PCNSA · domain
scenario questions
Practise Palo Alto Networks Certified Network Security Administrator PCNSA scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (385)
Click any question to see the full explanation, or start a practice session above.
A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?
Easy2An administrator is creating a Dynamic Address Group (DAG) that should include all servers tagged with 'web' and 'prod'. The firewall is configured to use a VMware NSX-T service manager for tag registration. Which configuration is required to ensure the DAG is populated correctly?
Hard3Match each firewall deployment mode to its description.
Medium4An administrator needs to create a service object for a custom application that uses TCP port 8080 and UDP port 8080. What is the most efficient way to create this service object?
Easy5A company uses dynamic address groups based on tags. A virtual machine receives the tag "WebServer". After the VM is decommissioned, the tag is removed. What happens to the dynamic address group?
Hard6A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?
Hard7An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?
Hard8A company is deploying multiple Palo Alto firewalls and wants to manage them centrally. Which method should be used?
Hard9An administrator needs to allow DNS traffic from the Trust zone to the Untrust zone. The security policy rule uses the application 'dns' and service 'application-default'. Which port will be allowed by default?
Easy10A company has a PA-5250 firewall with 10 Gbps threat prevention throughput. They are planning to enable SSL decryption for all traffic. What is the most likely impact on the firewall's throughput?
Easy11A large university uses a Palo Alto Networks firewall to secure its network. The security team has implemented a policy to block peer-to-peer (P2P) file sharing applications. They have configured a security rule that denies all applications in the 'peer-to-peer' category. However, they notice that some students are still able to download files using BitTorrent. The traffic logs show the application as 'bittorrent' but the rule does not match. Upon investigation, the rule is applied to the correct zones and includes the peer-to-peer category. The source and destination are any. What is the most likely cause of this issue?
Hard12An administrator needs to generate a report showing all applications used by a specific user group over the past week. Which method is most efficient?
Medium13A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?
Medium14Users report that some internal services are not accessible when connected via VPN, but they work when on the local network. The firewall has a policy allowing all traffic from the VPN zone to the internal zone. What should the administrator check first?
Medium15A security administrator notices that a Security policy rule permitting the application 'ssl' also allows users to access unauthorized SaaS applications that tunnel their traffic inside TLS on TCP 443. The administrator wants to block these applications without disrupting legitimate TLS traffic. Which Palo Alto Networks feature should be used to identify and control these applications?
Medium16An administrator needs to allow administrators to authenticate to the firewall's web interface using an external LDAP directory at ldap.corp.example.com, while still allowing a local break-glass account. The directory uses a bind DN of cn=svc-bind,ou=service,dc=corp,dc=example,dc=com. After configuring the LDAP server profile under Device > Server Profiles > LDAP, authentication still fails for directory users. Which additional step is required?
Medium17A security administrator wants to block all traffic using the BitTorrent protocol regardless of port. Which method should they use?
Easy18A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?
Medium19A company is deploying a PA-220 firewall in a branch office. The firewall will be managed by Panorama. Which THREE of the following are required to establish a successful connection between the firewall and Panorama?
Hard20An administrator is creating address objects in PAN-OS and needs to ensure that they can be used in security policies to identify specific sources and destinations. Which two of the following are valid address object types that can be directly referenced in a security policy rule? (Choose two.)
Medium21An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The firewall has two virtual routers: VR1 for the internal network and VR2 for the internet. The syslog server is reachable only through VR1. Which configuration setting must be applied to ensure syslog messages are sent via VR1?
Medium22A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?
Hard23An organization is using outbound SSL decryption with a forward proxy. They notice that mobile devices (iOS/Android) are having trouble connecting to many HTTPS sites after decryption is enabled. IT has installed the root CA certificate on all devices. What is the most likely reason?
Hard24A firewall administrator needs to ensure that the firewall can resolve domain names for security policy rules that use FQDN objects. The firewall is deployed in a network where DNS servers are reachable only through the dataplane interface ethernet1/2, which is in the untrust zone. The management interface cannot reach any DNS server. Which configuration should the administrator use to allow the firewall to resolve FQDNs?
Hard25An administrator is troubleshooting why a security rule that allows traffic from the Trust zone to the DMZ zone is not being hit. The administrator confirms that the source IP, destination IP, and application are correct. Which factor should the administrator check next to determine why the rule is being bypassed?
Hard26An administrator wants to schedule regular configuration backups to an external server. Which THREE methods are valid ways to achieve this? (Choose three.)
Hard27Which TWO are valid methods to decrypt SSL/TLS traffic on a Palo Alto Networks firewall? (Choose two.)
Medium28A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?
Medium29A security administrator notices traffic from an internal user to a known malicious IP address in the corporate network. The traffic is allowed despite a security rule that blocks traffic to that IP. The rule is in a rulebase with multiple rules, and the administrator verifies that the malicious IP is correctly listed in a custom object used by the rule. What is the most likely cause of this issue?
Hard30An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?
Medium31An administrator modifies a security policy but the change does not take effect. What must the administrator do?
Easy32An administrator has configured SSL decryption for outbound traffic. Users report that they can access most HTTPS sites, but when they visit their bank's website, they receive a certificate error and the connection is blocked. The administrator wants to allow access to the bank site without decryption. What should be configured?
Medium33After upgrading the PAN-OS version on a firewall, the administrator notices that the commit operation takes significantly longer than before. What is the most likely cause?
Medium34A security engineer is troubleshooting a connectivity issue where internal users cannot reach a public web server hosted on the internet. The firewall is configured with a security policy that allows traffic from the internal zone to the external zone on port 80. The engineer notices that traffic is being dropped. Upon checking the session table, the engineer sees that the session is initiated correctly but the return traffic is not matching the existing session. What is the most likely cause?
Medium35A company wants to block all social media except LinkedIn. Which combination of URL filtering actions should be implemented?
Easy36Which TWO actions should be taken to protect against DNS tunneling? (Choose two.)
Hard37A company's security policy uses application-based rules. However, some traffic from a new cloud application is being blocked even though the application is allowed in the rule. What should the administrator check first?
Medium38A security administrator at a branch office needs to allow a remote vendor to access the firewall's web management interface only from IP address 203.0.113.50. The firewall's management interface is in the Management zone. Which Palo Alto Networks feature should the administrator use to restrict access?
Medium39An administrator is configuring Network Address Translation (NAT) on a Palo Alto Networks firewall. Which of the following statements about the order of NAT rule evaluation is correct?
Medium40Which TWO are best practices for managing security policies in a Palo Alto Networks firewall?
Medium41An administrator needs to implement a policy where traffic from the 'Sales' zone to the 'Finance' zone is allowed only for the 'ms-office365' application, but traffic from 'Sales' to 'Finance' using any other application must be denied. Which rule design meets this requirement efficiently?
Hard42An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?
Hard43How can an administrator quickly identify which security rules are not being used in order to clean up the rulebase?
Easy44A security administrator is configuring a File Blocking profile to prevent users from downloading executable files from the internet. The administrator wants to ensure that the firewall blocks only the download direction and not the upload direction, while still logging the event. Which configuration should be used?
Hard45An administrator configures SNMP monitoring on a firewall but receives no data from the SNMP manager. Which check should be performed first?
Medium46Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?
Medium47A network engineer wants to configure a new VLAN interface on a Palo Alto Networks firewall. After creating the VLAN object and assigning it to an Ethernet interface, the VLAN interface remains down. What is the most likely cause?
Easy48An administrator is configuring a security policy rule that must allow access to a web server hosted at www.example.com. The web server's IP address changes frequently due to a content delivery network (CDN). The administrator wants the firewall to automatically update the IP address used in the rule without manual intervention. Which type of address object should be used?
Hard49A security architect is planning a deployment for a multi-tenant data center where each tenant requires isolated security policies and separate administrators. Which Palo Alto Networks architecture best meets these requirements?
Hard50An organization wants to segment internal traffic between the Engineering and Finance departments and apply threat prevention. Which TWO actions should be taken? (Choose two.)
Medium51An administrator is configuring a security policy on a PA-3260 firewall. The administrator wants to ensure that a rule allowing SSH from the 'Management' zone to the 'Internal' zone is only active during business hours (9 AM to 5 PM) on weekdays. The administrator creates a schedule object named 'BusinessHours' and attaches it to the rule. However, after applying the policy, SSH access is allowed at all times. What is the most likely reason?
Hard52A company has two PA-220 firewalls in active/passive HA. They want to ensure that if the active firewall loses internet connectivity but its management interface remains up, a failover occurs. Which monitoring method should be configured?
Medium53A large enterprise uses dynamic address groups based on tags to manage firewall policies. The administrator notices that a specific address object is being incorrectly included in a dynamic address group that should only contain servers from a different region. What could be the reason?
