Choose two.)
DoS Protection
DoS Protection can actively terminate sessions exceeding thresholds.
User-ID
SSL Decryption
URL Filtering
Zone Protection Profile
Zone Protection can drop traffic based on flood protection or packet-based attacks.
Want more Core Concepts and Architecture practice?
Practice this domain10% of exam · 6 sample questions below
An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?
Users are manually selecting the wrong gateway from the client.
The gateways are not configured with priority settings.
The gateway selection rules on the portal do not match the users' source IP ranges.
Gateway selection rules on the portal map source IP ranges to preferred gateways, so mismatched ranges send Asian users to the wrong region. The portal agent config evaluates these rules before the client connects, making the source-IP match the deciding factor here.
The DNS resolution for the portal returns multiple IPs in round-robin.
Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?
The IKE gateway is not configured with the correct peer IP.
No security policy allows traffic from the VPN zone.
A tunnel can negotiate successfully at IKE and IPsec phases while user traffic is silently dropped if no security policy permits the VPN zone as source or destination, which is the classic cause of an up-but-passing-no-traffic state.
The proxy IDs do not match the remote peer.
The tunnel interface is not assigned to a zone.
Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.
Configure filter, Start capture, Generate traffic, Stop capture, Download
This is correct because you must first define what traffic to capture, then enable the capture, generate the traffic, stop the capture to save the data, and finally download the file.
Start capture, Configure filter, Generate traffic, Stop capture, Download
Configure filter, Generate traffic, Start capture, Stop capture, Download
Configure filter, Start capture, Generate traffic, Download, Stop capture
A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?
User not assigned a license
Incorrect gateway IP address in portal configuration
The portal hands the client the gateway address to connect to; if that configured address is wrong, authentication succeeds but the tunnel to the internal gateway fails. This matches the stem's symptom of portal success with gateway failure on the same firewall.
Gateway interface not in the same zone as portal
Gateway MTU mismatch
An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?
show counter global | match ipsec
show log system
debug ike global on
With no IPsec SAs present, the failure lies in Phase 1, so IKE negotiation must be examined. The 'debug ike global on' command enables global IKE daemon debugging, exposing payload exchanges, proposal mismatches and authentication failures that explain why the tunnel never reaches quick mode. This targets the negotiation stage the stem identifies as failing.
debug flow basic
When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?
The certificate is expired
The portal authentication profile requires both certificate and password
The portal authentication profile governs which credential factors the client must supply. If it is set to require both certificate and password, the client prompts for credentials even when a valid certificate is present. Removing the password requirement restores certificate-only authentication.
The client certificate does not match the username
The root CA certificate is not imported into the firewall
Want more Secure Access and VPN practice?
Practice this domain19% of exam · 6 sample questions below
An administrator wants to generate a report that shows the top applications by bandwidth usage over the last week. Which report type should be used to accomplish this?
URL Filtering Report
Application Report
The Application Report aggregates traffic by application, exposing bandwidth consumption per application over a chosen period. Selecting a one-week timeframe directly satisfies the requirement to rank top applications by bandwidth usage, which other report types do not provide.
Traffic Report
Threat Report
A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?
Network > Virtual Routers
Policy Optimizer > Test Policy Match
Policy Optimizer's Test Policy Match simulates a flow against the current ruleset, returning the exact security policy that would apply for specified source, destination, application and port. This directly satisfies the stem's requirement to identify which policy matches 10.0.1.0/24 traffic, exposing any missing or shadowed rule causing the outage.
Monitor > Logs > Traffic
Device > Setup > Management
A company has a firewall with multiple virtual systems (vsys). The administrator wants to delegate management of one vsys to a junior administrator, allowing them to configure security policies but not access system settings or other vsys. Which administrative role should be assigned?
Virtual System Admin
A Virtual System Admin role scopes permissions to a single vsys, granting full policy configuration within it while denying access to system settings and other vsys. This satisfies the delegation constraint of policy-only rights without broader device administration.
Superuser
Device Admin
Role-Based Admin
An administrator is troubleshooting high CPU usage on a PA-5250 firewall. The CPU usage spikes every 5 minutes. Which CLI command should be used to identify the process causing the spike?
show session all
show dataplane
show running resource-monitor
The resource-monitor command samples per-process CPU and memory usage at intervals, so it captures the five-minute spike and names the offending process. Plain 'show system resources' gives only a point-in-time snapshot, which would likely miss the periodic spike.
show system resources
An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?
Add an external disk to the firewall
Configure log export and auto-deletion in Log Settings
Log Settings controls log storage behaviour, including export to external servers and automatic deletion of older logs once thresholds are reached. Enabling auto-deletion directly reduces disk consumption, satisfying the requirement to reclaim space without manual intervention.
