Courseiva

CCNA Device Mgmt Services Questions

75 of 78 questions · Page 1/2 · Device Mgmt Services topic · Answers revealed

1
MCQhard

A company is deploying multiple Palo Alto firewalls and wants to manage them centrally. Which method should be used?

A.Use Panorama
B.Use CLI scripts
C.Use a dedicated management server
D.Use SNMP
AnswerA

Panorama provides centralised policy and device management for multiple Palo Alto firewalls, satisfying the requirement to manage them centrally. It pushes shared policies, objects and software updates from one console, unlike managing each firewall individually via its own web interface. This directly meets the stem's multi-firewall central management constraint.

Why this answer

Panorama is the centralized management solution for Palo Alto Networks firewalls, providing a single pane of glass for policy management, log aggregation, and device configuration across multiple firewalls. It uses a dedicated management plane that communicates with firewalls via the management interface (MGT) or in-band using IPsec tunnels, ensuring consistent policy enforcement and simplified administration.

Exam trap

The trap here is that candidates often confuse centralized management with generic monitoring tools like SNMP or assume any dedicated server can replace Panorama, but only Panorama provides the full suite of centralized policy management, log collection, and device orchestration specific to Palo Alto firewalls.

How to eliminate wrong answers

Option B is wrong because CLI scripts are used for automation on individual firewalls but lack centralized visibility, log aggregation, and policy conflict detection that Panorama provides. Option C is wrong because a dedicated management server is a generic concept; Palo Alto Networks specifically requires Panorama (physical or virtual appliance) for centralized management, not any generic server. Option D is wrong because SNMP is a monitoring protocol for reading device statistics and sending traps, not for managing firewall policies or configurations centrally.

2
MCQmedium

An administrator needs to generate a report showing all applications used by a specific user group over the past week. Which method is most efficient?

A.Export Traffic logs to CSV and analyze in Excel
B.Use the Top Applications report in the Reports tab
C.Use the ACC (Application Command Center) and filter by user group and time range
D.Use the Monitor tab's Session Browser with a filter for the user group
AnswerC

The ACC aggregates application, user, and threat data with native filtering by user group and time range, delivering the report directly from existing logs. This avoids exporting raw traffic logs or building custom queries, making it the most efficient method for this specific reporting need.

Why this answer

The ACC (Application Command Center) is purpose-built for rapid application visibility and analysis. By filtering by user group and time range directly within the ACC, the administrator can instantly see the top applications used by that group without exporting or manually parsing logs, making it the most efficient method for this specific reporting need.

Exam trap

The trap here is that candidates confuse the Session Browser (for live sessions) with the ACC (for historical application analytics), or assume that exporting logs to Excel is a valid 'efficient' method, when Cisco tests the understanding that the ACC is the dedicated tool for application-centric reporting.

How to eliminate wrong answers

Option A is wrong because exporting Traffic logs to CSV and analyzing in Excel is inefficient and manual; it requires extra steps and lacks real-time filtering by user group. Option B is wrong because the Top Applications report in the Reports tab is a static, scheduled report that cannot be dynamically filtered by a specific user group for an ad-hoc time range. Option D is wrong because the Monitor tab's Session Browser is designed for real-time session monitoring and troubleshooting, not for generating a historical summary report of applications used over a past week.

3
MCQmedium

An administrator needs to allow administrators to authenticate to the firewall's web interface using an external LDAP directory at ldap.corp.example.com, while still allowing a local break-glass account. The directory uses a bind DN of cn=svc-bind,ou=service,dc=corp,dc=example,dc=com. After configuring the LDAP server profile under Device > Server Profiles > LDAP, authentication still fails for directory users. Which additional step is required?

A.Add the LDAP server to the firewall's DNS server list under Device > Setup > Services so the hostname ldap.corp.example.com resolves for authentication.
B.Enable 'LDAP Authentication' under Device > Setup > Management > Management Interface Settings to activate directory logins for the web UI.
C.Import the LDAP server's root CA certificate under Device > Certificate Management so the firewall can validate the bind DN.
D.Create an authentication profile that references the LDAP server profile and assign it to the management interface under Device > Setup > Management > Authentication Settings.
AnswerD

An LDAP server profile defines how to reach the directory, but it does not by itself enable authentication. An authentication profile binds the server profile to a login method and can include an allow list of permitted groups. Assigning that authentication profile to the management interface activates directory logins for the web UI while preserving local accounts for break-glass access.

Why this answer

LDAP authentication on PAN-OS requires two objects: a server profile describing the directory connection, and an authentication profile that references it and defines the login method and permitted groups. Assigning the authentication profile to the management interface enables directory logins for the web UI. Local accounts remain available unless explicitly disabled, which preserves break-glass access.

Exam trap

The trap here is assuming that defining an LDAP server profile is sufficient to enable directory logins, when an authentication profile must also be created and applied.

4
Multi-Selecthard

A company is deploying a PA-220 firewall in a branch office. The firewall will be managed by Panorama. Which THREE of the following are required to establish a successful connection between the firewall and Panorama?

Select 3 answers
A.Configuration of the Panorama IP address on the firewall
B.DNS resolution for the Panorama hostname
C.A valid Panorama auth key on the firewall
D.A DHCP server to assign an IP to the management interface
E.Network connectivity between the firewall and Panorama
AnswersA, C, E

The firewall needs to know where to connect.

Why this answer

The firewall must be configured with the Panorama IP address (or hostname) to initiate the management connection. This is typically done via the Panorama tab in the web interface or CLI using the 'set deviceconfig system panorama-server <IP>' command. Without this configuration, the firewall does not know where to send its registration and operational data.

Exam trap

The trap here is that candidates often assume DNS resolution is mandatory for Panorama connectivity, but it is only needed if the Panorama server is specified by hostname rather than IP address.

5
MCQmedium

An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The firewall has two virtual routers: VR1 for the internal network and VR2 for the internet. The syslog server is reachable only through VR1. Which configuration setting must be applied to ensure syslog messages are sent via VR1?

A.Under Device > Server Profiles > Syslog, set the virtual router to VR1 for the syslog server profile.
B.In the log forwarding profile, configure the syslog server to use VR1 as the source interface.
C.Create a static route in VR1 for the syslog server IP address and ensure the firewall uses the management interface for logging.
D.In the syslog server profile, specify the source address as an interface in VR1, and ensure a route exists in VR1 for the syslog server.
AnswerD

The syslog server profile allows you to specify a source address (an interface or IP) that the firewall uses when sending syslog messages. By selecting an interface that belongs to VR1, the outgoing packets will be routed via VR1. Additionally, a route must exist in VR1 for the syslog server. This option correctly addresses the requirement.

Why this answer

To force syslog traffic through a specific virtual router, you must specify a source address in the syslog server profile that belongs to that virtual router. The firewall then uses that source address for outgoing syslog packets, and the virtual router associated with that interface will handle routing. This ensures the syslog server is reached via the intended path.

Exam trap

The trap here is assuming that the log forwarding profile can select a virtual router, when in fact the source address in the syslog server profile determines the egress virtual router.

6
MCQhard

A firewall administrator needs to ensure that the firewall can resolve domain names for security policy rules that use FQDN objects. The firewall is deployed in a network where DNS servers are reachable only through the dataplane interface ethernet1/2, which is in the untrust zone. The management interface cannot reach any DNS server. Which configuration should the administrator use to allow the firewall to resolve FQDNs?

A.Create a service route for DNS that uses the dataplane interface ethernet1/2, and specify the DNS servers in Device > Setup > Services > DNS.
B.Configure a DNS proxy object and assign it to the untrust zone, then set the DNS servers in Device > Setup > Services > DNS.
C.Configure a static route on the management interface to the DNS servers, and set the DNS servers in Device > Setup > Services > DNS.
D.Enable DNS resolution on the untrust zone interface and set the DNS servers in Device > Setup > Services > DNS.
AnswerA

Service routes allow management-plane services, including DNS, to use a dataplane interface instead of the management interface. By creating a service route for DNS via ethernet1/2 and configuring the DNS servers, the firewall can resolve FQDNs through the dataplane, satisfying the requirement when the management interface lacks DNS reachability.

Why this answer

Service routes allow specific management-plane services (such as DNS, email, SNMP, syslog, etc.) to be sourced from a dataplane interface instead of the management interface. By configuring a service route for DNS that uses ethernet1/2, and specifying the DNS servers, the firewall can send DNS queries out the dataplane interface, which has reachability to the DNS servers. This enables FQDN resolution for security policies even when the management interface cannot reach DNS.

Exam trap

The trap here is assuming that DNS resolution for the firewall always uses the management interface, overlooking the service route capability that redirects DNS traffic through a dataplane interface.