Hard54A security administrator at a healthcare company needs to detect and block outbound emails that contain patient Social Security numbers. The company uses Microsoft Exchange over SMTP, and the firewall is running PAN-OS 10.1 with the appropriate subscriptions. Which Content-ID feature should the administrator configure to inspect the email body and attachments for sensitive data patterns?
Medium55Which three components are part of the Palo Alto Networks Next-Generation Firewall architecture? (Choose three.)
Easy56A university uses a Palo Alto Networks firewall to protect its network. They have implemented SSL Forward Proxy decryption for all student traffic. Recently, the IT helpdesk has received complaints from students that some websites (e.g., online banking, healthcare portals) are not loading properly. The firewall logs show that these sites are being decrypted, and no threats are detected. The university's legal team has advised that decryption of financial and healthcare sites may violate regulations. The network team wants to quickly resolve the issue while ensuring compliance. What is the best course of action?
Medium57An administrator needs to ensure that a security policy rule only allows traffic to a specific destination FQDN that resolves to multiple IP addresses, and the IP addresses change frequently. The administrator wants the firewall to automatically update the IP addresses without manual intervention. Which object type should the administrator use?
Medium58What does a 'shadowed' rule mean in the context of policy evaluation?
Easy59Which Content-ID feature can be used to prevent credit card numbers from being sent via webmail applications?
Easy60An organization needs to send threat logs to two different syslog servers: one for real-time alerts and one for long-term storage. They also need to send traffic logs to the long-term storage syslog only. They have configured two syslog server profiles. What is the correct approach?
Hard61Which of the following is a best practice when creating security policy rules on a Palo Alto Networks firewall?
Easy62An administrator is configuring a Dynamic Address Group (DAG) to automatically include all servers that have the tag 'WebServer'. The DAG will be used in a security policy. Which two of the following statements are true regarding the configuration and behavior of this DAG? (Choose two.)
Hard63A company uses App-ID to control cloud storage applications. Users report that uploads to Google Drive are blocked even though a rule allows 'google-drive-base'. What is the most likely cause?
Medium64A security policy rule references a service object "HTTP" which is pre-defined. What is the default port for the HTTP service object?
Easy65A security administrator needs to inspect traffic to a critical web server that uses HTTPS. The firewall is configured as a forward proxy for outbound traffic. Which decryption type should be used to decrypt the traffic inbound to the web server?
Easy66An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)
Medium67A security administrator is configuring a Security policy rule to allow access to a SaaS application. The administrator wants to ensure that the application is identified correctly even if it uses dynamic IP addresses and multiple ports. Which App-ID characteristic allows the firewall to identify the application regardless of IP address and port?
Medium68After a security policy change, users complain that they cannot upload files to a custom web application. The rule allows the custom application 'webapp' and Content-ID is enabled. What is the most likely cause?
Hard69An administrator is creating a new address object in PAN-OS and needs to ensure that the object can be used in security policies to match traffic from a specific subnet and also from a specific range of IP addresses within that subnet. Which two address object types should the administrator consider? (Choose two.)
Medium70Which THREE are default security profile groups in PAN-OS? (Choose three.)
Easy71A network security engineer is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable only through the untrust zone via the ethernet1/2 interface, which is in the untrust zone and uses the default virtual router. The engineer wants to ensure that syslog traffic egresses via ethernet1/2 and uses the correct source IP address. Which configuration should the engineer perform?
Hard72Drag and drop the steps to configure Active/Passive High Availability on a Palo Alto Networks firewall into the correct order.
Medium73A junior administrator is investigating a network issue where traffic to a critical server is being blocked. To see the specific security rule that matched and the action taken, which log should the administrator review?
Easy74An administrator needs to create a security rule that permits HTTP and HTTPS access to a web server cluster. The cluster members are defined as address objects named Web1, Web2, and Web3. The administrator wants to reference these three objects as a single entity in the security rule. Which object type should be created?
Medium75A firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which action should be taken?
Hard76A network security administrator is configuring a security policy on a PA-5220 firewall. The administrator wants to allow HTTP and HTTPS traffic from the 'Guest' zone to the 'Internet' zone, but only for specific users in the 'guest-users' group. The administrator creates a rule with source zone 'Guest', destination zone 'Internet', source user 'guest-users', and application 'web-browsing' and 'ssl'. However, when testing, all Guest users can access the Internet, not just those in the group. What is the most likely cause?
Hard77A hospital network uses a Palo Alto Networks firewall with outbound SSL decryption. The IT security team notices that during peak hours, the firewall CPU utilization spikes to 95% when decryption is enabled, causing latency for all users. They have already upgraded to maximum licensed throughput and added a dedicated decryption engine. However, the issue persists. The network has 10,000 endpoints and 500 Mbps throughput. The decryption policy includes rules to decrypt all traffic to critical medical cloud services (EHR, PACS) and social media sites. What should the administrator do first to reduce CPU load?
Medium78A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?
Medium79Drag and drop the steps to perform a packet capture (tcpdump) on a Palo Alto Networks firewall using the CLI into the correct order.
Medium80A company needs to block a list of known malicious domains that is updated daily by a threat intelligence vendor. Which Palo Alto Networks object should be used?
Medium81A firewall is configured with multiple Virtual Systems (vsys). An admin wants to assign a custom admin role that can manage only specific vsys. Which role type supports this?
Medium82An administrator wants to allow ping (ICMP) and SSH access on a data interface (e.g., ethernet1/1) for troubleshooting. Which configuration is required?
Hard83A company needs to receive email alerts for critical system events. What is the recommended method to configure email notifications on a Palo Alto Networks firewall?
Easy84Match each Palo Alto Networks service to its typical use.
Medium85A syslog server is only reachable through a specific interface on the firewall. To ensure syslog logs are sent via that interface, which configuration is required?
Hard86Which THREE are valid components of Content-ID? (Choose three.)
Hard87A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?
Medium88An administrator is configuring a Palo Alto Networks firewall to send SNMP traps to a monitoring server at 10.1.1.50. The administrator has already configured the SNMP community string under Device > Setup > Operations > SNMP Setup. Which two additional configurations are required to ensure traps are sent successfully? (Choose two.)
Medium89An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that management access to the firewall is secure. Which of the following is a best practice for securing management access?
Medium90A company wants to deploy a new firewall with a management interface on a separate VLAN to ensure management traffic is isolated from production traffic. Which interface type should be used for management access?
Easy91Refer to the exhibit. The administrator sees that traffic from 10.10.1.12 is being denied by rule2. Which action should the administrator take to allow this traffic while maintaining security?
Hard92A multinational company has deployed a Palo Alto Networks firewall in a datacenter to provide internet access to employees in the corporate office and remote branches via IPsec VPN. The firewall is configured with multiple virtual routers, security zones (trust, untrust, dmz, vpn), and policies for application and URL filtering. Recently, users in the corporate office report that they cannot access a critical cloud-based CRM application (https://crm.company.com) from their workstations, while access from remote VPN users works fine. Other websites are accessible from the corporate office. The IT team has verified that DNS resolution is correct and that the CRM server responds to pings from the firewall's management IP. The security policy includes a rule from trust to untrust that allows application 'crm-base' and 'ssl' with URL category 'crm-sites'. The administrator has checked the traffic logs and sees that sessions are being denied with the reason 'application mismatch'. Which of the following is the most likely cause and correct course of action?
Hard93Which three of the following services are commonly permitted on the management interface? (Choose three.)
Easy94An administrator is reviewing the security policy and notices a rule that allows all traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only web browsing (HTTP and HTTPS) is allowed, while all other traffic is blocked. What should the administrator do?
Medium95A network administrator notices that traffic from the internal zone to the external zone is being denied, even though a security policy allowing all outbound traffic exists. The internal zone is configured with a zone protection profile that has Flood Protection enabled. What is the most likely cause of the denial?
Medium96A security administrator wants to inspect decrypted traffic for threats. What is the minimum set of features required?
Easy97An administrator is configuring a security policy to allow access to a critical application. The application uses multiple protocols and dynamic ports. The administrator wants to ensure that the policy is as secure as possible while allowing legitimate traffic. Which two actions should the administrator take? (Choose two.)
Hard98A company wants to ensure that all traffic from the internet to their internal web server is inspected for threats. Which configuration component is essential to achieve this?
Easy99A network administrator is configuring a Security policy rule on a Palo Alto Networks firewall to allow HTTP traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that the rule only allows HTTP traffic on its default port. Which service setting should be used?
Easy100A security administrator notices that traffic from a specific subnet is not being logged in the Traffic logs, although the traffic is allowed by a security policy rule. Which configuration setting should be verified?