Disable logging for non-critical traffic
Manually delete logs from the CLI
A security team needs to capture traffic for forensic analysis of a specific application that uses non-standard ports. The administrator wants to capture packets on the firewall for that application only, without affecting performance. Which method should be used?
Set up a port mirror on the upstream switch
Create an application override policy
Configure a PCAP filter in the firewall's packet capture feature
A PCAP filter narrows capture to traffic matching the application's specific ports and addresses, so only relevant packets are recorded. This satisfies the requirement to target the non-standard-port application without the performance overhead of capturing all traffic.
Use tcpdump on the management interface
Want more Manage, Monitor and Operate practice?
Practice this domainA company is experiencing intermittent connectivity issues between two branch offices connected via an IPSec tunnel. Users report that they can access resources for a few minutes, then lose connectivity, and after a short time it comes back. Which troubleshooting step should be taken first?
Check the traffic logs for any denial events
Check the IPSec tunnel status and IKE/IPSEC SA rekey timers
Intermittent drops that recover after minutes typically indicate IKE or IPSec security association rekeying failures or mismatched lifetimes. Checking tunnel status and rekey timers first confirms whether SAs expire and fail to renegotiate, directly addressing the recurring loss of connectivity described.
Reboot the firewall to clear any stale sessions
Verify the routing table on both firewalls
A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?
Check the security policy rulebase order and matching
Security policies are evaluated top-down, so a deny rule above the permit rule for 10.1.1.0/24 would block this user despite the allow existing. Verifying rulebase order and matching confirms which rule actually handles the session, satisfying the need to identify why permitted subnet traffic is dropped.
Verify the user-ID agent is mapping the IP correctly
Check the service configuration for the destination port
Check the NAT configuration for the user's subnet
A user reports that they cannot access a specific website. The firewall security policy allows web traffic. The administrator checks the traffic log and sees that the session is being denied due to a 'URL Filtering' block. What should the administrator do to allow access?
Disable URL filtering on the existing security rule
Check the user-ID mapping to ensure the user is authenticated
Create a new security rule allowing the user's IP to any
Add the URL to an allow list in the URL filtering profile
The traffic log shows the session denied by URL Filtering rather than the security policy, so the URL category is blocked in the URL filtering profile. Adding the specific URL to the allow list in that profile permits access while the security policy remains unchanged.
An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?
The firewall's App-ID identified the traffic as a different application than the one specified in the rule
App-ID inspects the session and identifies the actual application, which may differ from the one the rule specifies. An 'application mismatch' denial means the detected application does not match the rule's application, so the session is dropped. This satisfies the stem's constraint that the policy allows the expected application.
The application is not recognized by the firewall and is treated as unknown
The security rule is not configured to allow any application
The firewall's SSL decryption is misconfigured
Which THREE components should be verified when troubleshooting a site-to-site IPSec VPN that is not coming up?
Zone protection profile on the untrust zone
Interface management profile on the external interface
Pre-shared key configuration on both ends
A mismatched pre-shared key causes IKE phase 1 authentication to fail, so the tunnel never negotiates. Verifying identical keys on both peers satisfies the stem's requirement to check components preventing the IPSec VPN from coming up, since the pre-shared key must match exactly on each end.
Peer IP address in the tunnel interface configuration
A mismatched peer IP address prevents IKE Phase 1 negotiation, so the tunnel never establishes. Verifying the configured peer address matches the remote gateway satisfies the stem's requirement to check tunnel interface settings, since incorrect values here cause silent negotiation failures before any Phase 2 traffic selectors are evaluated.
IKE version (v1 vs v2) compatibility
Mismatched IKE versions prevent Phase 1 negotiation entirely, so the tunnel never establishes. Verify both peers run IKEv1 or IKEv2, since the initiator's proposal must match the responder's configured version before any security association forms. This directly satisfies the stem's requirement to check IKE version compatibility.
Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?
show system info
show vpn ike-sa
The show vpn ike-sa command displays Phase-1 IKE security associations, including peer addresses, state, and remaining lifetime. Inspecting it confirms whether the IKE tunnel itself is established, which is the required status check for an IPSec tunnel.
show routing route
show vpn ipsec-sa
`show vpn ipsec-sa` lists active IPSec security associations, displaying tunnel names, peer addresses, and SPI values, which directly confirms whether a tunnel is established. It satisfies the stem's requirement to check IPSec tunnel status on a Palo Alto Networks firewall, complementing `show vpn ike-sa` for phase-1 verification.
show interface all
Want more Troubleshoot practice?
Practice this domainThe PCNSE exam has 75 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 9 domains: Deploy and Configure Firewalls, Securing Traffic and App-ID, Decryption and SSL Inspection, Securing Users and Applications with Authentication, Managing Troubleshooting and High Availability, Core Concepts and Architecture, Secure Access and VPN, Manage, Monitor and Operate, Troubleshoot. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks PCNSE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.