Courseiva
Back to Palo Alto Networks Certified Network Security Administrator PCNSA questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Palo Alto Networks Certified Network Security Administrator PCNSA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PCNSA
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PCNSA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

A network administrator wants to collect and analyze traffic logs from a Palo Alto firewall. Which two methods can be used? (Choose two.)

Question 2easymulti select
Full question →

An administrator wants to enforce that only certain approved applications can be used on the network. Which TWO features should be configured?

Question 3easymulti select
Full question →

A security administrator is troubleshooting an issue where users cannot access a specific website. The security policy allows web-browsing from the internal zone to the external zone. Which TWO actions should the administrator take to verify the traffic is being matched and allowed?

Question 4mediummulti select
Full question →

Which TWO are best practices for managing security policies in a Palo Alto Networks firewall?

Question 5easymulti select
Full question →

An administrator wants to ensure that traffic from the corporate network to the internet is inspected by the firewall's threat prevention features. Which TWO of the following are required to achieve this? (Choose two.)

Question 6mediummulti select
Full question →

A security administrator is analyzing the rulebase for best practices. Which TWO of the following are recommended practices for security policy management? (Choose two.)

Question 7hardmulti select
Full question →

An administrator is troubleshooting why a policy is not being matched. Which THREE of the following are valid reasons a security rule might not be hit? (Choose three.)

Question 8hardmulti select
Full question →

A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)

Question 9hardmulti select
Full question →

A security engineer is configuring a Palo Alto Networks firewall to protect a web server. The engineer wants to ensure that only HTTP and HTTPS traffic is allowed to the server, and that the traffic is inspected for threats. Which TWO actions should the engineer take?

Question 10mediummulti select
Full question →

A security administrator is reviewing best practices for creating security policies on a Palo Alto Networks firewall. Which two of the following are recommended practices?

Question 11mediummulti select
Full question →

Which TWO of the following are valid methods to bypass URL filtering for internal users while still enforcing it on external traffic?

Question 12mediummulti select
Full question →

Which TWO statements about External Dynamic Lists (EDLs) are true?

Question 13mediummulti select
Full question →

Which THREE actions can be performed in a decryption policy? (Choose three.)

Question 14easymulti select
Full question →

Which TWO security profile types are used to block known malware? (Choose two.)

Question 15easymulti select
Full question →

An administrator needs to block all traffic from a specific application that uses multiple ports. Which TWO methods can achieve this? (Choose two.)

Question 16mediummulti select
Full question →

Which TWO methods can be used to create a custom App-ID signature?

Question 17hardmulti select
Full question →

Which TWO are required for accurate application identification when an application uses non-standard ports?

An administrator wants to configure SNMP traps to send critical events from a firewall to a receiver at 192.168.1.100. Which TWO configuration objects must be created? (Choose two.)

Question 19mediummulti select
Full question →

An administrator needs to create a service group for a custom application that uses TCP ports 1000 and 2000. Which two methods will successfully create a service group that can be used in a single security rule? (Choose two.)

Question 20mediummulti select
Full question →

Which three of the following are valid types of address objects in Palo Alto Networks? (Choose three.)

These PCNSA practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.