Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
You are configuring an Auto-Scaling Group in AWS with the VM-Series. During the bootstrap process, which file is mandatory to ensure the firewall registers with Panorama successfully?
license.txt
init-cfg.txt
This file defines the basic registration parameters for Panorama.
bootstrap.xml
config.cfg
An administrator is using Terraform to manage Palo Alto Networks security policies. Which provider resource is used to create a security rule?
panos_firewall_rule
panos_policy_rule
panos_security_policy
panos_security_rule
This is the correct Terraform resource for defining security rules.
You are troubleshooting a REST API integration where Python scripts are failing to retrieve device information. The API returns a '403 Forbidden' error. What is the most likely cause?
The API Key is expired.
The JSON body is malformed.
The admin account lacks permissions for the requested object.
403 Forbidden implies authentication was successful, but authorization failed.
The API endpoint URL is incorrect.
Which feature allows an NGFW to dynamically update security objects based on an external feed such as an IP list or URL list?
User-ID Mapping
Log Forwarding Profiles
External Dynamic Lists
EDLs are designed specifically for this purpose.
Dynamic Address Objects
To ensure high availability for an automated script, which Panorama component should the script target?
Log Collector
Active/Passive Peer
Individual Firewall Management Plane
Panorama Management Server
Panorama provides a centralized API for all managed devices.
An administrator needs to automate the deployment of security policy updates using Panorama. Which XML API method should be invoked to commit changes to the candidate configuration?
/api/?type=commit
This is the correct path for triggering a configuration commit via the XML API.
/api/?type=config&action=save
/api/?type=export
/api/?type=op&cmd=<commit/>
Want more Integration And Automation practice?
Practice this domainAn administrator needs to ensure that the firewall uses a specific internal server for DNS resolution of external traffic. Where must this be configured?
Network > Interfaces
Network > Virtual Routers
Device > Setup > Service Route Configuration
Service routes allow you to override default routing for specific services like DNS.
Device > Setup > Services
You are deploying an HA pair. You need to ensure that the session state is synchronized immediately to prevent drops during a failover. Which setting ensures this?
Device > High Availability > Election Settings
Device > High Availability > HA1/HA2 configuration
The HA2 link carries the session state synchronization data.
Device > High Availability > Link and Path Monitoring
Device > High Availability > General
You are configuring a new Palo Alto Networks firewall and need to ensure that the management interface is only accessible from a specific subnet. Which configuration component is used to achieve this?
Access Control List (ACL)
Interface Management Profile
An Interface Management Profile allows you to define specific services (HTTPS, SSH, Ping) and permitted IP addresses for management access.
Security Policy
Service Routes
You are configuring a new Security Policy. Which TWO settings are required to enable App-ID enforcement for a rule?
Profile Group
Application
You must select specific applications or 'any'.
Service
Service defines the port/protocol, which App-ID validates against the traffic.
Zone
Action
You are configuring a new NGFW and need to ensure administrative access is restricted to a specific management subnet. Which interface setting should you modify to enforce this?
Management Interface Settings
The Management Interface Settings allow an administrator to specify allowed IP addresses for the management port.
Service Route Configuration
Device > Setup > Session
Network Profile - Interface Management
You want to implement User-ID without installing agents on every server. What is the most efficient method to map IP addresses to usernames?
Use IP-to-User static mapping
Enable GlobalProtect for internal users
Configure Agentless User-ID via Server Monitoring
Agentless User-ID allows the firewall to poll domain controllers directly using WMI or WinRM.
Use the User-ID Agent on a Windows Server
Want more PAN OS Device Setting Configuration practice?
Practice this domainWhich TWO actions must be performed to successfully configure a zone protection profile on a zone?
Create a security policy rule.
Apply the profile to the zone under Network > Zones.
The profile is applied in the zone configuration menu.
Assign the zone to a virtual router.
Create a Zone Protection Profile under Network > Network Profiles > Zone Protection.
The profile must be defined first.
Enable the 'Strict' mode on the interface.
You are configuring a virtual wire interface. Which setting is required to ensure that traffic is passed between the two interfaces?
Configure an IP address on both interfaces
Assign a security zone to each interface
Virtual wire interfaces require zone assignment to participate in security policies.
Create a loopback interface
Enable dynamic routing on the virtual wire
A administrator needs to allow traffic between two zones using a specific sub-interface. Which configuration step is mandatory?
Add the sub-interface to the default zone
Assign the sub-interface to a security zone
Zone assignment is mandatory for all interface types.
Configure the sub-interface as a loopback
Enable DHCP server on the sub-interface
Where do you configure the tunnel interface IP address in a Site-to-Site VPN setup?
Network > Zones
Network > GlobalProtect > Gateways
Network > Virtual Routers
Network > Interfaces > Tunnel
This is the correct path for assigning tunnel IPs.
When configuring OSPF on a PAN-OS firewall, what is the impact of setting the dead interval to a value different from the neighbor?
The adjacency will not form
OSPF state machine requires matching timers for adjacency.
The firewall will use the lowest timer value
Only LSA type 1 updates are exchanged
The adjacency forms but drops packets
In an HA active/passive configuration, which mechanism ensures the passive firewall is ready to take over traffic?
BGP peer failover
Heartbeat link synchronization
Heartbeat links monitor health and sync session tables.
ARP cache clearing
GlobalProtect gateway synchronization
Want more PAN OS Networking Configuration practice?
Practice this domainThe NGFW-Engineer exam has 200 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: Integration And Automation, PAN OS Device Setting Configuration, PAN OS Networking Configuration. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks NGFW-Engineer exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.