Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
You have a Security Policy rule allowing 'web-browsing' and 'ssl'. A user cannot access a specific site, and the logs show the traffic as 'web-browsing' but failing a specific Security Profile. Which action is most appropriate?
Disable App-ID for this rule.
Increase the timeout settings on the zone.
Check the logs for the specific Security Profile trigger.
The logs will indicate which profile (e.g., URL Filtering) is blocking the request.
Change the application to 'any'.
You are troubleshooting a performance issue in Prisma Access. Users report slow access to SaaS applications. You suspect the issue is related to the path selection. Which tool should you use to analyze the latency between the user's mobile client and the Service Connection?
Traffic Logs in Panorama
GlobalProtect App logs
Prisma Access Insights
Prisma Access Insights is designed specifically for monitoring performance and latency.
ACC (Application Command Center)
When using User-ID with Active Directory, what is the primary purpose of the User-ID Agent?
To cache user credentials for SSO.
To encrypt traffic for GlobalProtect.
To query domain controllers for IP-to-User mapping.
This is the core function of the agent for mapping users.
To push security policies to clients.
Which Content-ID component specifically prevents the exfiltration of sensitive data like credit card numbers?
Vulnerability Protection
URL Filtering
Data Filtering
Data Filtering is used to detect and block sensitive data patterns.
Antivirus
A administrator needs to ensure that users are authenticated before accessing a web-based internal application. Which User-ID method provides the most granular control by prompting users via a captive portal?
Captive Portal
Captive Portal is specifically designed to challenge users for credentials.
IP-to-User Mapping via XML API
Clientless VPN
GlobalProtect Transparent Authentication
You are migrating an existing branch office to Prisma Access. Which component is required to allow the branch to communicate with your on-premises data center?
Mobile User Connection
Service Connection
Service Connections provide the path to private data centers.
Prisma Access Insights
Remote Network Connection
Want more NGFW And SASE Solution Functionality practice?
Practice this domainYou are troubleshooting a connection that is being blocked despite a matching policy. Which tool is best for determining which specific rule is hitting the traffic?
Packet Capture (pcap)
GlobalProtect logs
Policy Test Tool (test security-policy-match)
This command simulates traffic and returns the matching rule.
Traffic Monitor
Which component of the Palo Alto Networks architecture is responsible for the 'Single Pass' processing engine?
Panorama
Data Plane
The data plane performs packet processing via the Single Pass architecture.
Management Plane
Control Plane
An administrator wants to ensure that only 'web-browsing' traffic is allowed on port 80. Which feature allows this enforcement?
App-ID
App-ID identifies the traffic signature regardless of port.
Zone Protection Profiles
Service Objects
Log Forwarding
Which object type in PAN-OS should be used to group multiple IP addresses for use in a security policy?
Application Group
Tag
Address Group
Address groups are the correct container for multiple IP objects.
Service Group
You have a policy matching 'web-browsing' but traffic is being denied. What is the most likely cause?
The dependent application, such as 'ssl', is not allowed in the policy.
App-ID dependencies must be explicitly allowed.
The source zone is incorrect.
The firewall is in transparent mode.
The security profile is missing.
When deploying a firewall in a Zero Trust environment, what is the recommended stance for the default interzone policy?
Deny all traffic by default.
Zero Trust requires implicit deny as the default.
Allow all internal traffic, deny external.
Allow traffic based on source IP only.
Allow all traffic to simplify configuration.
Want more Network Security Fundamentals practice?
Practice this domainWhich command is used on a Palo Alto Networks firewall to verify current license entitlements from the CLI?
show system license
check license-status
request license info
This command provides a detailed list of active and expired license entitlements.
debug license fetch
You are troubleshooting a connectivity issue between an SCM-managed firewall and the SCM cloud service. Which log source in the firewall UI provides the most detailed information regarding the management connection?
Configuration logs
Threat logs
Traffic logs
System logs
System logs contain events related to the management service and connectivity to SCM.
An administrator needs to enforce a consistent security policy across 50 branch firewalls using SCM. They want to ensure that any changes made at the local firewall level are overridden by SCM. Which setting must be configured?
Enable 'Local Policy Precedence' on all firewalls.