7
Multi-Selecthard

An administrator wants to schedule regular configuration backups to an external server. Which THREE methods are valid ways to achieve this? (Choose three.)

Select 3 answers
A.Use a script that logs in via SSH and runs 'save config to scp/tftp'
B.Use the CLI command 'request system backup config schedule'
C.Configure a scheduled backup via the web UI under Device > Setup > Operations
D.Set a recurring cron job via the firewall's built-in cron
E.Use Panorama to schedule backups for managed firewalls
AnswersA, C, E

Correct: External scripts can perform backups manually.

Why this answer

The firewall supports saving configuration backups to external servers via SCP or TFTP using the 'save config to scp/tftp' CLI command. This method can be automated by wrapping the command in a script that runs on an external scheduler (e.g., cron on a Linux host), which then connects to the firewall via SSH to execute the backup. This is a valid, albeit indirect, way to schedule regular backups.

Exam trap

The trap here is that candidates may assume the firewall has a native CLI command to schedule backups (Option B) or that the built-in cron is user-configurable (Option D), when in fact PAN-OS restricts scheduling to the web UI and Panorama to maintain security and consistency.

8
MCQeasy

An administrator modifies a security policy but the change does not take effect. What must the administrator do?

A.Commit the configuration.
B.Import the configuration.
C.Save the configuration.
D.Reboot the firewall.
AnswerA

Palo Alto Networks firewalls use a candidate configuration; policy edits stay pending until committed to the running configuration. Committing pushes the modified security policy into enforcement, which is why the change appeared ineffective beforehand. Without a commit, the firewall continues evaluating traffic against the previous ruleset.

Why this answer

In Palo Alto Networks firewalls, configuration changes are made in a candidate configuration that is not active until explicitly committed. The administrator must commit the configuration to apply the changes to the running configuration and enforce the new security policy. Without a commit, the modification remains pending and does not affect traffic.

Exam trap

Palo Alto Networks often tests the misconception that saving a configuration (e.g., via 'save config' or clicking Save) is sufficient to apply changes, but in Palo Alto firewalls, a commit is mandatory to move changes from candidate to active state.

How to eliminate wrong answers

Option B is wrong because importing a configuration is used to load a configuration file from an external source, not to apply pending changes. Option C is wrong because saving the configuration in the GUI or CLI only stores the candidate configuration to persistent storage but does not activate it; a commit is still required. Option D is wrong because rebooting the firewall would cause downtime and does not apply uncommitted changes; the candidate configuration would be lost if not saved, and even if saved, a commit is still necessary to activate it.

9
MCQmedium

A security administrator at a branch office needs to allow a remote vendor to access the firewall's web management interface only from IP address 203.0.113.50. The firewall's management interface is in the Management zone. Which Palo Alto Networks feature should the administrator use to restrict access?

A.Configure an Interface Management Profile with HTTPS allowed and permitted IP addresses set to 203.0.113.50, then apply it to the management interface.
B.Create a Security policy rule allowing traffic from 203.0.113.50 to the Management zone on port 443.
C.Configure an authentication profile that requires the vendor to authenticate with a certificate before accessing the web UI.
D.Add a static route for 203.0.113.50 pointing to the management interface.
AnswerA

An Interface Management Profile controls which management services (HTTP, HTTPS, SSH, etc.) are enabled on an interface and restricts access to specified IP addresses. Applying it to the management interface with HTTPS allowed and permitted IP 203.0.113.50 ensures only that source can reach the web UI, directly meeting the requirement.

Why this answer

The Interface Management Profile is the correct tool because it explicitly enables management services on an interface and can restrict them to specific source IP addresses. Applying it to the management interface with HTTPS enabled and the vendor's IP permitted ensures only that address can reach the web UI. Other options either do not affect management plane access or address routing/authentication rather than IP-based restriction.

Exam trap

The trap here is assuming that Security policy rules control access to the firewall's management interface, when actually management access is governed by Interface Management Profiles.

10
MCQmedium

An administrator configures SNMP monitoring on a firewall but receives no data from the SNMP manager. Which check should be performed first?

A.Check that the SNMP manager supports SNMPv3
B.Verify that the firewall's management IP is reachable from the SNMP manager
C.Ensure the SNMP manager is running on the same subnet as the firewall
D.Verify the SNMP community string and allowed management IPs in the SNMP server profile
AnswerD

SNMPv3 aside, v1/v2c authentication relies solely on the community string, and the firewall only answers managers whose source IP is in the permitted list. A wrong string or missing manager address silently drops polls, producing exactly the no-data symptom, so verifying both in the server profile is the fastest first check.

Why this answer

The most common cause of SNMP monitoring failure after initial configuration is a mismatch in the SNMP community string (for SNMPv2c) or authentication credentials, or the SNMP manager's IP not being permitted in the SNMP server profile. The SNMP server profile on the firewall explicitly defines which community strings and manager IPs are allowed to poll the device. If these are incorrect, the firewall will silently drop SNMP requests, even if network connectivity is fine.

Exam trap

The trap here is that candidates often assume the problem is network connectivity (Option B) or subnet mismatch (Option C), but the PCNSA exam emphasizes that SNMP-specific configuration errors—especially the community string and allowed IP list—are the most frequent first-check items.

How to eliminate wrong answers

Option A is wrong because the question does not specify which SNMP version is configured; checking manager support for SNMPv3 is irrelevant if the firewall is using SNMPv2c or if the issue is a community string mismatch. Option B is wrong because basic IP reachability is a lower-layer check that should be performed after verifying the SNMP-specific configuration, as the firewall may still drop SNMP packets even if pingable. Option C is wrong because SNMP managers can poll firewalls across different subnets via routed networks; there is no requirement for them to be on the same subnet.

11
MCQeasy

A network engineer wants to configure a new VLAN interface on a Palo Alto Networks firewall. After creating the VLAN object and assigning it to an Ethernet interface, the VLAN interface remains down. What is the most likely cause?

A.The VLAN interface needs an IP address configured
B.The VLAN interface must be assigned to a virtual router
C.The firewall needs a commit to apply the changes
D.The Ethernet interface is not set to layer 2 mode or the VLAN tag is not allowed
AnswerD

A Palo Alto VLAN interface only comes up when its parent Ethernet interface is configured as layer 2 and the VLAN tag is permitted on that interface. Without layer 2 mode or an allowed tag, the VLAN object has no traffic path, leaving the interface down.

Why this answer

For a VLAN interface to be operational on a Palo Alto Networks firewall, the underlying Ethernet interface must be configured in Layer 2 mode and the specific VLAN tag must be allowed on that interface. If the Ethernet interface remains in Layer 3 mode or the VLAN tag is not included in the allowed list, the VLAN interface will remain administratively down, as it cannot associate with a physical port that is not set to accept VLAN traffic.

Exam trap

The trap here is that candidates often assume a VLAN interface only needs an IP address or a virtual router assignment to come up, overlooking the prerequisite that the parent Ethernet interface must be in Layer 2 mode with the VLAN tag allowed.

How to eliminate wrong answers

Option A is wrong because a VLAN interface can be created without an IP address and still be administratively up; an IP address is only required for routing or management access, not for the interface to come up. Option B is wrong because assigning a VLAN interface to a virtual router is necessary for Layer 3 forwarding, but the interface will still show as down if the underlying Ethernet port is not in Layer 2 mode or the VLAN tag is not allowed. Option C is wrong because while a commit is required to make configuration changes permanent, the VLAN interface will remain down even after a commit if the Ethernet interface is not properly configured for VLAN tagging.

12
MCQmedium

A company has two PA-220 firewalls in active/passive HA. They want to ensure that if the active firewall loses internet connectivity but its management interface remains up, a failover occurs. Which monitoring method should be configured?

A.Path monitoring.
B.Heartbeat backup.
C.Session replication.
D.Link monitoring on all interfaces.
AnswerA

Path monitoring sends ICMP pings to defined destination IP addresses, so loss of upstream reachability triggers failover even while the management interface stays up. This satisfies the stem's constraint that internet connectivity loss, not interface state, must drive the active/passive PA-220 failover.

Why this answer

Path monitoring is the correct method because it monitors the dataplane connectivity to specific destination IP addresses (e.g., the internet gateway) and triggers a failover when those paths become unreachable, even if the management interface remains up. This ensures that the active firewall fails over based on actual data traffic path health, not just link or management status.

Exam trap

The trap here is that candidates often confuse 'link monitoring' (which only checks local interface status) with 'path monitoring' (which checks end-to-end connectivity to a remote target), leading them to select link monitoring when the question explicitly requires detection of internet connectivity loss beyond the first hop.