Medium101A security administrator notices that a SaaS application is allowed by the security policy, but the firewall is not decrypting the traffic. Without decryption, which Content-ID feature can still identify and control the application's use based on the server certificate?
Medium102When creating a security policy to block malware, which THREE profile types should be applied for comprehensive protection?
Medium103A network administrator wants to monitor HTTPS traffic without decrypting it, but still wants to identify the applications being used. Which feature can be used to identify HTTPS applications without decryption?
Medium104Which TWO statements about External Dynamic Lists (EDLs) are true?
Medium105An administrator wants to ensure that all traffic from the engineering zone to the server zone is logged, but only when a session is established. Which log setting should be configured in the security rule?
Easy106A decryption policy is configured to decrypt traffic to a specific external server. The admin notices that the traffic is not being decrypted. What is the first step in troubleshooting?
Medium107An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable via a specific interface and virtual router. Which two configurations are required to ensure that syslog messages are sent from the correct source interface? (Choose two.)
Medium108An administrator is designing a security policy for a Palo Alto Networks firewall. The administrator wants to ensure that the policy is efficient and follows best practices for rule evaluation. Which two actions should the administrator take? (Choose two.)
Hard109Refer to the exhibit. A user in the trust zone attempts to access https://www.example.com. The traffic matches rule 2 first. What is the expected behavior?
Medium110An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?
Easy111A firewall administrator is troubleshooting a situation where traffic from the 'Engineering' zone (source zone) to the 'Servers' zone (destination zone) is being allowed, but the desired behavior is to block it. The administrator runs 'show running security-policy' and sees the following rules in order: Rule1: from Engineering to Servers allow; Rule2: from Engineering to Servers deny; Rule3: from any to Servers allow. Which TWO statements are true regarding policy evaluation?
Hard112What is the primary benefit of using App-ID in a security policy instead of relying solely on port-based rules?
Easy113An administrator needs to provide internet access to employees while blocking access to social media sites. Which feature should be used to identify and block social media traffic?
Easy114A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?
Easy115A small business uses a single PA-220 firewall for internet access and has three internal zones: Trust, DMZ, and Guest. Users in the Trust zone report intermittent connectivity to a public cloud application. The firewall administrator checks the traffic logs and sees that sessions to the cloud application show "Application: ssl" and "Action: allow". The administrator suspects the issue might be related to decryption. The firewall currently has a decryption policy that decrypts all outbound HTTPS traffic for threat inspection. The cloud application uses certificate pinning and breaks when decrypted. What is the best solution to allow this application to function while still decrypting other traffic?
Medium116An administrator needs to create a security policy rule that allows access to a web server with IP address 203.0.113.10, but the IP address may change in the future. The administrator wants to minimize manual updates to the policy. Which address object type should the administrator use?
Hard117A security administrator is troubleshooting a rule that appears to be matching correctly but is not allowing traffic. The rule uses source zone 'Trust' and destination zone 'Untrust', and the action is 'allow'. The traffic source is in the 'DMZ' zone. What is the most likely reason the traffic is denied?
Medium118An administrator is troubleshooting why a security rule is not being hit. The rule is for traffic from the 'Trust' zone to the 'Untrust' zone, source address 10.1.1.0/24, destination address any, application 'web-browsing', service 'application-default', action allow. The traffic in question is from 10.1.1.5 to 8.8.8.8 on port 80. The administrator checks the traffic logs and sees that the session is being denied by the interzone default rule. What is the most likely cause?
Hard119A security administrator is creating a Security policy rule to allow only the business-critical functions of a SaaS application while blocking its social and file-sharing components. The administrator wants the firewall to distinguish between the different functions within the same application. Which App-ID capability should be used to accomplish this?
Medium120A security administrator needs to create an address object for a single host with IP address 192.168.1.100. Which address type should the administrator choose?
Easy121A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?
Hard122An administrator wants to ensure that a security policy rule is only active during business hours (9 AM to 5 PM) on weekdays. Which configuration element should be used?
Easy123A security administrator needs to ensure that files downloaded by users are scanned for malware. The administrator has already configured a File Blocking profile to block malicious files. Which additional Palo Alto Networks security profile must be applied to the Security policy rule to inspect the file contents for known threats?
Easy124A security administrator is reviewing the rulebase and notices that a rule allowing traffic from the 'Trust' zone to the 'Untrust' zone has the action set to 'Allow' but is not being hit. The administrator confirms that there is traffic matching the source and destination zones, addresses, and applications. What is the most likely reason the rule is not being hit?
Hard125A network administrator is configuring a security policy to allow SSH access to a server. The administrator wants to use a predefined service object for SSH. Which service object should be selected?
Easy126A network security administrator needs to create a rule that allows DNS traffic from the Trust zone to the Untrust zone. Which application should be selected in the security rule to allow DNS?
Easy127An administrator is creating service objects to define custom applications for a security policy. The administrator needs to create a service object for a custom TCP-based application that uses a single port, and another service object for an application that uses a range of UDP ports. Which two actions must the administrator take when defining these service objects? (Choose two.)
Medium128A security administrator is troubleshooting why some SSL Forward Proxy decrypted sessions are failing with 'certificate unknown' errors. The firewall is configured with a self-signed forward trust certificate. Which two actions should the administrator take to resolve the issue? (Choose two.)
Hard129An administrator has configured a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web-browsing and ssl applications. The rule is placed at the top of the rulebase. Users in the Guest zone report that they can access websites but cannot use other applications like SSH or FTP. Which statement explains this behavior?
Hard130A company wants to block file uploads of PDFs to the internet via HTTP. Which Content-ID profile should be configured?
Easy131Which TWO types of address objects can be used in a security policy? (Choose two.)
Easy132A company has multiple branch offices that use overlapping private IP ranges (192.168.0.0/16). To avoid conflicts when these branches connect to the data center via IPsec, the administrator needs to translate branch source IPs to unique addresses. Which object type is best suited for this task?
Medium133A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?
Medium134An administrator is reviewing the security policy on a Palo Alto Networks firewall and notices that a rule allowing web browsing from the Trust zone to the Untrust zone has no application specified. The administrator wants the firewall to permit only web-browsing and ssl while blocking all other applications on ports 80 and 443. What should the administrator do to meet this requirement?
Easy135A security administrator wants to block all peer-to-peer file sharing applications while allowing web browsing. Which type of security policy rule should they configure?
Easy136A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?
Easy137An administrator wants to synchronize the firewall's clock with a central NTP server. Where is this configured?
Easy138A security administrator notices that a large number of unknown TCP sessions are being generated by an internal application. The administrator wants to identify the application using App-ID. Which action should they take first?
Medium139A company deploys a Palo Alto Networks firewall in a cloud environment using the VM-Series. The firewall must scale to handle traffic spikes. Which architectural approach provides the best elasticity and management simplicity?
Medium140During an App-ID upgrade, some applications are no longer identified correctly. What is the most likely cause?
Hard141A network security administrator needs to ensure that a Palo Alto Networks firewall sends SNMP traps to a monitoring server at 10.1.1.50 using the MGT interface. The administrator has already added the SNMP community string and trap destination under Device > Setup > Services > SNMP. However, no traps are being received. Which additional configuration is required to ensure traps are sent from the MGT interface?
Medium142Refer to the exhibit. An admin adds a new address object 'web-04' with IP 10.0.0.4 and applies it to a security policy that references the address group 'web-servers'. However, traffic to 10.0.0.4 is not allowed. What is the most likely cause?
Medium143Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?
Medium144A network security administrator is configuring a security policy rule to allow DNS traffic from the Trust zone to the Untrust zone. The rule uses application dns and service application-default. Users report that DNS queries to external servers are failing. The administrator notices that the firewall is allowing the DNS queries but the responses are being dropped. What is the most likely cause?
Hard145A network administrator notices that traffic for a custom business application is being incorrectly identified as 'ssl' by the firewall. What is the most efficient way to ensure this application is accurately identified without impacting other SSL traffic?
Medium146Which TWO of the following are key benefits of using an Application-Based Security Policy compared to a Port-Based Security Policy? (Choose TWO.)
Medium147An administrator wants to allow only specific applications (e.g., web-browsing, ssl) from the internal network to the internet. Which object type should be used in the security policy application field?
Medium148An administrator needs to decrypt HTTPS traffic from external users to the company's web servers. Which decryption policy should the administrator configure?
Medium149An administrator needs to allow inbound SMTP traffic to a mail server located in the DMZ. The firewall has a public IP address on the external interface. Which configuration is necessary to ensure the mail server receives the traffic?