Set the 'Device Override' to 'Disabled' in the SCM container settings.
Disabling device overrides ensures that local changes cannot deviate from the pushed SCM policy.
Disable 'Management Plane Access' for local admins.
Configure 'Auto-Commit' on every firewall.
When using Panorama, an administrator wants to push policies to specific firewalls based on their geographical location. Which feature should be used?
Device Groups
Device Groups are the primary mechanism for grouping firewalls for shared configuration.
Panorama Templates
Address Groups
Policy Groups
Which protocol does Panorama use to communicate with managed firewalls for configuration synchronization?
SSH
HTTP
SSL/TLS
Panorama uses a secure SSL/TLS connection to manage firewalls.
SNMPv3
You are migrating existing on-premises Panorama appliances to Strata Cloud Manager (SCM). After establishing connectivity, you notice that your device groups are not appearing in the SCM interface. Which action is required to resolve this?
Manually export and import XML configurations for every device group.
Enable Panorama mode on SCM.
Re-register all managed firewalls directly to SCM via serial number.
Run the SCM migration utility to map Panorama device groups to SCM containers.
The migration tool is necessary to transition the hierarchy to SCM's container-based architecture.
Want more Platform Solutions Services And Tools practice?
Practice this domainAn administrator notices intermittent packet loss in a GlobalProtect deployment where users connect via IPv6. Which configuration change is likely to resolve the issue if MTU fragmentation is suspected?
Decrease the MTU size on the tunnel interface.
Reducing MTU accounts for VPN overhead, preventing fragmentation.
Increase the GlobalProtect timeout value.
Disable hardware offloading for IPv6.
Enable IPv6 transition mechanisms on the external interface.
An administrator wants to use DHCP to assign IP addresses to GlobalProtect clients. Where is this setting configured?
Objects > Addresses
Network > GlobalProtect > Gateways > Client Settings
This is the correct navigation path to define client IP assignment.
Network > DHCP > Server
Device > Setup > Management
Which CLI command is most effective for verifying if a specific packet is being blocked by a security policy in real-time?
debug dataplane packet-diag
test security-policy-match source <ip> destination <ip> protocol <proto>
This command correctly simulates traffic flow against the policy database.
show running security-policy
show session all filter source <ip>
When troubleshooting a BGP peering issue between a Palo Alto Networks firewall and an ISP, which log should be reviewed to see state changes and neighbor messages?
Traffic logs
System logs
BGP status changes are logged under the System category.
Threat logs
Config logs
When using OSPF with a Palo Alto Networks firewall, which area type would you configure to ensure the firewall does not receive external routing information while still maintaining connectivity to the backbone?
Totally Stubby Area
Totally Stubby areas minimize the routing table size by injecting only a default route.
NSSA
Backbone Area (Area 0)
Standard Area
An administrator is configuring a Site-to-Site VPN and needs to ensure that the tunnel interface is included in the routing table. What must be done to ensure traffic can be routed across the tunnel?
Configure the tunnel interface in a separate security zone.
Change the tunnel interface type to Layer 3.
Enable Proxy-ID settings on the tunnel interface.
Add a static route in the Virtual Router pointing to the remote subnet using the tunnel interface as the next hop.
A route is required to direct traffic towards the tunnel interface.
Want more Connectivity And Security practice?
Practice this domainYou are troubleshooting an application that is being blocked despite having an Allow security policy. You observe in the Traffic Log that the App-ID is identified as 'incomplete'. What is the most likely cause?
The Security Policy is missing a Decryption Profile.
The App-ID database is outdated.
The client sent a SYN packet but the server did not respond.
Incomplete sessions are often caused by the firewall seeing the start of a flow but no further packets to finalize the handshake.
The application is using a custom port not defined in the Service object.
Which feature allows an administrator to prevent unauthorized users from using a stolen credential by requiring a second form of authentication?
Authentication Portal
MFA Profile
The MFA Profile is the configuration object that links the firewall to an external MFA provider.
Credential Protection Profile
GlobalProtect Authentication Override
A company requires that traffic from the VPN zone to the Untrust zone undergoes source NAT using a specific interface IP. Which configuration step is mandatory to ensure this traffic is correctly matched?