How to eliminate wrong answers

Option B (Heartbeat backup) is wrong because heartbeat backup refers to the HA control link used for state synchronization and peer liveness detection, not for monitoring external path connectivity. Option C (Session replication) is wrong because session replication is a mechanism to mirror active sessions to the passive firewall for stateful failover, not a monitoring method to detect path loss. Option D (Link monitoring on all interfaces) is wrong because link monitoring only detects physical link state changes (up/down) on local interfaces, not the loss of internet connectivity beyond the first hop.

13
MCQhard

An organization needs to send threat logs to two different syslog servers: one for real-time alerts and one for long-term storage. They also need to send traffic logs to the long-term storage syslog only. They have configured two syslog server profiles. What is the correct approach?

A.Create two separate log forwarding profiles, one for threat logs with both syslog profiles, and one for traffic logs with only the long-term storage profile.
B.Use the default log forwarding settings and configure the syslog servers globally.
C.Create a single log forwarding profile with both syslog profiles and assign it to all rules.
D.Configure each firewall rule to specify which syslog server to send logs to.
AnswerA

Separate log forwarding profiles let each log type target distinct syslog servers. Threat logs reference both profiles for real-time alerting and archival, while traffic logs reference only the long-term profile, satisfying the selective routing requirement without duplicating server configuration.

Why this answer

Palo Alto Networks firewalls use separate log forwarding profiles to control which logs are sent to which syslog servers. By creating two profiles—one for threat logs that includes both syslog server profiles (real-time and long-term storage) and one for traffic logs that includes only the long-term storage profile—the organization can selectively route logs to meet their requirements. This approach leverages the firewall's ability to assign different log forwarding profiles to different log types, ensuring granular control over log distribution.

Exam trap

The trap here is that candidates often assume a single log forwarding profile can be assigned to multiple log types with different server destinations, but Palo Alto requires separate profiles to achieve selective routing, as a single profile applies all its servers to all logs it covers.

How to eliminate wrong answers

Option B is wrong because the default log forwarding settings do not allow selective routing to multiple syslog servers; they apply a single global configuration that cannot differentiate between log types or servers. Option C is wrong because a single log forwarding profile with both syslog profiles would send both threat and traffic logs to both servers, failing the requirement to send traffic logs only to long-term storage. Option D is wrong because firewall rules do not directly specify syslog servers; log forwarding is configured via log forwarding profiles, not per-rule syslog server assignments.

14
MCQhard

A network security engineer is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable only through the untrust zone via the ethernet1/2 interface, which is in the untrust zone and uses the default virtual router. The engineer wants to ensure that syslog traffic egresses via ethernet1/2 and uses the correct source IP address. Which configuration should the engineer perform?

A.Enable 'Use management interface for all services' under Device > Setup > Management and add a policy-based forwarding rule for syslog traffic.
B.Configure a static route for the syslog server's IP address pointing to ethernet1/2 and set the source IP in the syslog server profile.
C.Create a security policy rule allowing syslog traffic from the trust zone to the untrust zone and apply a NAT rule to translate the source IP to ethernet1/2.
D.Configure a Syslog service route under Device > Setup > Services > Service Route Configuration, selecting the 'custom' option for Syslog and specifying the source interface as ethernet1/2.
AnswerD

Service routes determine the source interface and source IP address for outbound services like Syslog, SNMP, and email. By default, these services use the management interface. Configuring a custom service route for Syslog with ethernet1/2 as the source interface ensures that syslog packets are sent from that interface's IP address and routed via the associated virtual router, meeting the requirement.

Why this answer

Syslog is an outbound management service, and its source interface is controlled by service routes. By default, it uses the management interface. To send syslog via ethernet1/2, a custom service route must be configured for Syslog, specifying ethernet1/2 as the source interface.

Security policies, NAT, and static routes do not affect firewall-generated syslog traffic, so they cannot fulfill the requirement.

Exam trap

The trap here is assuming that security policy or routing changes affect firewall-generated traffic, when in fact management services like syslog require service route configuration.

15
MCQmedium

A firewall is configured with multiple Virtual Systems (vsys). An admin wants to assign a custom admin role that can manage only specific vsys. Which role type supports this?

A.Panorama Admin
B.Read Only Admin
C.Virtual System Admin
D.Superadmin
E.Device Admin
AnswerC

A Virtual System Admin role is scoped to specific vsys, granting administrative access limited to those virtual systems rather than the whole firewall. This directly satisfies the requirement to manage only particular vsys, unlike a superuser or device-level role.

Why this answer

The Virtual System Admin role is specifically designed to grant administrative access to one or more Virtual Systems (vsys) within a Palo Alto Networks firewall. This role type allows the admin to manage only the assigned vsys, with no visibility or control over other vsys or the shared firewall configuration, which directly matches the requirement in the question.

Exam trap

The trap here is that candidates often confuse 'Virtual System Admin' with 'Device Admin' or 'Read Only Admin,' assuming that any admin role can be scoped to a vsys, but only the Virtual System Admin role provides the granular per-vsys restriction required.

How to eliminate wrong answers

Option A is wrong because Panorama Admin is a role used for managing Panorama, the centralized management platform, not for assigning per-vsys administrative access on a firewall. Option B is wrong because Read Only Admin provides read-only access to the entire firewall configuration, including all vsys, and cannot be scoped to specific vsys. Option D is wrong because Superadmin has full, unrestricted access to all vsys and all firewall settings, which is the opposite of the required restricted access.

Option E is wrong because Device Admin is a role that manages device-level settings (e.g., network interfaces, certificates) across all vsys, not limited to specific vsys.

16
MCQhard

An administrator wants to allow ping (ICMP) and SSH access on a data interface (e.g., ethernet1/1) for troubleshooting. Which configuration is required?

A.Enable 'Management' profile on the VLAN interface
B.Configure an interface management profile on ethernet1/1
C.Create a security policy allowing ICMP and SSH inbound
D.Enable the service route for ping and SSH
AnswerB

An interface management profile defines which management services, such as ping and SSH, are permitted on that specific data interface. Without it, management traffic is blocked by default on dataplane interfaces, so attaching the profile to ethernet1/1 is the required step to allow troubleshooting access.

Why this answer

Interface management profiles control which management services (ping, SSH, HTTP, etc.) are permitted on a data interface.

17
MCQeasy

A company needs to receive email alerts for critical system events. What is the recommended method to configure email notifications on a Palo Alto Networks firewall?

A.Create an Email server profile under Device > Server Profiles with SMTP settings
B.Configure an SNMP trap receiver to forward events to email
C.Enable ICMP echo replies to trigger email via a separate scripting tool
D.Set up a syslog server that sends email alerts
AnswerA

An Email server profile under Device > Server Profiles supplies the SMTP server, port, sender and authentication details that the firewall's log-forwarding and alerting engine uses to dispatch event notifications. Without this profile, no email alerting path exists.

Why this answer

Palo Alto Networks firewalls provide a native Email Server Profile under Device > Server Profiles that allows direct SMTP configuration for sending email alerts. This is the recommended method as it integrates directly with the firewall's alerting system without requiring external tools or services.

Exam trap

The trap here is that candidates may confuse syslog or SNMP as direct email notification methods, but Palo Alto Networks firewalls require a dedicated Email Server Profile for native SMTP-based alerting, and other methods like syslog or SNMP need additional infrastructure to generate emails.

How to eliminate wrong answers

Option B is wrong because SNMP trap receivers forward traps to an SNMP manager, not directly to email; they require additional translation or middleware to convert traps into email messages, which is not a recommended or native method. Option C is wrong because ICMP echo replies are a network diagnostic tool and have no mechanism to trigger email alerts; this would require a separate scripting tool and is not a supported configuration on the firewall. Option D is wrong because syslog servers forward log messages to a centralized logging system, but they do not natively send email alerts; additional configuration or a separate email gateway would be needed to convert syslog messages into emails.

18
MCQhard

A syslog server is only reachable through a specific interface on the firewall. To ensure syslog logs are sent via that interface, which configuration is required?

A.Configure a static route for the syslog server IP
B.Set up a service route for syslog
C.Enable NAT on the syslog traffic
D.Use policy-based forwarding for syslog traffic
AnswerB

A service route forces traffic originating from the firewall itself, such as syslog, to egress a specified interface rather than following the routing table. This satisfies the constraint that syslog must be sent via a particular interface.

Why this answer

Service routes in Palo Alto Networks firewalls allow you to specify which source interface or IP address is used for outbound traffic from the firewall itself, such as syslog, SNMP, or authentication. By configuring a service route for syslog, you ensure that syslog messages are sourced from the specific interface that can reach the syslog server, even if the routing table would otherwise choose a different path.

Exam trap

The trap here is that candidates often confuse service routes with static routes or policy-based forwarding, assuming that any routing change will fix the source interface issue, but service routes are the only mechanism that controls the source interface for firewall-originated traffic.