Medium150Which TWO statements are true regarding App-ID and Content-ID? (Choose two.)
Medium151A company uses Panorama to manage multiple device groups. They want to push a set of global security policies to all firewalls. Where should the administrator configure these policies in Panorama?
Hard152A security administrator wants to allow access to a SaaS application but block specific high-risk functions within that application, such as file uploads. The application uses HTTP and HTTPS. Which Palo Alto Networks feature should the administrator use to granularly control application functions?
Medium153A network administrator wants to ensure that the firewall sends SNMP traps to a monitoring server at 192.168.1.50. The administrator has already configured the SNMP community string and added the trap destination under Device > Setup > Services. However, traps are not being received. What is the most likely missing configuration?
Easy154A network admin needs to push a security policy change to firewall-01 and firewall-02. Both firewalls have different interface configurations but should share the same security rules. What is the best way to achieve this using Panorama?
Easy155A security administrator needs to create a policy that allows users in the 'trust' zone to access the internet, but blocks access to a specific set of known malicious URLs. The administrator has subscribed to a URL filtering service and wants to use a custom URL category to block the malicious sites. Which configuration should be used?
Medium156A security administrator is configuring a Palo Alto Networks firewall with a security policy that allows traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only specific users can access certain applications. The administrator creates a rule with source zone Trust, destination zone Untrust, source user 'domain\jdoe', application 'web-browsing', action allow. However, after committing, the user jdoe reports that they cannot access the web. The administrator checks the traffic logs and sees that the traffic is being denied by the implicit rule. What is the most likely cause?
Hard157Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)
Medium158A company wants to block file-sharing applications like BitTorrent, but allow HTTP and HTTPS. Which type of policy is most appropriate to achieve this granular control?
Easy159A user reports that they are unable to download executable files from the internet. The firewall security rule allows the application. What should the administrator check first?
Medium160Which TWO statements about App-ID are correct? (Choose two.)
Medium161Which THREE components are required to successfully decrypt outbound SSL traffic using forward proxy? (Choose three.)
Hard162A network administrator needs to restrict which source IP addresses can access the firewall's web management interface. Which feature should be configured?
Medium163An administrator is configuring a security policy on a Palo Alto Networks firewall. The administrator wants to allow only HTTP and HTTPS traffic from the Trust zone to the Untrust zone, and block all other applications. The administrator creates a rule with source zone Trust, destination zone Untrust, application 'web-browsing' and 'ssl', action allow. However, after committing, users can still access other applications like SSH. What is the most likely explanation?
Easy164Which two authentication methods can be used for administrative access to the firewall's web interface? (Choose two.)
Medium165Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)
Easy166A firewall uses an external SMTP server for email alerts. The SMTP server is reachable via a specific virtual router and interface. What must be configured to ensure the firewall uses the correct path to reach the SMTP server?
Easy167During a security audit, an administrator notices that a security policy rule uses an address group that includes an FQDN object. The FQDN resolves to multiple IP addresses that change frequently. What is the best practice for ensuring the firewall uses the current resolved IPs without manual intervention?
Hard168After making configuration changes, an administrator clicks 'Commit' but the changes are not applied. What is the most likely cause?
Medium169An administrator configures SSL Forward Proxy decryption on a Palo Alto Networks firewall. Internal users report that when they browse to https://portal.hr.example.com, the browser presents a certificate issued by the firewall's forward trust CA instead of the website's real certificate. The administrator wants the browser to trust this dynamically generated certificate without user warnings. What should the administrator do?
Medium170A company uses Panorama to manage multiple firewalls. After pushing a template change, one firewall fails to commit with error 'invalid certificate path'. What is the most likely cause?
Hard171An organization uses a custom ERP system that communicates over TCP port 4444. The firewall's App-ID incorrectly identifies some of the traffic as 'ssl' because the ERP system uses a proprietary encryption wrapper. What is the recommended approach to ensure correct identification?
Hard172An organization is implementing a high availability pair of Palo Alto firewalls in active/passive mode. Which three actions are necessary for proper failover functionality? (Choose three.)
Medium173A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)
Hard174An administrator needs to block traffic from a specific internal IP address to the internet. Which object type should be used in the security policy source field?
Easy175An administrator is configuring a Dynamic Address Group (DAG) that uses tags to automatically include members. The administrator wants to ensure that the DAG is populated correctly. Which two actions are required to make a firewall register an IP address as a member of the DAG? (Choose two.)
Hard176A security analyst wants to send firewall logs to an external syslog server for long-term storage. Which three configuration steps are necessary?
Medium177A large financial institution runs a PA-5250 firewall in a virtual wire mode between two core switches. The firewall is configured with multiple virtual wire sub-interfaces to segregate traffic for different VLANs. Recently, the security team noticed that multicast traffic from a critical trading application is not being forwarded across the virtual wire link. The firewall has multicast policies enabled, and the trading application uses IGMPv3. The administrator has verified that the firewall's multicast policy allows the traffic and that the IGMP snooping is enabled on the adjacent switches. However, the multicast stream does not reach the receivers on the other side. Which step should the administrator take to resolve this issue?
Hard178Which THREE actions can be taken based on hit counts in security rules? (Select three.)
Medium179A company uses a Palo Alto Networks firewall to secure outbound internet access. The security team wants to ensure that users cannot access malicious websites. They have configured a URL Filtering profile with the 'malware' category set to 'block' and attached it to a Security policy rule that allows web-browsing. However, users report that they can still access some known malicious sites that are categorized as 'malware'. What is the most likely reason?
Hard180An organization has implemented SSL forward proxy decryption. Users on Windows workstations report that many HTTPS sites show certificate errors. The firewall's decryption policy is configured correctly. What is the most likely cause?
Hard181An administrator wants to create a service object for TCP port 8080 and call it 'web-proxy'. Which properties must be specified?
Medium182Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?
Medium183After a firewall upgrade, the system clock shows a time that is five minutes behind the actual time, even though NTP is synchronized. What is the most likely cause?
Hard184Which THREE log types can be forwarded to a syslog server?
Hard185A security administrator is configuring a Data Filtering profile to prevent sensitive customer data from leaving the network via webmail. The administrator wants to block any email that contains a U.S. Social Security Number. Which Data Filtering profile setting should be used to detect the SSN pattern?
Hard186An administrator creates a custom service object for TCP port 3389. What is the standard name for this service?
Medium187What is the purpose of the 'Telemetry' feature in PAN-OS?
Easy188Which object type is used to group multiple service objects together for use in a security policy?
Easy189An administrator is troubleshooting why an application is being identified as 'incomplete' in the traffic log. What does this indicate?
Hard190A security team wants to inspect traffic to and from a critical application server. They configure an inbound decryption rule to decrypt traffic destined to the server's IP address. After deploying, they find that traffic is not being decrypted. What is the first step to troubleshoot?
Hard191Which Palo Alto Networks subscription service provides real-time threat intelligence about unknown files and links?
Easy192Which TWO are methods used by App-ID to identify applications? (Choose two.)
Easy193Which THREE of the following are valid steps when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?
Hard194A firewall is configured to send logs to an external syslog server. Some logs are missing, but other logs are arriving. Which step should be taken to troubleshoot this issue?
Hard195Which Content-ID feature can be used to prevent data loss by blocking specific patterns in traffic?
Easy196A security administrator has configured a security policy rule to allow SSH from the Trust zone to the Untrust zone. The rule uses the application 'ssh' and the service 'application-default'. Users report that SSH connections to external servers on port 2222 are failing, while SSH on port 22 works. What is the most likely cause of the failure?
Medium197During troubleshooting, an administrator needs to review firewall system events such as user logins, configuration changes, and commit failures. Which log type should be examined?
Easy198An administrator is reviewing the rulebase and finds a rule with a hit count of 0 over the past 30 days. What action should the administrator consider?
Easy199A firewall administrator notices that traffic from an internal user is being decrypted, but the user's browser shows a certificate warning. The firewall uses a CA certificate issued by the company's internal PKI. What is the most likely reason for the browser warning?
Hard200An administrator has created an address group that includes an FQDN address object. When the FQDN's IP address changes, how does the firewall update the group?
Medium201A company uses Active Directory for user authentication. They want to enforce security policies based on user identity. What is the required first step to enable User-ID on the Palo Alto Networks firewall?
Easy202An administrator wants to ensure that a specific security policy rule is applied before all other rules. What should be configured?
Medium203An administrator notices that the firewall's web interface is accessible via HTTPS but shows an expired certificate warning. The firewall's management certificate was issued by an internal CA and has a validity of two years. The administrator checks the certificate and sees it expired yesterday. The administrator generates a new self-signed certificate through the firewall's GUI. After generating, the administrator assigns the new certificate to the HTTPS management interface. Despite this, the firewall still presents the old expired certificate when accessed. What is the most likely cause?
