Practice NGFW-Engineer PAN OS Device Setting Configuration questions with full explanations on every answer.
Start practicing
PAN OS Device Setting Configuration — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to ensure that the firewall uses a specific internal server for DNS resolution of external traffic. Where must this be configured?
2You are deploying an HA pair. You need to ensure that the session state is synchronized immediately to prevent drops during a failover. Which setting ensures this?
3You are configuring a new Palo Alto Networks firewall and need to ensure that the management interface is only accessible from a specific subnet. Which configuration component is used to achieve this?
4You are configuring a new Security Policy. Which TWO settings are required to enable App-ID enforcement for a rule?
5You are configuring a new NGFW and need to ensure administrative access is restricted to a specific management subnet. Which interface setting should you modify to enforce this?
6You want to implement User-ID without installing agents on every server. What is the most efficient method to map IP addresses to usernames?
7Where do you configure the DNS servers that the firewall itself uses to resolve hostnames for updates?
8You have configured a GlobalProtect VPN, but users cannot access internal resources. What is the first troubleshooting step?
9Which object type should be used to group multiple IP addresses to simplify security policy management?
10How do you ensure that the firewall automatically blocks traffic from a list of known malicious IP addresses?
11An administrator needs to identify the cause of intermittent connectivity drops for a specific application. What feature provides the most granular visibility?
12When configuring NAT, which option allows the firewall to preserve the original source IP of the traffic?
13Which feature must be enabled to inspect traffic for threats?
14Which tab in the web interface is used to create and manage security policies?
15If you have a primary and secondary firewall, what is the best way to synchronize configuration changes?
16An administrator wants to ensure that internal users only access approved websites. Which profile is used?
17An administrator wants to use a specific user's group membership for policy enforcement. What is the requirement?
18Which action in a security policy should be used to drop traffic silently without sending a notification to the client?
19Which configuration object allows you to restrict traffic based on geographic location?
20How do you verify if a security policy is actually matching the traffic you expect?
21You notice that the firewall is not identifying traffic as 'web-browsing' even though it is on port 80. What is the most likely cause?
22Which tab is used to configure logging settings for a specific security policy?
23What is the primary function of a Security Profile Group?
24Which feature is used to ensure the firewall clock is accurate?
25What happens if a packet matches no security policies?
26You are experiencing issues with traffic passing through the firewall. What command is used to see the session table in the CLI?
27What is the purpose of the 'Pre-Rulebase' and 'Post-Rulebase' in Panorama?
28When troubleshooting routing, which command allows you to test the path of a packet?
29Which tab allows you to configure the firewall's hostname and domain?
30Which object should be configured for a server that needs to be accessed from the internet via a public IP?
31What is the recommended way to manage certificates on a Palo Alto Networks firewall?
32Which type of interface is used for connecting to a Layer 3 network?
33How do you back up the firewall's configuration?
34What is the purpose of a 'Zone' in a Palo Alto Networks firewall?
35You need to perform a packet capture on a specific firewall interface. Which tool is used?
36What is the consequence of having overlapping IP subnets on different interfaces?
37Which tab is used to view real-time log activity?
38What is the recommended method to update the firewall's threat signatures?
39How do you ensure that only the most secure TLS versions are used for management access?
40What must you do after making any change in the web interface to make it active?
41Which feature helps to identify and block traffic from compromised hosts based on suspicious behavior?
42What is the purpose of the 'Policy Optimizer' feature?
43Where do you view the system logs to troubleshoot hardware issues?
44How do you ensure that a specific security policy rule is only active during business hours?
45What is the best way to monitor the firewall's CPU and memory usage?
46When configuring an interface, what is the role of a 'Security Zone'?
47What is the default action for the 'interzone-default' security policy?
48Which object type should you use to handle large lists of URLs that you want to block or allow?
49Which TWO settings are required to configure an Interface Management Profile?
50Which TWO objects can be used as a source in a Security Policy?
51Which TWO items are required to configure a site-to-site IPsec VPN?
52Which THREE components are necessary to successfully implement SSL Forward Proxy?
53Which TWO of the following are valid methods to authenticate administrators to the firewall?
54Which TWO types of logs can be forwarded to an external server?
55Which TWO features require a valid subscription license?
56Which THREE options are available under the 'Actions' tab of a Security Policy?
57Which TWO objects can be used to identify traffic in an Application Override policy?
58Which TWO types of NAT are supported in PAN-OS?
59Which THREE items are found under the 'Network' tab?
60Which THREE settings can be modified in a custom Antivirus Profile?
61Which TWO items can be configured in a Virtual Router?
62Which THREE steps are involved in the standard User-ID agentless configuration?
63Which THREE items are part of the 'Device > Setup' configuration?
64Which TWO authentication protocols are commonly supported by PAN-OS for VPN user authentication?
65Which THREE features are associated with Threat Prevention?
66You are configuring a Palo Alto Networks firewall to support User-ID. You have successfully installed the User-ID agent on a Windows Server and connected it to the firewall. However, the firewall is not mapping IP addresses to usernames. What is the most likely cause?
67A network administrator needs to ensure that internal users can access a public-facing web server located in the DMZ using its public IP address (Hairpin NAT). The policy exists, but traffic is being dropped. Which configuration step is critical to enable this?
68A firewall is experiencing high CPU usage during traffic spikes. You suspect that App-ID is performing too much scanning on internal traffic. Which action should you take to optimize performance while maintaining security?
69You are managing a firewall and need to ensure that dynamic updates are downloaded automatically. Where do you configure the schedule for these updates?
70You have configured an IPsec VPN tunnel between two sites, but the tunnel status shows 'init-passive' and never transitions to 'up'. What is the most likely configuration error?
71You are configuring a Security Profile to detect and prevent malware. Which profile is most appropriate for identifying malicious files being downloaded?
72Which TWO of the following are valid methods for an administrator to authenticate to the Palo Alto Networks firewall management plane?
73Which TWO of the following settings are required when configuring a Service Route to ensure the firewall uses a specific interface for external traffic?
The PAN OS Device Setting Configuration domain covers the key concepts tested in this area of the NGFW-Engineer exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all NGFW-Engineer domains — no account required.
The Courseiva NGFW-Engineer question bank contains 73 questions in the PAN OS Device Setting Configuration domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the PAN OS Device Setting Configuration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included