How to eliminate wrong answers

Option A is wrong because configuring a static route for the syslog server IP only influences the path taken by packets destined to that server, but does not control the source interface or source IP used by the firewall when sending syslog messages; the firewall may still use a different source interface based on its default route or management interface. Option C is wrong because enabling NAT on syslog traffic would translate the source IP address but does not guarantee that traffic egresses through a specific interface; NAT operates after the routing decision and does not force interface selection. Option D is wrong because policy-based forwarding (PBF) is used to override routing decisions for traffic passing through the firewall (transit traffic), not for traffic originated by the firewall itself, such as syslog logs.

19
Multi-Selectmedium

An administrator is configuring a Palo Alto Networks firewall to send SNMP traps to a monitoring server at 10.1.1.50. The administrator has already configured the SNMP community string under Device > Setup > Operations > SNMP Setup. Which two additional configurations are required to ensure traps are sent successfully? (Choose two.)

Select 2 answers
A.Configure an SNMP trap destination under Device > Setup > Operations > SNMP Setup, specifying the server IP 10.1.1.50 and the community string.
B.Configure a service route for SNMP under Device > Setup > Services > Service Route Configuration to use an interface that can reach 10.1.1.50.
C.Enable SNMPv3 and configure a user with authentication and encryption, because SNMPv2c traps are not supported.
D.Create a security policy rule allowing SNMP traffic from the firewall to the monitoring server on UDP port 162.
E.Add the monitoring server's IP address to the management interface's permitted IP list for SNMP.
AnswersA, B

SNMP trap destinations must be explicitly defined under Device > Setup > Operations > SNMP Setup. The trap destination includes the server IP address and the community string. Without this, the firewall will not know where to send traps, even if the community string is configured for polling. This is a required step to enable trap delivery to the monitoring server.

Why this answer

To send SNMP traps, the firewall must have a trap destination configured with the server IP and community string. Additionally, a service route for SNMP may be needed if the default management interface cannot reach the server. Security policy rules and management interface permitted IPs do not affect outbound traps, and SNMPv3 is optional.

Thus, the trap destination and service route are the required configurations.

Exam trap

The trap here is thinking that security policy or permitted IP lists control outbound SNMP traps, when they actually govern inbound polling or dataplane traffic.

20
MCQeasy

A company wants to deploy a new firewall with a management interface on a separate VLAN to ensure management traffic is isolated from production traffic. Which interface type should be used for management access?

A.HA1 interface
B.VLAN interface
C.Ethernet 1/1
D.MGT (Management) interface
AnswerD

The MGT interface carries management-plane traffic only, so placing it on a dedicated VLAN isolates administrative access from production data flows. This satisfies the stem's isolation requirement, unlike dataplane or HA interfaces that serve traffic forwarding.

Why this answer

The MGT (Management) interface is a dedicated physical port on Palo Alto Networks firewalls designed specifically for out-of-band management traffic. It operates on a separate routing table and does not participate in production data forwarding, ensuring complete isolation of management traffic from production traffic as required by the scenario.

Exam trap

The trap here is that candidates often confuse the MGT interface with a standard data interface (like Ethernet 1/1) or a logical VLAN interface, assuming any interface can be used for management if an IP address is assigned, but the PCNSA emphasizes the need for out-of-band management isolation via the dedicated MGT port.

How to eliminate wrong answers

Option A is wrong because the HA1 interface is used exclusively for firewall high-availability control plane synchronization (heartbeat and session state), not for general management access. Option B is wrong because a VLAN interface is a logical Layer 3 interface that routes production traffic within a VLAN, and it does not provide out-of-band management isolation; using it would mix management and production traffic. Option C is wrong because Ethernet 1/1 is a standard data port that forwards production traffic and can be configured for in-band management, but it does not offer the dedicated, isolated management plane that the MGT interface provides.

21
Multi-Selecteasy

Which three of the following services are commonly permitted on the management interface? (Choose three.)

Select 3 answers
B.Ping
E.SSH
AnswersB, C, E

Ping is commonly permitted for network reachability testing.

Why this answer

Ping (ICMP Echo) is commonly permitted on the management interface because it allows network administrators to verify the interface's reachability and responsiveness without exposing management services to unnecessary risk. While ICMP is not a management protocol per se, it is a fundamental troubleshooting tool that is typically allowed on the management plane to test connectivity to the management IP address.

Exam trap

Palo Alto Networks often tests the misconception that HTTP and Telnet are acceptable for management access because they are 'simpler' or 'legacy' protocols, but the PCNSA exam emphasizes that only encrypted protocols (HTTPS, SSH) and basic troubleshooting (ping) are permitted on the management interface.

22
Multi-Selectmedium

An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The syslog server is reachable via a specific interface and virtual router. Which two configurations are required to ensure that syslog messages are sent from the correct source interface? (Choose two.)

Select 2 answers
A.Configure a Syslog Server Profile and assign it to the appropriate log forwarding settings.
B.Configure a service route for the syslog service to use the desired source interface.
C.Specify the source interface in the Syslog Server Profile.
D.Enable syslog on the management interface via an Interface Management Profile.
E.Create a Security policy rule allowing syslog traffic from the firewall to the syslog server.
AnswersA, B

A Syslog Server Profile defines the server address, port, and format. Assigning it to log forwarding settings (e.g., under Device > Log Settings) ensures that logs are sent to the external server. Without this profile, no logs are forwarded. This is a fundamental step for external logging.

Why this answer

To send logs to an external syslog server, you must configure a Syslog Server Profile and apply it to log forwarding settings. To control the source interface used for syslog messages, you must configure a service route for the syslog service, specifying the desired interface and virtual router. These two steps ensure that logs are sent from the correct interface.

Security policies and Interface Management Profiles do not influence syslog source interface selection.

Exam trap

The trap here is thinking that the Syslog Server Profile includes a source interface setting, when actually the source interface is controlled via service routes.

23
MCQeasy

An administrator wants to synchronize the firewall's clock with a central NTP server. Where is this configured?

A.Under Objects > Regions
B.Under Device > Setup > Services, NTP tab
C.Under Device > Licenses
D.Under Network > Interfaces, Management Interface
AnswerB

NTP server settings live under Device > Setup > Services on the NTP tab, where the administrator adds the central server address. This satisfies the requirement to synchronise the firewall clock with a central time source.

Why this answer

NTP (Network Time Protocol) client configuration on a Palo Alto Networks firewall is performed under Device > Setup > Services, where the NTP tab allows you to specify primary and secondary NTP servers. This synchronizes the firewall's system clock, which is critical for accurate log timestamps, certificate validation, and security policy enforcement. The firewall acts as an NTP client, sending periodic NTP requests (typically using UDP port 123) to the configured servers.

Exam trap

The trap here is that candidates often confuse the management interface IP configuration (Network > Interfaces) with NTP settings, or they mistakenly think NTP is part of license management or object definitions, but Palo Alto Networks specifically places NTP under Device > Setup > Services to separate network-layer settings from system services.

How to eliminate wrong answers

Option A is wrong because Objects > Regions is used to define geographic regions for policy-based filtering (e.g., blocking traffic from specific countries), not for clock synchronization. Option C is wrong because Device > Licenses is where you manage subscription licenses (e.g., Threat Prevention, URL Filtering) and activate the firewall, not for NTP configuration. Option D is wrong because Network > Interfaces, Management Interface is used to configure the dedicated management port (MGT) IP address, default gateway, and DNS settings, but NTP server configuration is a separate service setting under Device > Setup > Services.

24
MCQmedium

A network security administrator needs to ensure that a Palo Alto Networks firewall sends SNMP traps to a monitoring server at 10.1.1.50 using the MGT interface. The administrator has already added the SNMP community string and trap destination under Device > Setup > Services > SNMP. However, no traps are being received. Which additional configuration is required to ensure traps are sent from the MGT interface?

A.Create a service route for SNMP under Device > Setup > Services > Service Routes.
B.Enable SNMP on the MGT interface under Network > Interfaces > Management.
C.Assign the SNMP server IP address to a custom zone and create a NAT policy.
D.Configure a security policy rule allowing SNMP traffic from the MGT interface to the SNMP server.
AnswerA

Service routes define the source interface and IP address for outbound management traffic. By default, SNMP traps may use the management interface, but if a specific interface is required, a service route must be configured. In this scenario, the administrator must create a service route for SNMP specifying the MGT interface to ensure traps are sent from that interface.

Why this answer

Service routes override the default source interface for management services such as SNMP, syslog, and email. When a specific source interface is required, a service route must be configured. Without it, the firewall may use a different interface, causing the SNMP server to reject or ignore traps.

Thus, creating a service route for SNMP is the correct action.

Exam trap

The trap here is assuming that security policy rules apply to management-plane traffic, when in fact service routes control outbound management traffic.