Hard204A security administrator is troubleshooting an issue where users cannot access a specific website. The security policy allows web-browsing from the internal zone to the external zone. Which TWO actions should the administrator take to verify the traffic is being matched and allowed?
Easy205Which TWO methods are valid for managing a Palo Alto Networks firewall? (Select two)
Medium206Which of the following is a primary benefit of using App-ID in a security policy?
Easy207Refer to the exhibit. The firewall is currently running PAN-OS 9.1.4. The administrator wants to upgrade to the latest available version shown. What should the administrator do first?
Medium208A company has a security policy that allows 'ssl' application but does not have SSL decryption enabled. What can App-ID still identify from the encrypted session?
Medium209A network security administrator needs to create an address object that represents a range of IP addresses from 10.1.1.10 to 10.1.1.20. Which address object type should be used?
Medium210A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?
Easy211Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?
Hard212Which THREE actions can improve firewall performance by reducing CPU load? (Choose three.)
Hard213A security administrator wants to block all peer-to-peer file sharing applications, such as BitTorrent, regardless of the port they use. Which Palo Alto Networks feature should the administrator use to accomplish this?
Easy214A security analyst needs to monitor decryption performance and identify sessions that are bypassing decryption due to policy or technical reasons. Which two monitoring tools or methods can provide this insight?
Hard215During SSL decryption, which three factors can cause the firewall to fail to decrypt a session or to bypass decryption?
Medium216Which TWO management methods allow CLI access to a Palo Alto Networks firewall?
Easy217An administrator needs to restrict access to the firewall's web management interface to only the IT department subnet 10.0.0.0/24. The firewall's management interface is in the 'Management' zone. Which configuration step is required to enforce this restriction?
Medium218An administrator is troubleshooting why a rule is not being hit. The rule has source zone Trust, destination zone Untrust, source address 10.0.0.0/8, destination address any, application web-browsing, action allow, and log at session end. The traffic is coming from 10.1.1.1 to 1.2.3.4 on port 80, zone Trust to Untrust. The rule count shows zero hits. What could be the issue?
Medium219A firewall administrator is reviewing the security policy and notices that a rule allowing traffic from the Trust zone to the DMZ zone is not being hit. The rule is placed after a rule that denies all traffic from Trust to DMZ. What is the most likely explanation?
Medium220A security administrator is configuring a security policy rule to allow access to a web server from the internet. The rule is set to allow HTTP and HTTPS traffic to the server's public IP address. However, after committing the change, users report that they cannot access the web server from the internet. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit rule. What is the most likely cause of the issue?
Hard221An administrator needs to access the firewall's CLI via SSH, but the default SSH port (22) is blocked by the corporate firewall. Which configuration allows SSH on a non-standard port?
Easy222An administrator configures a security policy with three rules in order: Rule1 allows any to any with log at session start, Rule2 allows HTTP from trust to untrust, Rule3 denies any. Traffic from an internal user to an external web server is logged as allowed. Which rule processed the traffic?
Hard223An administrator is configuring a security policy and needs to reference a set of external servers that are frequently updated by a third-party service. The servers' IP addresses change often, and the administrator wants the firewall to automatically update the list without manual intervention. Which type of object should the administrator use?
Easy224A company wants to decrypt all SSL/TLS traffic from internal users except traffic to financial sites. The firewall is placed as a forward proxy. Which policy configuration ensures that traffic to financial sites is not decrypted?
Medium225Which TWO methods can be used to help prevent rule shadowing? (Select two.)
Easy226A company is deploying a Palo Alto firewall in a high-availability (HA) pair. They want to ensure that when a failover occurs, session information is preserved to maintain active connections. Which feature must be enabled?
Hard227An administrator wants to block all peer-to-peer file sharing traffic, but must ensure that legitimate business applications like FTP are not affected. Which approach is most effective?
Medium228A network engineer needs to apply the same security policy to multiple firewalls. Which tool should be used to centralize policy management?
Easy229A network administrator needs to configure SNMPv3 on a Palo Alto Networks firewall to allow a monitoring server to query interface statistics. The administrator wants to ensure that SNMP queries are authenticated and encrypted. Which SNMPv3 configuration is required to meet these requirements?
Medium230A firewall administrator is tasked with implementing a policy that allows SSH access from the 'Admin' zone to the 'Core' zone only for specific administrators, and all other SSH attempts should be logged and dropped. The company has a large number of administrators. Which method is most efficient and scalable?
Hard231A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?
Medium232An administrator is configuring a Palo Alto Networks firewall to send email alerts for critical system events. The administrator has configured an SMTP server under Device > Setup > Services > Email. However, test emails are not being delivered. Which additional step is required to allow the firewall to send email alerts?
Easy233A network security engineer is configuring a Palo Alto Networks firewall to send SNMP traps to a management server. The engineer has already configured the SNMP community string and the trap destination IP. However, the management server is not receiving any traps. Which additional configuration is required to allow SNMP traps to be sent?
Hard234A network administrator is troubleshooting a connectivity issue where users in the 192.168.1.0/24 subnet cannot reach a server at 10.0.0.10. The firewall has a rule that allows traffic from source zone 'Trust' to destination zone 'DMZ' with source address 192.168.1.0/24 and destination address 10.0.0.10. The traffic is matching the rule, but the packets are being dropped. What is the most likely reason?
Hard235Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)
Hard236An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?
Hard237An organization is deploying a Palo Alto Networks firewall in a data center to segment traffic between three application tiers: web, app, and database. The web servers must be accessible from the internet, the app servers must only be reachable from the web servers, and the database servers must only be reachable from the app servers. Which security policy design best meets these requirements?
Medium238An administrator needs to create a dynamic address group that automatically includes all virtual machines in a VMware environment based on their tags. The firewall is integrated with VMware NSX-T. Which two actions must the administrator take to enable this dynamic grouping? (Choose two.)
Hard239An administrator is configuring a security policy and needs to allow access to a set of web servers that are defined by a dynamic address group. The dynamic address group uses the filter 'web-server' and tags are applied to the address objects. However, the administrator notices that the dynamic group is not populating with the expected members. Which action should the administrator take to troubleshoot this issue?
Medium240Refer to the exhibit. The firewall is experiencing performance issues and dropping sessions. Based on the exhibit, what is the most likely cause?
Medium241Refer to the exhibit. The firewall raises a certificate expiry warning for the decryption CA. Which action is required?
Easy242A security administrator notices that traffic from a custom application is being incorrectly identified as web-browsing. What is the most likely cause?
Easy243An administrator needs to block all traffic from a specific application that uses multiple ports. Which TWO methods can achieve this? (Choose two.)
Easy244An organization wants to prevent data exfiltration via DNS tunneling. Which security profile should be applied to the outbound DNS traffic?
Easy245A company recently deployed a Palo Alto Networks PA-220 firewall to secure outbound web access. The security policies include a rule named 'Allow-Web' with the following configuration: source zone 'Inside', destination zone 'Outside', application 'web-browsing', service 'application-default', action 'allow'. All other traffic is denied by a default deny rule. Users report that they can access most public websites, but they cannot access a partner's website hosted at 203.0.113.50 on TCP port 8080. Connections to this site time out. DNS resolution for the hostname works correctly. The firewall logs show that traffic from internal users to 203.0.113.50:8080 is not matching any rule and is being denied by the default deny rule. Which action should the administrator take to resolve the issue while adhering to security best practices?
Easy246An administrator is configuring a new PA-3220 firewall and needs to allow DNS queries from the internal network to an external DNS server. The internal network is in the Trust zone, and the external DNS server is reachable via the Untrust zone. Which type of security policy rule should be created to permit this traffic?
Easy247An administrator is auditing the security policy on a PA-3220 firewall. The administrator notices that a rule allowing RDP from the 'Trust' zone to the 'DMZ' zone has a source user of 'domain\jdoe' and is positioned below a broader rule that allows any application from Trust to DMZ for any user. The administrator wants the user-specific rule to be evaluated first. What is the most efficient way to achieve this?
Medium248A network administrator adds a new security rule allowing HTTP from the Trust zone to the Untrust zone. After committing, traffic from the Trust zone to the Untrust zone is still blocked. What is the most likely cause?
Easy249An administrator is designing a security policy for a new branch office. The policy must allow outbound web traffic from the Trust zone to the Untrust zone, but only for specific users in the 'Marketing' group. The firewall is integrated with Active Directory. Which TWO configurations are required to enforce this policy? (Choose two.)
Hard250Which THREE of the following are valid features of Palo Alto Networks active/passive HA?
Hard251A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?
