Courseiva
← Back to Palo Alto Networks Certified Network Security Administrator PCNSA questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Palo Alto Networks Certified Network Security Administrator PCNSA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
PCNSA
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related PCNSA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

An administrator notices that the firewall's time is incorrect. Based on the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit.
```
> show system services status
Service          Status
DNS proxy        running
NTP              stopped
SNMP             running
Syslog           running
```
Question 2easymultiple choice
Full question →

A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?

Exhibit

Refer to the exhibit.

admin@PA-500> show running security-policy

  name                             from             to              source        destination    application     action
  ------------------------------------------------------------------------------------------------------------------
1  allow-web                       trust            untrust         192.168.1.0/24 any            web-browsing    allow
2  block-social                    trust            untrust         192.168.1.0/24 any            social-networking deny
3  allow-all                       trust            untrust         any            any            any             allow
Question 3easymultiple choice
Full question →

Based on the exhibit, what is the role of the rule "Allow_Outbound"?

Exhibit

Refer to the exhibit.
Exhibit: Output from 'show session id 12345':

```
session id 12345
  application: ssl
  source: 192.168.1.10/20000
  destination: 203.0.113.5/443
  zone: inside -> outside
  rule: Allow_Outbound
  decrypted: yes
  decryption profile: Decrypt_Forward
  decrypted-policy: Decrypt_All
```
Question 4mediummultiple choice
Full question →

Refer to the exhibit. The firewall is experiencing performance issues and dropping sessions. Based on the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit.

admin@PA-500> show system info | match uptime
System time: Fri Aug 23 14:22:10 2024
Uptime: 0 days, 2:15:33

admin@PA-500> show system resources
CPU: 45%  Memory: 78%

admin@PA-500> show session info
Total active sessions: 85000
Max sessions: 100000

admin@PA-500> show running resource-monitor
Resource: dataplane
CPU: 89%  Memory: 92%
Question 5mediummultiple choice
Full question →

Refer to the exhibit. A security analyst reviews a traffic log entry in JSON format. Which firewall feature is responsible for including the 'user' field in the log?

Exhibit

{"type":"traffic","subtype":"end","from":"trust","to":"untrust","sourceip":"10.1.1.100","destip":"203.0.113.50","user":"jdoe","action":"allow","bytes_sent":1024,"bytes_received":2048}
Question 6hardmultiple choice
Full question →

Refer to the exhibit. A user reports being unable to connect to a website over HTTPS. The traffic log shows the application as 'incomplete' and the rule 'Block-Unknown-App' is matched. What is the most likely reason the application is 'incomplete'?

Exhibit

Refer to the exhibit.

security-rule show rule-id 1001
  rule-id: 1001
  name: Block-Unknown-App
  from: any
  to: any
  source: any
  destination: any
  application: (none)
  service: application-default
  action: deny
  log-start: yes
  log-end: yes

Traffic log:
  time: 2025-03-15 10:00:00
  src: 10.1.1.10
  dst: 198.51.100.20
  port: 443
  app: incomplete
  rule: Block-Unknown-App
Question 7easymultiple choice
Full question →

Refer to the exhibit. An admin reviews the traffic log and sees that traffic from 192.168.1.100 to 10.0.0.50 is allowed by rule 'rule1'. The rule uses a service group 'web-services' which includes 'service-http' and 'service-https'. However, the admin intended to block HTTPS traffic. What is the misconfiguration?

Exhibit

TRAFFIC log:
  time: 2024/01/01 10:00
  src: 192.168.1.100
  dst: 10.0.0.50
  rule: rule1
  action: allow
  application: web-browsing
  service: service-https
Question 8mediummultiple choice
Full question →

Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?

Exhibit

# show decryption statistics
Decryption failures: 120
  SSL handshake failures: 80
  Certificate validation failures: 40
  Decryption successful: 980
Question 9hardmultiple choice
Full question →

Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?

Exhibit

admin@PA-220> show decryption policy
name             from      to        source           destination        service   action       type
Decrypt-SSH      trust     untrust   10.0.0.0/24      0.0.0.0/0          any       decrypt      ssh-proxy

admin@PA-220> show session all
Total sessions: 1

ID   Application      State   Type   Src IP:Port      Dst IP:Port          Protocol   Ingress   Egress
1    ssh              ACTIVE  FLOW   10.0.0.10:22     192.168.1.50:22       tcp        eth1/1    eth1/2

admin@PA-220> show system log | match ssh
2024-06-15 12:00:00  ssh_decrypt  error  Failed to decrypt SSH session: unsupported key exchange algorithm.  Src: 10.0.0.10 Dst: 192.168.1.50
Question 10hardmultiple choice
Full question →

Refer to the exhibit. What is the default gateway of the firewall?

Exhibit

admin@PA-5000> show routing route

-----------------------------------------
Flags: A: Active, C: Candidate, S: Static, D: Dynamic, R: RIP, O: OSPF

---[Virtual Router default]---

Destination   Next Hop    Interface   Flags
0.0.0.0/0     10.0.0.1    ethernet1/1  A S
10.0.0.0/24   0.0.0.0     ethernet1/1  A C
Question 11mediummultiple choice
Full question →

Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?

Exhibit

> show decryption rule
rule name: Default-No-Decrypt, source: any, dest: any, action: no-decrypt
rule name: Decrypt-Web, source: any, dest: any, action: decrypt, profile: strict
Question 12easymultiple choice
Full question →

Refer to the exhibit. What is the effect of this configuration?

Exhibit

<devices>
  <name>PA-220</name>
  <vlan>none</vlan>
  <ip>10.0.0.1/24</ip>
  <management-profile>allow-ping</management-profile>
</devices>
Question 13mediummultiple choice
Full question →

Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?

Exhibit

1. 2023/08/15 10:30:45, info, ssl-decrypt, session 12345, Decryption failed: certificate validation error: certificate is not yet valid
Question 14mediummultiple choice
Full question →

Refer to the exhibit. The firewall is currently running PAN-OS 9.1.4. The administrator wants to upgrade to the latest available version shown. What should the administrator do first?

Exhibit

Refer to the exhibit.

admin@PA-220> show system info
System info:
Hostname: PA-220
Model: PA-220
Serial: 0123456789
Software version: 9.1.4
Operating mode: normal
Uptime: 10 days, 5 hours, 23 mins

admin@PA-220> show system software status
PAN-OS version: 9.1.4
Installed packages: none
Latest available: 9.1.7
Question 15easymultiple choice
Full question →

Based on the exhibit, what action did the firewall take on this traffic?

Exhibit

Refer to the exhibit.

2023/07/25 14:35:12,THREAT,url,1,2023/07/25 14:35:12,192.168.1.10,203.0.113.5,192.168.1.10,203.0.113.5,allow,,,web-browsing,vsys1,trust,untrust,ethernet1/1,ethernet1/2,2012,1,1,45,2023/07/25 14:35:12,0,any,0,2621440000,10.0.0.1,0,0,0,0,,PA-5250,from-policy,,,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0

Note: The log entry is truncated for readability.

These PCNSA practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.