25
MCQhard

A company uses Panorama to manage multiple device groups. They want to push a set of global security policies to all firewalls. Where should the administrator configure these policies in Panorama?

A.As pre-rules in the 'shared' device group
B.As pre-rules in each regional device group
C.In the default rule base of each device group
D.As post-rules in the 'shared' device group
AnswerA

Pre-rules in shared are pushed to all firewalls first.

Why this answer

In Panorama, the 'shared' device group is designed for policies that must apply globally across all managed firewalls. Configuring security policies as pre-rules in the shared device group ensures they are evaluated before any device-group-specific rules, providing a consistent global baseline that cannot be overridden by local rules.

Exam trap

The trap here is that candidates often confuse 'shared' with 'post-rules', mistakenly thinking post-rules are the correct location for global policies, but post-rules are evaluated last and can be overridden by device-group rules.

How to eliminate wrong answers

Option B is wrong because pre-rules in each regional device group would only apply to firewalls within that specific group, not globally across all device groups. Option C is wrong because the default rule base of each device group is local to that group and does not provide a single, centralized location for global policies. Option D is wrong because post-rules in the shared device group are evaluated after device-group rules, which would allow local policies to override the global intent, defeating the purpose of a global security baseline.

26
MCQeasy

A network administrator wants to ensure that the firewall sends SNMP traps to a monitoring server at 192.168.1.50. The administrator has already configured the SNMP community string and added the trap destination under Device > Setup > Services. However, traps are not being received. What is the most likely missing configuration?

A.A security policy rule allowing SNMP traffic from the firewall to the monitoring server.
B.An Interface Management Profile allowing SNMP on the interface used for traps.
C.A NAT rule to translate the firewall's management IP to a routable address.
D.Configuring the SNMP version to v3 with authentication.
AnswerB

SNMP traps are sent from the firewall's management interface or the interface specified in the SNMP configuration. If an Interface Management Profile is applied to that interface and does not permit SNMP, traps will be blocked. Enabling SNMP in the profile allows the firewall to send traps out that interface.

Why this answer

SNMP traps are sent from the firewall's management plane, and the interface used must permit SNMP via an Interface Management Profile. If the profile does not allow SNMP, traps are dropped. Security policies and NAT rules do not apply to management traffic.

Therefore, the missing configuration is the Interface Management Profile allowing SNMP.

Exam trap

The trap here is assuming that security policies control outbound management traffic, when in fact management traffic is governed by Interface Management Profiles.

27
MCQeasy

A network admin needs to push a security policy change to firewall-01 and firewall-02. Both firewalls have different interface configurations but should share the same security rules. What is the best way to achieve this using Panorama?

A.Create separate device groups for each firewall and configure identical policies manually.
B.Create a single device group containing both firewalls and configure security policies there.
C.Use templates to define security policies and assign to both firewalls.
D.Use the Shared policy and override for interfaces.
AnswerB

A device group containing both firewalls lets you author security policies once and push them to both devices, while each firewall retains its own interface configuration in separate templates. This satisfies the requirement for shared rules despite differing interface setups.

Why this answer

The best way to share security policies across firewalls with different interface configurations is to use a single device group containing both firewalls. Device groups are designed to manage security policies centrally, while templates handle device-specific settings like interface configurations. Option B is correct because it allows policy consistency without duplicating effort.

Option A (separate device groups) would require manual duplication. Option C (templates) is incorrect because templates are for device-level configuration, not security policies. Option D (Shared policy with overrides) is not a standard or efficient approach for this scenario.

28
MCQmedium

A network administrator needs to restrict which source IP addresses can access the firewall's web management interface. Which feature should be configured?

A.Management Profile
B.Access Control List on the data plane
C.Interface management settings
D.Security policy rule for management traffic
AnswerA

A Management Profile binds permitted source IP addresses to the management interface, so only trusted hosts can reach the web UI. This directly satisfies the restriction requirement, unlike security zones or policies that govern transit traffic rather than administrative access to the firewall itself.

Why this answer

Management Profile. A Management Profile is a firewall configuration object that defines which services (e.g., HTTPS, SSH, ping) are allowed on a specific interface and, critically, which source IP addresses or subnets can access those services. By binding a Management Profile to an interface, the administrator can restrict web management access to only trusted source IPs, such as a management subnet.

This is the intended and most secure method for controlling management plane access on Palo Alto Networks firewalls.

Exam trap

The trap here is that candidates often confuse data plane security policies (which control traffic through the firewall) with management plane access controls, leading them to select Option D or Option B, when in fact the Management Profile is the dedicated feature for restricting source IPs to the firewall's own management services.

How to eliminate wrong answers

Option B is wrong because an Access Control List (ACL) on the data plane controls traffic passing through the firewall (e.g., between zones), not traffic destined to the firewall itself (management plane traffic). Option C is wrong because Interface Management Settings is a generic term; the specific feature that includes source IP restriction is the Management Profile, not a separate setting. Option D is wrong because a Security Policy Rule for management traffic would apply to transit traffic and is not designed to filter management plane access to the firewall's own interfaces; management traffic is handled by the management plane, not the data plane security policy.

29
Multi-Selectmedium

Which two authentication methods can be used for administrative access to the firewall's web interface? (Choose two.)

Select 2 answers
A.SAML
B.NTLM
C.OAuth
D.Local database
E.Kerberos
AnswersA, D

SAML is supported for single sign-on to the web interface.

Why this answer

SAML (Security Assertion Markup Language) is correct because it enables single sign-on (SSO) for administrative access to the firewall's web interface, allowing integration with external identity providers (IdPs) such as Okta or Azure AD. The local database is correct because it is the default authentication method, where administrators are created and stored locally on the firewall, and credentials are verified against the internal user database. Both methods are natively supported in PAN-OS for web interface (GUI) access.

Exam trap

Palo Alto Networks often tests the misconception that any common enterprise authentication protocol (like NTLM or Kerberos) is automatically supported for administrative access, but Palo Alto firewalls specifically support only SAML, local database, RADIUS, LDAP, and TACACS+ for web interface authentication.

30
MCQeasy

A firewall uses an external SMTP server for email alerts. The SMTP server is reachable via a specific virtual router and interface. What must be configured to ensure the firewall uses the correct path to reach the SMTP server?

A.Ensure the SMTP server is in the same zone as the management interface.
B.Configure an SNMP trap destination.
C.Configure a service route for SMTP.
D.Add a static route for the SMTP server.
AnswerC

A service route binds a specific service, here SMTP, to a designated virtual router and interface, forcing outbound traffic for that service along the required path. Without it, the firewall may select a different egress interface and fail to reach the SMTP server.

Why this answer

Service routes in Palo Alto Networks firewalls explicitly define the source interface and virtual router used for outbound management traffic, such as SMTP email alerts. By configuring a service route for SMTP, the firewall ensures that email alerts are sent via the specified virtual router and interface, overriding the default management plane routing behavior.

Exam trap

The trap here is that candidates often assume a static route is sufficient, but without a service route, the firewall's management plane will use the default management interface and its associated routing table, which may not have a path to the SMTP server.

How to eliminate wrong answers

Option A is wrong because the SMTP server does not need to be in the same zone as the management interface; service routes decouple management traffic from security zones. Option B is wrong because SNMP trap destinations are used for SNMP notifications, not for SMTP email alerts. Option D is wrong because while a static route could influence routing, it does not control which source interface or virtual router the firewall uses for management traffic; service routes are required to bind the SMTP service to a specific path.

31
MCQmedium

After making configuration changes, an administrator clicks 'Commit' but the changes are not applied. What is the most likely cause?

A.Configuration validation errors exist
B.The commit is scheduled for a later time
C.The commit was canceled by another admin
D.The firewall is in multi-vsys mode and only the current vsys is committed
AnswerA

PAN-OS validates the candidate configuration before committing. If validation errors exist, the commit fails and no changes are applied, which matches the symptom of a clicked Commit with no effect. Resolving the flagged errors allows the commit to succeed.

Why this answer

When an administrator clicks 'Commit' but the changes are not applied, the most likely cause is that configuration validation errors exist. The Palo Alto Networks firewall performs a validation check before committing; if any errors are found (e.g., invalid IP addresses, missing required fields, or conflicting rules), the commit is blocked and an error message is displayed. This ensures that only syntactically and semantically correct configurations are applied to the running state.

Exam trap

The trap here is that candidates may assume a commit always succeeds if no syntax errors are shown in the GUI, but PAN-OS performs deep validation that can catch semantic issues (e.g., referencing a non-existent security profile) that prevent the commit from completing.