Easy252An administrator is configuring a security policy rule and needs to reference a service that uses both TCP port 80 and TCP port 443. The administrator wants to minimize the number of objects in the policy. What should the administrator create to achieve this?
Easy253Based on the exhibit, what is the role of the rule "Allow_Outbound"?
Easy254An administrator wants to monitor which applications are being used on the network after SSL decryption. Which Palo Alto Networks feature provides detailed information about applications, including those that use SSL/TLS?
Easy255A security administrator is configuring a policy to allow access from the Guest zone to the Internet zone. The administrator wants to ensure that only HTTP and HTTPS traffic is allowed, and all other traffic is blocked. The administrator creates a rule with source zone Guest, destination zone Internet, application web-browsing and ssl, and action Allow. However, users report that they cannot access websites. What is the most likely cause?
Medium256Refer to the exhibit. A security analyst reviews a traffic log entry in JSON format. Which firewall feature is responsible for including the 'user' field in the log?
Medium257An administrator needs to create an External Dynamic List (EDL) that contains a list of malicious IP addresses. The list is hosted on an internal web server at http://192.168.1.50/malicious.txt. The firewall must check for updates every hour. Which configuration is required?
Medium258An organization has multiple virtual routers on a single firewall. Traffic between two virtual routers must be inspected by security policies. How should this be configured?
Medium259Refer to the exhibit. A user reports being unable to connect to a website over HTTPS. The traffic log shows the application as 'incomplete' and the rule 'Block-Unknown-App' is matched. What is the most likely reason the application is 'incomplete'?
Hard260A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?
Easy261A company is expanding its network and needs to add a new data center. The two data centers will be connected via a WAN link. To protect the traffic between data centers, the security team wants to use site-to-site VPNs. Which Palo Alto Networks feature is used to route traffic between VPN tunnels and security zones?
Medium262An administrator needs to allow traffic from multiple subnets to a specific internal server. The subnets are all part of the same address group. Which object would simplify the security policy rule?
Medium263An administrator needs to create an object that represents a set of subnets belonging to the same department, but the subnets are not contiguous. The object will be used in a security policy rule and must be updated automatically when new subnets are added in IP address management (IPAM). Which type of address object should the administrator use?
Medium264A security administrator is troubleshooting why a custom application is not being identified by App-ID. The application uses a proprietary protocol over TCP and is not recognized. Which two actions can the administrator take to enable App-ID to identify this application? (Choose two.)
Hard265An administrator is creating a security policy and needs to reference multiple service objects for different applications. The administrator wants to group these services into a single object that can be used in the policy. Which TWO of the following statements are true about service groups in PAN-OS? (Choose two.)
Medium266A small business has a Palo Alto Networks firewall with a single security policy rule that allows all traffic from the 'Trust' zone to the 'Untrust' zone. The business recently experienced a malware infection originating from an internal host that communicated with known malicious IP addresses. The administrator wants to implement a security policy to block traffic to these malicious IP destinations. The administrator has a list of 500 malicious IP addresses that may change frequently. What is the most efficient way to create a policy to block traffic to these IPs?
Easy267A firewall administrator needs to generate a report that shows the top applications consuming bandwidth over the last week. Which Palo Alto Networks tool should be used?
Medium268During a security audit, it is discovered that FTP traffic over non-standard ports is bypassing App-ID inspection. What is the most effective method to ensure all FTP traffic is identified, regardless of port?
Hard269A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?
Easy270After a policy change, a security administrator commits the candidate configuration, but the changes do not take effect immediately for all users. Some users report connectivity issues while others do not. What should the administrator check first?
Hard271A security administrator is configuring a rule to allow access to a web server. The rule uses a URL category as the destination. The administrator notices that the rule is not matching traffic to the web server's IP address when users connect directly via IP. What is the most likely reason?
Medium272A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?
Medium273Based on the exhibit, what action did the firewall take on this traffic?
Easy274A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal users and the internet. The security team wants to enforce different security profiles based on the destination country of outbound traffic. They have created a Security policy rule that allows web-browsing and ssl from the trust zone to the untrust zone. They now need to apply a URL Filtering profile that blocks malicious sites only when the destination IP is geolocated in a specific high-risk country. What should the administrator configure to achieve this?
Hard275Two Palo Alto Networks firewalls are configured in an active/passive high-availability pair. During a failover event, the passive firewall becomes active but the session table is empty. What is the most likely cause?
Hard276A security administrator at a company with a PA-5220 running PAN-OS 10.2 must ensure that configuration backups can be restored to a replacement firewall of the same model. The administrator plans to use scheduled configuration exports and also wants to retain a copy of the running configuration before a major change. Which TWO actions will satisfy these requirements? (Choose two.)
Hard277An administrator wants to block traffic from a specific user using User-ID. What is required to identify users in security policies?
Easy278An administrator is creating an application filter to allow only specific applications while blocking others within a category. The administrator wants to ensure that the filter matches applications based on their risk level. Which attribute should the administrator use in the application filter?
Medium279Which THREE actions can a Security policy rule perform on traffic?
Hard280An administrator is configuring a Palo Alto Networks firewall to use an external LDAP server for administrator authentication. The administrator wants to ensure that only members of the 'NetworkAdmins' group can log in with read-write privileges. Which configuration steps are required?
Hard281A company uses Palo Alto Networks firewall and wants to configure NAT to allow internal users to access the internet using a public IP address pool. Which NAT type should be used?
Medium282A firewall administrator is reviewing the security policy and notices that a rule allowing DNS from the Trust zone to the Untrust zone has a hit count of zero. The administrator confirms that DNS traffic is being generated and that the rule is enabled. Which action should the administrator take to troubleshoot why the rule is not being hit?
Medium283Drag and drop the steps to configure a GlobalProtect portal and gateway on a Palo Alto Networks firewall into the correct order.
Medium284A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?
Medium285A security administrator needs to ensure that employees cannot post credit card numbers on social media websites. The company uses Palo Alto Networks firewalls with SSL decryption configured for outbound traffic. Which Content-ID feature should be used to detect and block the credit card numbers in HTTP POST requests to social media sites?
Hard286Which TWO are best practices for securing management access to a Palo Alto firewall? (Select two)
Easy287A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?
Medium288A network security administrator is configuring a Palo Alto Networks firewall to decrypt outbound HTTPS traffic. The administrator wants to ensure that the firewall can present a valid certificate to internal users for any website they visit, without manually importing each website's certificate. Which configuration is required to achieve this?
Medium289Refer to the exhibit. What is the default gateway of the firewall?
Hard290An administrator is creating a new security rule at the top of the rulebase to allow specific web traffic. After committing, users report that all web traffic is now blocked, including traffic that was previously allowed by a lower rule. The new rule's action is set to 'Deny' and its source and destination are set to 'any'. What is the most likely cause?
Medium291A network administrator notices that traffic from a specific subnet is being denied even though there is a permit rule that matches the source and destination. The rulebase has over 500 rules. What is the most likely cause?
Medium292A network security administrator is configuring a security policy to allow access to a set of web servers. The servers are located in a dynamic environment where new instances are added frequently. The administrator wants to ensure that the policy automatically includes new web servers without manual updates. The administrator has created a dynamic address group named 'WebServers-DAG' with the filter 'WebServer'. Which additional configuration is required to ensure that the dynamic address group is populated correctly?
Medium293An administrator at a branch office with a PA-440 needs to allow the firewall itself to resolve external hostnames and to forward DNS queries from internal clients to public resolvers. The administrator wants to configure a DNS proxy on the firewall so clients use the firewall's interface IP as their DNS server. Which configuration step is required to enable this behavior?
Easy294Which of the following is NOT a valid method for upgrading PAN-OS software on a Palo Alto firewall?
Easy295An administrator wants to ensure that only the firewall administrator's workstation at 203.0.113.45 can reach the web management interface on a PA-3220 running PAN-OS 10.2. The workstation is on the trust zone, and management access is currently allowed from any address on the management interface. Which configuration object should the administrator create and apply to the management interface?
Medium296Refer to the exhibit. A firewall has learned three routes for the 10.0.1.0/24 network. Which route will be used for forwarding traffic destined to 10.0.1.1?
Medium297A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?
Medium298A network administrator is troubleshooting a connectivity issue. The firewall has a security rule that allows traffic from the Trust zone to the Untrust zone for the subnet 192.168.1.0/24 with application 'web-browsing'. However, users in that subnet cannot access any external websites. The administrator checks the logs and sees that the traffic is being blocked by a rule named 'Deny All' that is listed before the allow rule in the policy order. What is the most likely cause of the problem? The rule order is incorrect; the allow rule is below the 'Deny All' rule. The source address object for the allow rule is misconfigured with a wrong subnet mask. The application 'web-browsing' is not being properly identified by App-ID. The User-ID agent is overriding the allow rule and triggering a block action.
