Courseiva
← Back to Palo Alto Networks Certified Network Security Administrator PCNSA questions

Scenario-based practice

Hard Difficulty Questions

Practise Palo Alto Networks Certified Network Security Administrator PCNSA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PCNSA
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PCNSA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. A newly deployed web server has an address object with tags 'Production' and 'Web'. However, the 'Allow SSL to Internet' security rule using the dynamic address group 'MyServers' as source is not matching traffic destined to the internet. What is the most likely cause?

Exhibit

admin@PA-5050> show running address-group MyServers
  name: MyServers
  type: dynamic
  filter: "'Production' andd 'Web'"
Question 2hardmulti select
Full question →

Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)

Question 3hardmultiple choice
Full question →

Based on the exhibit, what will happen when a user in the trust zone attempts to access an HTTPS website (TCP 443)?

Exhibit

Refer to the exhibit.

config

security {
    rules {
        rule allow-http {
            source-zone [ trust ];
            destination-zone [ untrust ];
            source-address [ any ];
            destination-address [ any ];
            application [ web-browsing ];
            service [ application-default ];
            action allow;
            log-start yes;
        }
    }
}
Question 4hardmultiple choice
Full question →

An administrator needs to create a security policy that allows access to a set of servers identified by a dynamic address group. The dynamic address group filter is 'WebServer' and 'Production'. The administrator wants to ensure that only servers that have both tags are included. After configuring the tags on the address objects, the administrator notices that some servers with only one of the tags are also being allowed. What is the most likely cause?

Question 5hardmultiple choice
Full question →

A company has a PA-5250 firewall in an active/passive HA pair. During a maintenance window, the administrator upgrades the passive firewall from PAN-OS 10.0 to 10.1. After the upgrade, the passive firewall fails to synchronize with the active firewall. The active firewall remains at 10.0. What is the most likely cause?

Question 6hardmultiple choice
Full question →

An organization implements SSL Forward Proxy to decrypt outbound HTTPS traffic, with a security rule that includes Vulnerability Protection and Anti-Malware profiles. Despite this, certain malware downloaded over HTTPS is not being blocked. The administrator observes that the traffic is decrypted and matches the security rule. The decryption policy excludes decryption for financial services category. The malware is delivered from a known malicious domain that is not in the financial services category. The analysis shows that the malware uses a custom packer that is not recognized by the current Anti-Malware signatures. What is the most likely reason the malware bypasses detection? The decryption exclusion list includes the domain of the malware source. The Anti-Malware profile is set to 'default' which may not block unknown malware effectively. The firewall is missing the latest content updates for WildFire. The security rule uses application 'ssl' but not 'web-browsing' for the traffic.

Question 7hardmultiple choice
Full question →

During an App-ID upgrade, some applications are no longer identified correctly. What is the most likely cause?

Question 8hardmultiple choice
Full question →

A global company uses a Palo Alto Networks firewall at its headquarters. They have a security policy that allows 'web-browsing' and 'ssl' for all users. Recently, they deployed a new custom web application for internal use that runs on TCP port 8443 with SSL. The application is not identified by App-ID as 'web-browsing' or 'ssl', but as 'unknown-tcp'. The security team wants to ensure that only this specific application is allowed, and all other unknown traffic is blocked. They have created a custom App-ID for the application using application override. However, after applying the override, the traffic is still shown as 'unknown-tcp' in logs. What is the most likely reason?

Question 9hardmultiple choice
Full question →

An organization uses App-ID to allow 'web-browsing' but notices that some web traffic is being blocked. The traffic is HTTP over port 8080. What is a likely cause?

Question 10hardmultiple choice
Review the full subnetting walkthrough →

A company has a Palo Alto Networks firewall with multiple virtual routers. The security policy has a rule that allows SSH from the 'Internal' zone to the 'DMZ' zone. Recently, a new subnet 10.10.20.0/24 was added to the Internal zone. Users in that subnet report they cannot SSH to a server at 192.168.1.10 in the DMZ, while users from other subnets in Internal can. The rule has source address object '10.0.0.0/8' which includes the new subnet. The rule's source zone is Internal, destination zone is DMZ, and application is SSH. The administrator confirms the new subnet's IPs are within 10.0.0.0/8. What is the most likely cause of the problem?