How to eliminate wrong answers

Option B is wrong because a scheduled commit would still be applied at the specified time, not silently ignored; the administrator would see a confirmation that the commit is pending. Option C is wrong because if another admin cancels a commit, the administrator would receive a notification or error message indicating the cancellation, not a silent failure. Option D is wrong because in multi-vsys mode, committing only the current vsys is a normal operation and would still apply changes to that vsys; the commit would not fail silently unless there were validation errors in that vsys's configuration.

32
MCQhard

A company uses Panorama to manage multiple firewalls. After pushing a template change, one firewall fails to commit with error 'invalid certificate path'. What is the most likely cause?

A.The firewall's management IP changed
B.Template commit requires reconnection
C.The template includes a certificate that has no trusted root on that firewall
D.The firewall's certificate has expired
E.Panorama's certificate is mismatched
AnswerC

Certificates referenced in a template must chain to a root the managed firewall trusts; if that root is absent from the firewall's trusted certificate store, the commit fails with an invalid certificate path error. The template pushed a certificate lacking a locally trusted root.

Why this answer

When a template push includes a certificate (e.g., for SSL decryption or authentication) that references a Certificate Authority (CA) not trusted by the target firewall, the commit fails with 'invalid certificate path'. The firewall cannot validate the certificate chain because the root or intermediate CA certificate is missing from its trusted store, causing the commit to abort.

Exam trap

The trap here is that candidates often confuse certificate expiration (Option D) with a missing trusted root, but the specific error 'invalid certificate path' points to a chain validation issue, not a time-based expiry.

How to eliminate wrong answers

Option A is wrong because a change in the firewall's management IP would cause connectivity loss, not a commit error related to certificate validation. Option B is wrong because template commits do not require a reconnection; Panorama pushes configurations to firewalls over the existing management connection, and a reconnection is not a prerequisite for commit. Option D is wrong because an expired certificate on the firewall would generate a different error (e.g., 'certificate expired') and would not specifically reference an 'invalid certificate path'.

Option E is wrong because a mismatched Panorama certificate would cause authentication or communication failures between Panorama and the firewall, not a commit failure on the firewall itself with a certificate path error.

33
Multi-Selectmedium

An organization is implementing a high availability pair of Palo Alto firewalls in active/passive mode. Which three actions are necessary for proper failover functionality? (Choose three.)

Select 3 answers
A.Set the firewall priority to determine the active role.
B.Enable session synchronization.
C.Assign the same IP address to both firewalls for the data interface.
D.Sync the running configuration to the passive firewall.
E.Configure the HA interface IP addresses.
AnswersA, B, E

Priority determines which firewall becomes active.

Why this answer

In an active/passive HA pair, the firewall priority (1-100, lower is higher priority) determines which firewall assumes the active role. The firewall with the numerically lower priority value becomes the active unit, ensuring deterministic failover behavior.

Exam trap

The trap here is that candidates often confuse configuration synchronization (which is automatic) with a manual step, or mistakenly think both firewalls can share the same data interface IP address, not realizing that only the active firewall uses the floating IP while each unit has its own unique management and interface IPs.

34
Multi-Selectmedium

A security analyst wants to send firewall logs to an external syslog server for long-term storage. Which three configuration steps are necessary?

Select 3 answers
A.Apply the log forwarding profile to a security policy rule.
B.Enable the syslog server in the Device > Server Profiles menu.
C.Set the syslog server to use TCP port 514.
D.Configure a log forwarding profile with syslog as the destination.
E.Specify the syslog facility code in the log forwarding profile.
AnswersA, B, D

The profile must be applied to a rule to generate logs.

Why this answer

A log forwarding profile must be applied to a security policy rule to specify which traffic logs should be forwarded to the external syslog server. Without this association, the firewall will not send the logs generated by that rule to the syslog destination.

Exam trap

The trap here is that candidates assume TCP port 514 is the default or required for syslog, but Palo Alto firewalls use UDP 514 by default, and changing to TCP is an optional optimization, not a necessary step.

35
MCQhard

After a firewall upgrade, the system clock shows a time that is five minutes behind the actual time, even though NTP is synchronized. What is the most likely cause?

A.The firewall is using a stratum 2 server that is inaccurate.
B.The timezone offset is incorrectly set.
C.NTP authentication is not configured.
D.The NTP admin state is enabled but the service route is misconfigured.
AnswerB

A wrong timezone would cause the displayed local time to differ from UTC, even if NTP is synced.

Why this answer

When NTP is synchronized but the system clock is offset by a fixed amount (e.g., five minutes), the most likely cause is an incorrect timezone offset. NTP synchronizes the UTC time, and the firewall then applies the configured timezone offset to display the local time. If the offset is wrong, the displayed time will be consistently off by that offset value, even though NTP shows synchronization.

Exam trap

The trap here is that candidates often assume NTP synchronization guarantees correct local time, but they overlook that the timezone offset must be independently configured; Palo Alto Networks tests this by presenting a scenario where NTP is synchronized yet the displayed time is wrong, leading to confusion between NTP server issues and timezone configuration errors.

How to eliminate wrong answers

Option A is wrong because a stratum 2 server that is inaccurate would cause the clock to drift or show a varying offset, not a consistent five-minute offset, and NTP would likely show the server as unsynchronized or with high jitter. Option C is wrong because NTP authentication is used to verify the identity of NTP servers, not to correct time offset; its absence does not cause a fixed time difference. Option D is wrong because if the NTP admin state is enabled but the service route is misconfigured, the firewall would not be able to reach the NTP server at all, resulting in no synchronization, not a synchronized clock with a fixed offset.

36
Multi-Selecthard

Which THREE log types can be forwarded to a syslog server?

Select 3 answers
A.Packet capture logs
B.Threat logs
C.Configuration logs
D.Traffic logs
E.System logs
AnswersB, D, E

Threat logs can be forwarded to syslog.

Why this answer

B is correct because threat logs capture security-related events such as intrusion attempts, malware detection, and vulnerability exploits, which are critical for security monitoring. The Palo Alto Networks firewall can forward these logs to a syslog server (e.g., using UDP 514 or TCP 6514) for centralized analysis and alerting. This is a standard feature in PAN-OS for integrating with SIEM systems.

Exam trap

The trap here is that candidates often confuse 'packet capture logs' with 'traffic logs' or assume all log types are syslog-forwardable, but PAN-OS restricts syslog forwarding to specific log types (threat, traffic, system) by default, while packet captures and configuration logs require separate handling.

37
MCQeasy

What is the purpose of the 'Telemetry' feature in PAN-OS?

A.To send anonymous device health and usage data to Palo Alto Networks
B.To send logs to Panorama
C.To enable DNS proxy
D.To configure User-ID agent
AnswerA

Telemetry periodically transmits anonymised device health, configuration and usage statistics to Palo Alto Networks, enabling proactive support and product improvement. It satisfies the stem's purpose by describing outbound vendor data sharing, not local logging or policy enforcement.

Why this answer

The Telemetry feature in PAN-OS sends anonymous device health and usage data to Palo Alto Networks to help improve product development and threat detection. This data includes information such as system resource utilization, feature usage statistics, and aggregate threat information, but does not include sensitive or personally identifiable information. It is an opt-in feature that enhances Palo Alto Networks' ability to provide proactive support and security updates.

Exam trap

The trap here is that candidates often confuse Telemetry with log forwarding or Panorama integration, assuming it is used for centralized management or log collection, when in fact it is solely for anonymous data sharing to improve Palo Alto Networks' services.

How to eliminate wrong answers

Option B is wrong because sending logs to Panorama is the function of log forwarding or the Panorama integration, not the Telemetry feature. Option C is wrong because enabling DNS proxy is a separate network service configuration, unrelated to Telemetry. Option D is wrong because configuring User-ID agent is a distinct identity management function, not part of Telemetry.

38
Multi-Selecthard

Which THREE of the following are valid steps when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?

Select 3 answers
A.Add two or more interfaces as members of the virtual wire
B.Assign an IP address to the virtual wire
C.Commit the configuration
D.Create a security policy allowing traffic on the virtual wire
E.Create a virtual wire object under Network > Virtual Wires
AnswersA, C, E

A virtual wire requires at least two interfaces bound as members, since it bridges traffic between them. Adding two or more interfaces as vwire members is therefore a valid configuration step, satisfying the requirement that the vwire have a defined ingress and egress pair.

Why this answer

Option E is correct because creating the virtual wire object under Network > Virtual Wires is the foundational step that defines the vwire and lets you bind its interfaces. Option A is correct because a virtual wire must have at least two interfaces assigned as members (typically a pair) so that traffic can be bridged transparently between them. Option C is correct because, as with any PAN-OS configuration change, the candidate configuration must be committed for the virtual wire to take effect.

Option B is not valid because a virtual wire operates at Layer 2 and is transparent, so it does not have or require an IP address. Option D is not a required configuration step for the vwire itself; security policy is a separate function and is not part of the virtual wire setup process.