Easy299A network engineer is troubleshooting a drop in traffic from a critical application. The traffic is allowed by the security policy, but the firewall is dropping the packets. The engineer views the session log and sees that the session is being terminated due to 'tcp-non-syn'. What is the most likely cause?
Medium300A firewall administrator needs to allow traffic based on the application, not just port. Which type of object should be used in the security policy?
Hard301Two Palo Alto Networks firewalls are deployed in an active/passive high availability pair. The passive firewall does not synchronize configuration changes. What is the most likely cause?
Easy302A network security administrator needs to create a service object that represents a custom application running on TCP port 8443 and UDP port 8443. The administrator wants to ensure that both protocols are matched by a single service object to simplify policy management. Which action should the administrator take?
Medium303A security administrator at a hospital needs to allow clinicians to access a cloud-based electronic health record (EHR) system at ehr.example.com. The firewall must inspect the traffic for threats, but the EHR vendor requires that the firewall not decrypt the traffic due to strict patient data privacy regulations. Which Security policy rule configuration should the administrator implement?
Medium304A security administrator needs to ensure that users cannot upload files containing malware to cloud storage applications. The administrator has enabled SSL decryption and wants to use WildFire to inspect files. Which configuration is required to submit files to WildFire for analysis?
Medium305A company requires automatic daily backups of the firewall configuration. Which method should be used?
Medium306A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal zones. The security team wants to ensure that all traffic from the Users zone to the Servers zone is inspected for threats, but they also need to allow specific applications that use non-standard ports. They create a Security policy rule with 'application: any' and 'service: any', and attach a Vulnerability Protection profile. However, they notice that some traffic is not being inspected because it is being allowed by a more specific rule higher in the rulebase that allows only web-browsing and ssl. What should the administrator do to ensure all traffic is inspected?
Hard307A security administrator is troubleshooting why a security rule that allows traffic from the 'Trust' zone to the 'DMZ' zone is not being matched. The administrator confirms that the source IP, destination IP, and application are correct. The rule is placed at the top of the rulebase. What is the most likely reason the rule is not being hit?
Hard308An administrator creates a dynamic address group named 'prod-servers' configured to match any tag with the value 'production'. After tagging address objects with 'Production' (capital P), the group does not include them. What is the most likely cause?
Medium309A security team notices that custom application 'myapp' is not being identified by App-ID even though the correct application override is in place. What should they verify first?
Hard310An administrator wants to block all peer-to-peer (P2P) file sharing applications while allowing other traffic. Which security policy action should be used to achieve this?
Medium311A security administrator notices that a user's traffic is being blocked unexpectedly. The user's IP is 10.1.1.100, and the traffic is destined to a web server at 192.168.2.10. The administrator has already verified that there are no security rules explicitly denying the traffic. Which Log Viewer query should the administrator use to quickly identify the cause?
Medium312Refer to the exhibit. A firewall administrator is reviewing a Panorama template configuration. What is the purpose of the 'profile' statement under the interface?
Easy313A security administrator is configuring a Palo Alto Networks firewall to send syslog messages to an external syslog server at 203.0.113.10. The syslog server is reachable only through the ethernet1/1 interface, which is in the untrust zone. The administrator has configured the syslog server under Device > Server Profiles > Syslog and attached it to a log forwarding profile. However, syslog messages are not being received by the server. What is the most likely cause?
Hard314Which TWO of the following are methods to identify users for User-ID? (Choose two.)
Medium315A company is migrating from a legacy firewall to a Palo Alto Networks firewall. The legacy policy has many rules with overlapping source and destination objects. Which feature should the administrator use to simplify the policy before migration?
Medium316A firewall is configured with multiple security zones. Traffic from the 'Untrust' zone to the 'DMZ' zone is allowed for web services. The administrator wants to ensure that the DMZ servers cannot initiate connections to the Untrust zone. What is the correct approach?
Easy317Refer to the exhibit. A user reports that they receive a certificate warning when accessing https://example.com. The firewall is configured to decrypt SSL traffic. What is the most likely cause?
Hard318An organization deploys VM-Series firewalls in a public cloud. They need to ensure consistent security policy management across multiple cloud accounts. Which architecture best addresses this requirement?
Hard319An administrator configures a custom App-ID signature using a packet buffer override. What is the implication?
Hard320An administrator manages a PA-3220 running PAN-OS 10.2 with two virtual routers: VR-A for the internal network and VR-B for the internet. The firewall must send SNMP traps, syslog, and email alerts to servers reachable only through VR-B. Which setting directly controls which virtual router the firewall uses to egress that management-plane traffic?
Medium321Drag and drop the steps to configure a User-ID agent on a Palo Alto Networks firewall into the correct order.
Medium322An organization has a security policy that allows all traffic from the corporate user zone to the internet, but they want to block access to social media sites only for a specific group of users in the HR department. What is the best approach?
Hard323A network administrator is configuring a new Palo Alto Networks firewall for the first time. Which THREE initial configuration steps are required to allow basic outbound internet access from the internal network?
Easy324An administrator has created a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web browsing. Users in the Guest zone report that they can access some websites but not others. The administrator checks the traffic logs and sees that some sessions are being denied by the implicit deny rule. What is the most likely reason?
Medium325Refer to the exhibit. An administrator is analyzing the rulebase. Traffic from source 10.1.1.5 to destination 8.8.8.8 using web-browsing application (HTTP TCP/80). Which rule will match?
Medium326A network engineer needs to ensure that all traffic from the 'Guest' zone to the 'Internet' zone is inspected for malware, but also wants to allow high-bandwidth video conferencing traffic to bypass threat inspection for performance reasons. Which approach best achieves this?
Hard327A security administrator wants to block traffic from a specific country using the firewall. How can this be achieved with minimal administrative overhead?
Easy328Your organization has deployed a Palo Alto Networks PA-5250 firewall in a high-availability active/passive configuration. The firewall is connected to two ISPs for redundancy. The internal network uses OSPF with the firewall as an ASBR redistributing a default route. Recently, users reported intermittent connectivity to external resources. During troubleshooting, you notice that the active firewall's management interface has high CPU usage, and the show session all command displays many sessions in the 'active' state but with minimal data transfer. The passive firewall shows no such issues. The OSPF neighbor relationships are stable. What is the most likely cause of the intermittent connectivity?
Hard329A security administrator wants to prevent users from posting sensitive data, such as social security numbers, to web forms on external websites. The administrator has enabled SSL decryption for outbound traffic. Which Content-ID feature should be configured to detect and block this activity?
Medium330A security analyst notices that a legitimate application is being incorrectly identified as a different application by the firewall. What is the best first step to resolve this issue?
Medium331A network security administrator is reviewing the security policy on a Palo Alto Networks firewall. The administrator wants to ensure that traffic from the Trust zone to the Untrust zone is inspected by a specific security profile group. Which policy component should the administrator configure to attach the security profile group?
Easy332A company is implementing SSL Decryption with a forward proxy for outbound traffic. They want to ensure that traffic to sensitive sites like banking is not decrypted. What is the correct configuration?
Hard333A company has a firewall configured with multiple virtual routers. A user on a trusted network can ping the firewall's management IP but cannot reach an external server. The security policy allows the traffic. What is the most likely cause?
Hard334A network administrator wants to allow HTTP and HTTPS traffic from untrust zone to DMZ zone for a web server, but block all other traffic. What is the most efficient way to achieve this with a single rule?
Easy335An administrator has configured a security rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for specific applications. The rule is placed at position 5 in the rulebase. A user reports that traffic matching this rule is being denied. Upon inspection, the administrator finds that a rule at position 3 denies all traffic from 'Trust' to 'Untrust' for any application. What is the most likely cause of the denial?
Medium336An administrator notices that the firewall's time is incorrect. Based on the exhibit, what is the most likely cause?
Medium337A network engineer is configuring a new PA-220 firewall in a small branch office. The firewall must be managed centrally from Panorama. What is the first step after physically installing the firewall?
Medium338Which THREE actions can be performed in a decryption policy? (Choose three.)
Medium339A network security administrator needs to back up the firewall configuration before making changes. The administrator wants to store the backup on an external SCP server at 198.51.100.10 using the account 'backupuser'. Which sequence of steps should the administrator take in the web interface?
Easy340Which THREE factors should be considered when deciding which traffic to decrypt? (Select exactly three.)
Medium341Traffic between two internal zones is being dropped due to a security policy rule that blocks any traffic. However, the administrator needs to allow specific inter-zone traffic for a critical application. The allowed traffic is sourced from a special IP range. How should the administrator configure the security policy to permit only this traffic while still blocking other traffic?