Disable 'Address Translation' in the NAT rule.
Enable 'Proxy ARP' on the egress interface.
Select the specific source zone and destination zone in the NAT rule.
NAT rules are zone-based; you must specify the source and destination zones for the rule to trigger.
Configure a policy-based forwarding rule instead of NAT.
An administrator needs to ensure that internal users can reach the internet while hiding their private IP addresses. Which NAT type should be configured on the egress interface?
Static NAT
Double NAT
Destination NAT
Source NAT
Source NAT allows hiding internal IP addresses behind a public IP address.
You have configured a custom application object for a proprietary internal tool. When you attempt to use this object in a Security Policy, traffic is still being denied. What is a common configuration error?
The application signature does not match the traffic's port or pattern.
If the traffic pattern doesn't match the signature criteria, the firewall will not identify it as the custom app.
The application must be assigned to the 'web' category.
The App-ID must be added to a service group.
The application requires an SSL decryption policy first.
You want to perform a configuration backup and store it on an external server using SCP. Which menu path contains the configuration for scheduled exports?
Network > GlobalProtect
Objects > External Dynamic Lists
Device > Software
Device > Setup > Operations
This is the correct location for managing configuration backups and exports.
Want more NGFW And SASE Solution Maintenance And Configuration practice?
Practice this domainWhat is the primary function of the 'DNS Sinkhole' feature in a DNS Security profile?
To encrypt DNS traffic between the firewall and the ISP.
To allow a firewall to act as a DNS server for internal clients.
To cache DNS queries to improve network performance.
To redirect requests for malicious domains to a specific IP address to alert the administrator.
Sinkholing is used to identify and log clients attempting to resolve malicious domains.
You are configuring Advanced URL Filtering. Users report that a site is being blocked, but the category is 'Newly Registered Domains'. How can you allow access to this specific site while keeping the policy for other newly registered domains?
Add the site to the 'Allow List' in the URL Filtering profile object assigned to the security policy.
The Allow List within a URL Filtering profile overrides category-based blocks.
Move the security policy to the top of the policy list.
Add the site to the 'Blocked' list in the URL Filtering profile.
Create a new URL category and add the domain to it, then block that category.
A company is experiencing high false-positive rates with WildFire for custom proprietary executable files. What is the recommended configuration to minimize these while maintaining security?
Lower the threat prevention action from block to alert for all executables.
Disable WildFire on the specific security policy rule.
Create a WildFire analysis profile and add the proprietary file hashes to the WildFire File Exclusion list.
File exclusions allow known-good proprietary files to bypass analysis.
Change the WildFire forwarding location to a local WildFire appliance.
An administrator needs to enable Threat Prevention to protect against a specific zero-day exploit. How are the signatures for these new threats delivered to the firewall?
By manually downloading the threat signature database from the Customer Support Portal.
Through the scheduled 'Threats' dynamic update package.
The 'Threats' dynamic update contains the latest vulnerability and exploit signatures.
Through the daily WildFire update package.
By enabling the 'Automatic Update' feature in the Device > Software menu.
Which action is required to ensure that WildFire analysis results are applied to traffic as quickly as possible?
Configure the WildFire profile to use the 'Real-time' analysis mode.
Real-time mode minimizes latency in file analysis and protection.
Enable 'Packet Capture' for all security policies.
Increase the WildFire cloud region to the nearest geographic site.
Set the WildFire forwarding to 'Legacy' mode.
You are deploying Advanced URL Filtering. How does the 'Credential Phishing' prevention feature operate?
It analyzes the URL to determine if it is a known malicious site.
It detects and blocks the submission of enterprise credentials to untrusted or newly registered websites.
This describes the core mechanism of Credential Phishing prevention.
It requires an agent installed on the endpoint to monitor browser activity.
It monitors all inbound traffic for known phishing signatures.
Want more Infrastructure Management And CDSS practice?
Practice this domainThe NetSec-Pro exam has 200 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: NGFW And SASE Solution Functionality, Network Security Fundamentals, Platform Solutions Services And Tools, Connectivity And Security, NGFW And SASE Solution Maintenance And Configuration, Infrastructure Management And CDSS. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks NetSec-Pro exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.