Exam trap

The trap here is that candidates confuse the need for an IP address on a virtual wire (which is Layer 2) with the requirement for IP addresses on Layer 3 interfaces, leading them to incorrectly select option B as a valid step.

39
MCQeasy

During troubleshooting, an administrator needs to review firewall system events such as user logins, configuration changes, and commit failures. Which log type should be examined?

A.Threat logs
B.Traffic logs
C.System logs
D.URL filtering logs
AnswerC

System logs record administrative and daemon activity, including administrator logins, configuration commits, and commit failures. Traffic, threat, and URL filtering logs capture sessions and detections instead, so they cannot show the management-plane events the administrator needs.

Why this answer

System logs in Palo Alto Networks firewalls capture administrative and system-level events, including user logins, configuration changes, and commit failures. These logs are generated by the management plane and are essential for auditing and troubleshooting device management activities.

Exam trap

The trap here is that candidates often confuse system logs with traffic logs, assuming all firewall events are recorded in traffic logs, but system logs are specifically for management-plane events like user logins and commits.

How to eliminate wrong answers

Option A is wrong because Threat logs record security threats such as intrusions, malware, and spyware detected by the firewall, not administrative or system events. Option B is wrong because Traffic logs contain session-level details about allowed or denied network flows, not user logins or configuration changes. Option D is wrong because URL filtering logs track web requests and categorization results, not system-level administrative actions.

40
MCQmedium

An administrator wants to ensure that a specific security policy rule is applied before all other rules. What should be configured?

A.Set the rule's priority to 1
B.Use a schedule
C.Move the rule to the top of the rulebase
D.Enable 'Optimize' on the rule
AnswerC

Top-down evaluation means top rule is evaluated first.

Why this answer

In Palo Alto Networks firewalls, security policy rules are evaluated in a top-down order, and the first matching rule is applied. Moving a rule to the top of the rulebase ensures it is evaluated before all other rules, guaranteeing it takes precedence regardless of its priority number. Priority numbers (1-65535) are used for ordering within the rulebase, but the physical position in the list determines evaluation order; setting priority to 1 does not automatically place the rule at the top if other rules with lower numbers exist.

Exam trap

The trap here is that candidates confuse the 'priority' field with physical rule order, assuming a lower priority number automatically places the rule at the top, when in fact the rule must be physically moved to the top of the rulebase to ensure it is evaluated first.

How to eliminate wrong answers

Option A is wrong because setting the rule's priority to 1 only assigns a numerical value for ordering, but the actual evaluation order is determined by the rule's position in the rulebase; a rule with priority 1 can still be placed below other rules if not physically moved to the top. Option B is wrong because a schedule controls when a rule is active (time-based enforcement), not its evaluation order relative to other rules. Option D is wrong because 'Optimize' is not a valid configuration option on security rules in Palo Alto Networks; it is a feature for rulebase optimization in Panorama, not for ordering rules.

41
MCQhard

An administrator notices that the firewall's web interface is accessible via HTTPS but shows an expired certificate warning. The firewall's management certificate was issued by an internal CA and has a validity of two years. The administrator checks the certificate and sees it expired yesterday. The administrator generates a new self-signed certificate through the firewall's GUI. After generating, the administrator assigns the new certificate to the HTTPS management interface. Despite this, the firewall still presents the old expired certificate when accessed. What is the most likely cause?

A.The firewall must be restarted for the change to take effect.
B.The new certificate was not committed.
C.The old certificate is still bound to a different service.
D.The browser has cached the old certificate.
AnswerB

PAN-OS applies management-plane configuration changes only after a commit; generating and assigning a certificate updates the candidate configuration, not the running one. Until the administrator commits, the web interface continues presenting the previously committed expired certificate, so the assignment appears ineffective.

Why this answer

In Palo Alto Networks firewalls, changes to management interface settings, including certificate assignments, require a commit operation to become active. Generating and assigning the new certificate through the GUI only stages the change; without a commit, the firewall continues to use the previously committed configuration, which still references the expired certificate. This is why the old certificate persists despite the assignment.

Exam trap

The trap here is that candidates assume GUI assignments take effect immediately, overlooking the mandatory commit step required for all configuration changes on Palo Alto firewalls.

How to eliminate wrong answers

Option A is wrong because restarting the firewall is not required for certificate changes; a commit is sufficient to apply the new configuration. Option C is wrong because the question states the certificate was assigned to the HTTPS management interface, and even if bound elsewhere, the management interface would use its own assigned certificate. Option D is wrong because the browser caching the old certificate would only affect the client-side display, not the server-side presentation; the firewall itself is serving the old certificate due to the uncommitted change.

42
Multi-Selectmedium

Which TWO methods are valid for managing a Palo Alto Networks firewall? (Select two)

Select 2 answers
B.SNMP (Read/Write)
D.SSH
AnswersC, D

HTTPS is used for web-based management.

Why this answer

HTTPS (port 443) is the standard web-based management interface for Palo Alto Networks firewalls, providing encrypted GUI access via the Panorama or local web interface. SSH (port 22) is the secure CLI access method, allowing command-line management with encryption and authentication. Both are explicitly supported and recommended for secure management.

Exam trap

The trap here is that candidates often confuse SNMP's read/write community strings with management capability, but SNMP on Palo Alto Networks firewalls is strictly for monitoring and cannot be used to change configuration or perform administrative tasks.

43
Multi-Selecteasy

Which TWO management methods allow CLI access to a Palo Alto Networks firewall?

Select 2 answers
A.SSH
B.Serial console
AnswersA, B

SSH provides encrypted remote command-line access to the firewall's management interface, satisfying the CLI access requirement. Administrators authenticate against the management plane and issue operational or configuration commands through the terminal. This is one of the two supported CLI methods, alongside the console port, making it valid for this scenario.

Why this answer

SSH (Secure Shell) is a standard management method that provides encrypted CLI access to Palo Alto Networks firewalls, allowing administrators to execute commands securely over a network. The serial console port on the firewall provides direct, out-of-band CLI access for initial configuration or troubleshooting when network connectivity is unavailable.

Exam trap

The trap here is that candidates often confuse management methods that provide GUI access (HTTPS) with those that provide CLI access, or incorrectly assume that Telnet is still a supported option on modern firewalls due to its prevalence in older networking equipment.

44
MCQmedium

An administrator needs to restrict access to the firewall's web management interface to only the IT department subnet 10.0.0.0/24. The firewall's management interface is in the 'Management' zone. Which configuration step is required to enforce this restriction?

A.Enable 'Require HTTPS' and configure an authentication profile with allowed users from 10.0.0.0/24.
B.Configure an Interface Management Profile with permitted IP addresses 10.0.0.0/24 and apply it to the management interface.
C.Create a security policy rule allowing only 10.0.0.0/24 to the Management zone and deny all other sources.
D.Set up a NAT rule to translate external IPs to the management IP and restrict via security policy.
AnswerB

Interface Management Profiles define which IP addresses are allowed to access management services (HTTPS, SSH, etc.) on an interface. By specifying 10.0.0.0/24 and applying the profile to the management interface, only hosts in that subnet can reach the web UI, effectively enforcing the restriction.

Why this answer

Interface Management Profiles are specifically designed to control management access to an interface by specifying allowed IP addresses and enabled services. Applying such a profile to the management interface with 10.0.0.0/24 ensures only that subnet can access the web UI. Other options either apply to transit traffic or do not enforce source IP restrictions.

Exam trap

The trap here is assuming that security policies govern management plane access, when in fact management access is controlled by Interface Management Profiles.

45
MCQeasy

An administrator needs to access the firewall's CLI via SSH, but the default SSH port (22) is blocked by the corporate firewall. Which configuration allows SSH on a non-standard port?

A.Device > Setup > Management > Port for SSH
B.Device > Setup > Services > SSH Port
C.Device > Setup > Management > Port for HTTP/HTTPS
D.Device > Administration > SSH Port
E.Device > Setup > Operations > SSH
AnswerA

Palo Alto firewalls expose the management-plane SSH port under Device > Setup > Management, letting administrators move SSH off port 22 to a permitted value. This satisfies the stem's constraint that corporate firewall blocks the default port, while the dataplane security policy remains unaffected.

Why this answer

The firewall's SSH port is configured under Device > Setup > Management > Port for SSH. This setting allows the administrator to change the default TCP port 22 to any non-standard port, enabling SSH access when the corporate firewall blocks the default port. The management interface settings control all inbound management protocols, including SSH, HTTPS, and ping.

Exam trap

The trap here is that candidates confuse the management port settings for SSH with other protocol settings (like HTTP/HTTPS) or assume a 'Services' or 'Administration' menu exists, leading them to pick an option that sounds plausible but does not exist in the PAN-OS GUI.