Hard342Refer to the exhibit. An admin reviews the traffic log and sees that traffic from 192.168.1.100 to 10.0.0.50 is allowed by rule 'rule1'. The rule uses a service group 'web-services' which includes 'service-http' and 'service-https'. However, the admin intended to block HTTPS traffic. What is the misconfiguration?
Easy343A security administrator needs to restrict access to the firewall's web management interface to only the IP address 10.1.1.100. The administrator logs into the firewall and navigates to Device > Setup > Management. Which configuration should be modified?
Easy344A security engineer is deploying a PA-5220 firewall in a high-availability active/passive pair. The engineer wants to ensure that the management interface of the passive firewall is reachable for out-of-band management. The firewalls are configured with HA1 and HA2 links. Which statement accurately describes the management interface behavior in this HA configuration?
Hard345Which TWO of the following are true about App-ID? (Choose two.)
Medium346A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)
Medium347An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?
Easy348A network security administrator at a university wants to allow students in the 'Student' zone to access the internet, but only during exam periods should they be blocked from social media. The administrator creates a security rule at the top of the rulebase that denies social media applications from the Student zone to the Internet zone and schedules it to be active only during exam weeks using a schedule object. Which statement correctly describes the evaluation of this rule?
Medium349A medium-sized enterprise has a Palo Alto Networks firewall in your data center. They have recently deployed a new cloud-based CRM system that uses a proprietary protocol over TCP port 8443. The firewall is configured with App-ID enabled, but traffic to the CRM is being incorrectly identified as 'web-browsing' and 'ssl'. Users are able to access the CRM, but the security team wants to ensure that only authorized users can use this application. They have created a custom App-ID signature based on a unique payload pattern in the first packet. However, after applying the signature and committing, the traffic logs still show the application as 'incomplete' or 'web-browsing'. The firewall is running PAN-OS 10.1. What is the most likely reason the custom App-ID is not working?
Medium350Match each Palo Alto Networks feature to its category.
Medium351Which THREE are required for Panorama to manage a firewall? (Select three)
Hard352A security administrator is configuring a Data Filtering profile to prevent sensitive information from leaving the corporate network via web traffic. The administrator wants to detect and block patterns such as credit card numbers and social security numbers in HTTP POST requests. Which two actions can the Data Filtering profile take when a match is found? (Choose two.)
Hard353An organization is planning to deploy SSL decryption for outbound traffic. They want to inspect all traffic from internal users to the internet, but they need to exclude traffic to financial sites for compliance reasons. Which approach should be taken?
Hard354An administrator has configured a security policy rule to allow traffic from the 'trust' zone to the 'untrust' zone with application 'any' and service 'any'. The administrator wants to ensure that the firewall logs all allowed traffic, but notices that not all sessions are being logged. What is the most likely reason?
Hard355A security administrator configures log forwarding to send threat logs to a central SIEM. The administrator creates a log forwarding profile that includes 'threat' and 'traffic' log types, and applies the profile to several security rules. After verifying, the SIEM receives logs for allowed traffic, but does not receive any logs for denied traffic. The administrator confirms that the deny rules also have the same log forwarding profile applied. What is the most likely cause of the missing denied traffic logs? The log forwarding profile is not configured to forward logs for denied sessions. The SIEM is not configured to receive syslog messages for deny actions. The firewall is logging only at session end and the deny sessions are not completing. The log forwarding profile only includes 'traffic' logs and not 'threat' logs.
Medium356Which license is required for the firewall to use URL filtering?
Easy357An administrator has configured a security policy with a rule that allows traffic from the 'Guest' zone to the 'Internet' zone. The rule uses the application 'web-browsing' and 'ssl' with service 'application-default'. Users in the Guest zone report that they cannot access a specific website that uses a non-standard port for HTTPS (port 8443). What is the most likely cause of the issue?
Hard358An administrator needs to deploy a Palo Alto Networks firewall in a location where the network infrastructure does not support routing. The firewall must be transparent to the existing network. Which deployment mode should be used?
Easy359Match each PAN-OS component to its role.
Medium360Which THREE Content-ID components typically require a separate license or subscription?
Easy361What is the primary benefit of using Content-ID in a security policy?
Easy362Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?
Medium363Which of the following is a best practice when configuring an HA (High Availability) pair of Palo Alto Networks firewalls?
Easy364An administrator needs to allow a specific set of external IP addresses to access an internal web server on port 443, but all other traffic to that server must be blocked. The administrator creates a security policy rule that allows the specific IP addresses and places it at the bottom of the rulebase. What will be the result?
Medium365Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)
Hard366Refer to the exhibit. What is the effect of this configuration?
Easy367A company has a Palo Alto Networks firewall with multiple virtual routers. The security policy has a rule that allows SSH from the 'Internal' zone to the 'DMZ' zone. Recently, a new subnet 10.10.20.0/24 was added to the Internal zone. Users in that subnet report they cannot SSH to a server at 192.168.1.10 in the DMZ, while users from other subnets in Internal can. The rule has source address object '10.0.0.0/8' which includes the new subnet. The rule's source zone is Internal, destination zone is DMZ, and application is SSH. The administrator confirms the new subnet's IPs are within 10.0.0.0/8. What is the most likely cause of the problem?
Hard368An administrator is creating a security policy rule that must allow traffic from a group of users who are currently logged into the firewall via GlobalProtect. The administrator wants the rule to automatically include all users who are members of the 'Marketing' group in the directory service. Which type of object should be used in the Source User field of the security policy rule?
Medium369A security administrator is configuring an External Dynamic List (EDL) for IP addresses that will be used in a security policy to block malicious traffic. The EDL is hosted on an internal web server at https://edl.example.com/blocklist. The administrator wants to ensure that the firewall can retrieve the list and that it is updated every hour. Which configuration is required for the EDL to function correctly?
Hard370A security administrator is reviewing the security policy on a PA-220 firewall. The administrator notices that a rule allowing DNS from the 'Trust' zone to the 'Untrust' zone is being shadowed by a rule above it that denies all traffic from 'Trust' to 'Untrust'. What is the term for this situation?
Easy371A security administrator is configuring a rule to allow access to a web application hosted on multiple servers with changing IP addresses. The administrator wants to ensure the rule automatically updates as the IP addresses change, without manual intervention. Which feature should be used?
Hard372Drag and drop the steps to perform a factory reset on a Palo Alto Networks firewall into the correct order.
Medium373A network security administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable only via a specific interface in the 'untrust' zone. The administrator creates a syslog server profile and a log forwarding profile. Which additional configuration is required to ensure that syslog messages are sent from the firewall's interface in the 'untrust' zone?
Hard374An administrator wants to block upload of files with extension .exe to the application 'box-net'. Which security policy component is most appropriate?
Medium375An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?
Hard376Drag and drop the steps to configure a NAT policy on a Palo Alto Networks firewall into the correct order.
Medium377Based on the exhibit, what is the most likely cause if the firewall is dropping new connections but existing sessions continue to work?
Medium378Drag and drop the steps to configure a VLAN interface on a Palo Alto Networks firewall into the correct order.
Medium379Which of the following is a prerequisite for App-ID to identify applications in encrypted traffic?
Medium380A company is using Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection) in their security policies. Malware is still getting through. What is a common misconfiguration that could cause this?
Medium381An administrator is configuring a security rule that allows access from the Trust zone to the DMZ zone for a specific application. The administrator wants to ensure that the rule only allows the application on its default port and blocks the application if it attempts to use a non-standard port. Which setting should be used in the Service column of the security rule?
Hard382A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?
Easy383A small business owner wants to block all social media applications during work hours for employees. The firewall is configured with App-ID and has a security rule that denies the 'social-networking' application category from the internal zone to the internet zone. However, employees are still able to access Facebook and Twitter. The traffic logs show these applications are being allowed by a different rule. The administrator checks the security policy and finds the deny rule for social-networking is present but not matched. What is the most likely reason the deny rule is not being matched?
Easy384A company has a decryption policy that decrypts all traffic except for traffic to financial sites. However, users report that some financial sites are still being decrypted. What should the admin check first?
Medium385A company has a PA-5250 firewall in an active/passive HA pair. During a maintenance window, the administrator upgrades the passive firewall from PAN-OS 10.0 to 10.1. After the upgrade, the passive firewall fails to synchronize with the active firewall. The active firewall remains at 10.0. What is the most likely cause?
HardOther domains
All PCNSA exam domains
Frequently asked questions
- What does the scenario questions domain cover on the PCNSA exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 385 scenario questions questions in the PCNSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.