Question 11hardmultiple choice
Full question →

A company has two Palo Alto Networks firewalls in an active/passive HA pair (PA-5250) running PAN-OS 10.1. The HA configuration uses dedicated HA1 (control link) and HA2 (data link) interfaces. The network team recently replaced a failed switch that connected the HA1 interfaces. After the switch replacement, the HA pair is not forming. The administrator logs into the active firewall and runs 'show high-availability state' which shows the local state as 'active' and the peer state as 'unknown'. The HA1 interface status shows 'link down'. The administrator checks the physical connections and confirms the cables are connected and the switch ports are up. What is the most likely cause and the best course of action?

Question 12hardmultiple choice
Full question →

An administrator is tasked with centralizing the management of 50 Palo Alto firewalls spread across four geographical regions. The company has a Panorama VM deployed in the data center. Each firewall must receive a common set of security policies and URL filtering profiles, but regional administrators need the ability to add locally required policies. The administrator configures Panorama with device groups: 'Shared' device group for global policies, and four regional device groups (Americas, EMEA, APAC, Oceania). They create a template for basic network settings and use template stacks. After pushing the Device Group and Template configuration, some regional firewalls report that they are not receiving the shared policies. What is the most likely cause?

Question 13hardmultiple choice
Full question →

A firewall administrator is troubleshooting a scenario where outbound HTTPS traffic to a specific website is being blocked. The security rule allows application 'ssl' and service 'application-default'. The URL Filtering profile blocks the category 'hacking'. The administrator confirms the destination URL falls under 'hacking' category. Which action should be taken to allow the traffic while maintaining security?

Question 14hardmultiple choice
Full question →

A company has a security policy rule that allows traffic from the Trust zone to the DMZ zone. The rule includes the application 'ftp' and service 'application-default'. Users can connect to the FTP server but cannot transfer files in passive mode. What is the most likely cause?

Question 15hardmultiple choice
Full question →

Refer to the exhibit. A security engineer observes that SSL decryption is not working for session 1. The policy and session table are shown. What is the most likely reason?

Exhibit

admin@PA-220> show session all
Total sessions: 3

ID   Application      State   Type   Src IP:Port      Dst IP:Port          Protocol   Ingress   Egress
1    ssl              ACTIVE  FLOW   10.0.0.1:44321   192.168.1.100:443     tcp        eth1/1    eth1/2
2    web-browsing     ACTIVE  FLOW   10.0.0.2:53241   192.168.1.200:80      tcp        eth1/1    eth1/2
3    dns              ACTIVE  FLOW   10.0.0.3:45321   8.8.8.8:53            udp        eth1/1    eth1/3

admin@PA-220> show running security-policy
name    from    to      source      destination    application    action   decrypt
POL-1   trust   untrust 10.0.0.0/24 192.168.1.0/24 ssl            allow    forward-proxy
POL-2   trust   untrust 10.0.0.0/24 any             web-browsing   allow    no-decrypt
POL-3   trust   untrust 10.0.0.0/24 any             dns            allow    no-decrypt

admin@PA-220> show decryption statistics
Forward Proxy SSL/TLS Decryption: 0 sessions, 0 bytes decrypted
Question 16hardmulti select
Full question →

Which THREE of the following are valid steps when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?

An administrator is configuring a syslog server that is only reachable through a specific interface, ethernet1/2, which is in the 'dmz' zone. The syslog server IP is 172.16.1.100. To ensure syslog logs are sent via ethernet1/2, which configuration is required?

Question 18hardmultiple choice
Full question →

During a security audit, it is discovered that some internal hosts are using TLS 1.0, which is deprecated. The firewall is configured to decrypt SSL traffic. How can the administrator use the firewall to detect and report these connections without breaking them?

Question 19hardmultiple choice
Full question →

Refer to the exhibit. An administrator notices a large number of decryption sessions. What is a valid conclusion based on the output?

Exhibit

Refer to the exhibit.

# show system info | match decrypt
Decryption status: enabled
Decryption sessions: 523 (current), 1024 (peak)
Certificate errors: 12 (since last hour)

# show decryption statistics
Policy hits: Decrypt: 1500, No Decrypt: 300
TLS version failures: 5 (TLS 1.0: 3, TLS 1.1: 2)
Question 20hardmultiple choice
Full question →

A company has a decryption policy that decrypts all outbound SSL traffic. Recently, users accessing a partner website receive a certificate warning. The partner uses a self-signed certificate. The firewall is configured with a CA-signed certificate for decryption. Which action should the firewall take?

These PCNSA practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.