PCNSA Device Management and Services Practice Question
Exhibit
Refer to the exhibit.
admin@PA-500> show system state | match "ntp|time"
ntp-config:
ntp-servers {
primary-ntp-server {
address: pool.ntp.org;
}
secondary-ntp-server {
address: time.google.com;
}
}
ntp-admin-state: enabled;
ntp-sync-state: sync;
time-config:
timezone: America/New_York;
current-time: 2025-03-15 14:30:22;After a firewall upgrade, the system clock shows a time that is five minutes behind the actual time, even though NTP is synchronized. What is the most likely cause?
⚠ Common exam trap
Many candidates assume NTP synchronization guarantees correct local time, but they overlook that the timezone offset must be independently configured; Palo Alto Networks tests this by presenting a scenario where NTP is synchronized yet the displayed time is wrong, leading to confusion between NTP server issues and timezone configuration errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The timezone offset is incorrectly set.
When NTP is synchronized but the system clock is offset by a fixed amount (e.g., five minutes), the most likely cause is an incorrect timezone offset. NTP synchronizes the UTC time, and the firewall then applies the configured timezone offset to display the local time. If the offset is wrong, the displayed time will be consistently off by that offset value, even though NTP shows synchronization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall is using a stratum 2 server that is inaccurate.
Why it's wrong here
A stratum 2 server is a normal, accurate reference; stratum only expresses distance from the reference clock, not accuracy, so a five-minute offset is not explained by stratum level. Stratum becomes relevant when validating hierarchy depth or detecting an unintended server.
- ✓
The timezone offset is incorrectly set.
Why this is correct
A wrong timezone would cause the displayed local time to differ from UTC, even if NTP is synced.
- ✗
NTP authentication is not configured.
Why it's wrong here
Missing NTP authentication causes the server to be rejected outright, leaving the clock unsynchronised and drifting, not offset by a fixed five minutes. Authentication is the right control when spoofed or rogue NTP sources must be excluded from synchronisation.
- ✗
The NTP admin state is enabled but the service route is misconfigured.
Why it's wrong here
A misconfigured service route prevents NTP packets reaching the server, so the clock would drift arbitrarily rather than sit a consistent five minutes behind. Service routes are the correct fix when NTP traffic must egress a specific interface or virtual router.
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.