How to eliminate wrong answers

Option B is wrong because there is no 'Services' submenu under Device > Setup; SSH port configuration is under 'Management', not 'Services'. Option C is wrong because 'Port for HTTP/HTTPS' controls web-based management access, not SSH. Option D is wrong because there is no 'Administration' menu under Device; SSH port settings are not located there.

Option E is wrong because 'Operations' under Device > Setup is for operational tasks like rebooting or generating tech support files, not for configuring SSH port settings.

46
MCQhard

A company is deploying a Palo Alto firewall in a high-availability (HA) pair. They want to ensure that when a failover occurs, session information is preserved to maintain active connections. Which feature must be enabled?

A.Session synchronization
B.Stateful failover
C.Packet buffer
D.Session Timer adjustment
AnswerA

Session synchronisation replicates the Layer 4 session table and, where configured, application state between the HA peers, so established flows continue through the newly active firewall after failover. It directly satisfies the stem's requirement to preserve session information and maintain active connections, unlike configuration-only HA synchronisation.

Why this answer

Session synchronization (option A) is the correct feature because it enables the active firewall to share session table entries with the passive peer in real time. When a failover occurs, the newly active firewall already has the session state, so it can continue forwarding traffic for existing connections without interruption. Without session synchronization, all active sessions would be dropped and must be re-established by clients.

Exam trap

The trap here is that candidates confuse the general concept of 'stateful failover' (which is the desired outcome) with the specific feature name that must be enabled in the Palo Alto configuration, leading them to select option B instead of the precise mechanism 'session synchronization'.

How to eliminate wrong answers

Option B (Stateful failover) is wrong because it is a generic term describing the overall capability of preserving state during failover, not a specific feature that must be enabled; the actual mechanism that achieves this in Palo Alto firewalls is session synchronization. Option C (Packet buffer) is wrong because it refers to temporary storage of packets during congestion or processing delays, not to sharing session state between HA peers. Option D (Session Timer adjustment) is wrong because modifying session timeouts affects how long idle sessions remain in the table, but does not replicate session information to the standby firewall.

47
MCQmedium

A network administrator needs to configure SNMPv3 on a Palo Alto Networks firewall to allow a monitoring server to query interface statistics. The administrator wants to ensure that SNMP queries are authenticated and encrypted. Which SNMPv3 configuration is required to meet these requirements?

A.Create an SNMPv3 user with auth and priv passwords, and assign the default view that includes all OIDs.
B.Create an SNMPv3 user with only an auth password, and assign a view that includes the interface statistics OIDs.
C.Create an SNMPv3 user with auth password and priv password, and assign a view that includes the interface statistics OIDs.
D.Create an SNMPv3 user with only a priv password, and assign a view that includes the interface statistics OIDs.
AnswerC

SNMPv3 provides authentication and encryption through the use of auth and priv passwords. To allow queries for interface statistics, you must create a user with these credentials and assign a view that grants access to the relevant MIB objects. This configuration ensures both security and access to the required data.

Why this answer

SNMPv3 requires both authentication and encryption to secure queries. This is achieved by configuring an SNMPv3 user with both an auth password and a priv password. Additionally, the user must be associated with a view that permits access to the specific OIDs needed, such as interface statistics.

Using the default view with all OIDs is overly permissive and not recommended.

Exam trap

The trap here is assuming that a priv password alone provides authentication, when it only provides encryption; both auth and priv passwords are needed for secure SNMPv3.

48
MCQeasy

An administrator is configuring a Palo Alto Networks firewall to send email alerts for critical system events. The administrator has configured an SMTP server under Device > Setup > Services > Email. However, test emails are not being delivered. Which additional step is required to allow the firewall to send email alerts?

A.Enable SMTP in the Management Interface settings under Network > Interfaces.
B.Set up a service route for SMTP under Device > Setup > Services > Service Routes.
C.Configure a security policy rule allowing SMTP traffic from the firewall to the SMTP server.
D.Add an SNMP trap destination for email notifications.
AnswerB

A service route for SMTP defines the source interface and IP address for outbound email traffic. If the SMTP server is reachable only via a specific interface, a service route ensures that emails are sent from the correct interface. Without it, the firewall may attempt to send emails from an interface that cannot reach the SMTP server, causing delivery failures.

Why this answer

Email alerts are sent from the management plane, and their source interface is determined by service routes. If the SMTP server is not reachable from the default management interface, a service route must be configured to specify the correct egress interface. This ensures that the firewall can deliver email alerts successfully.

Without a service route, the firewall may use an interface that cannot reach the SMTP server.

Exam trap

The trap here is confusing management-plane email alerts with data-plane SMTP traffic that would require a security policy.

49
MCQhard

A network security engineer is configuring a Palo Alto Networks firewall to send SNMP traps to a management server. The engineer has already configured the SNMP community string and the trap destination IP. However, the management server is not receiving any traps. Which additional configuration is required to allow SNMP traps to be sent?

A.Configure an SNMPv3 user with authentication and encryption.
B.Configure a Security policy rule allowing SNMP traffic from the firewall to the management server.
C.Enable SNMP on the management interface by applying an Interface Management Profile that includes SNMP.
D.Add a static route to the management server via the management interface.
AnswerC

SNMP traps are sent from the management interface. By default, SNMP is not enabled on the management interface. An Interface Management Profile must be applied to the management interface with SNMP enabled for the firewall to send traps. Without this, even with community and destination configured, traps will not be transmitted.

Why this answer

SNMP traps are generated by the management plane and sent out the management interface. By default, SNMP is not enabled on that interface. An Interface Management Profile with SNMP enabled must be applied to the management interface.

Once that is done, the firewall can send traps to the configured destination. Other options either relate to data plane policies or routing, which are not the cause of the missing traps.

Exam trap

The trap here is assuming that configuring the SNMP community and trap destination is sufficient, overlooking the need to enable SNMP on the management interface via an Interface Management Profile.

50
MCQhard

An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?

A.Configure HA1 and HA2 interfaces with appropriate IPs
B.Enable Config Sync on the HA General tab
C.Enable Session Setup and State Synchronization under HA configuration
D.Configure Path Monitoring to detect link failures
AnswerC

Enabling Session Setup and State Synchronization under HA configuration replicates session tables and state between peers, so established flows survive failover without re-establishment. Without it, the passive firewall lacks session context and drops active connections during transition.

Why this answer

Session state synchronization (also known as stateful failover) requires enabling both Session Setup and State Synchronization under the HA configuration. This ensures that the active firewall's session table is continuously replicated to the passive firewall, so when a failover occurs, existing sessions are not dropped and can continue without interruption.

Exam trap

The trap here is that candidates confuse Config Sync (which synchronizes configuration files) with Session State Synchronization (which synchronizes active session data), leading them to select Option B instead of C.

How to eliminate wrong answers

Option A is wrong because configuring HA1 and HA2 interfaces with appropriate IPs is necessary for HA communication (heartbeat and backup links), but it does not enable session state synchronization by itself. Option B is wrong because Config Sync synchronizes configuration files (policies, objects) between firewalls, not session state; it is unrelated to preserving active sessions during failover. Option D is wrong because Path Monitoring detects link failures to trigger failover, but it does not replicate session state; it only helps decide when to fail over, not what happens to existing sessions.

51
MCQmedium

Refer to the exhibit. The firewall is experiencing performance issues and dropping sessions. Based on the exhibit, what is the most likely cause?

A.Dataplane resources are exhausted
B.The firewall has been recently rebooted
C.System CPU is too high
D.The session limit is being reached
AnswerA

The exhibit shows dataplane utilisation at or near maximum, meaning the firewall's dataplane processing capacity is exhausted. When dataplane resources are saturated, the firewall cannot process sessions fast enough and begins dropping them, matching the reported performance issues.

Why this answer

The exhibit shows that the dataplane (DP) utilization is at 100%, which directly indicates that the dataplane resources are exhausted. When the dataplane is fully utilized, the firewall cannot process new sessions or maintain existing ones, leading to session drops and performance issues. This is the most likely cause because the dataplane handles packet forwarding and session setup, and its exhaustion is a common bottleneck in high-throughput environments.

Exam trap

Palo Alto Networks often tests the distinction between management plane (system CPU) and dataplane resources, so the trap here is that candidates confuse high system CPU with dataplane exhaustion, not realizing that session drops are almost always a dataplane issue, not a management plane one.

How to eliminate wrong answers

Option B is wrong because a recent reboot would typically show low dataplane utilization and a gradual increase as sessions build up, not sustained 100% utilization with session drops. Option C is wrong because system CPU (management plane) being high does not directly cause session drops; the dataplane operates independently, and high system CPU affects management tasks like logging or UI responsiveness, not packet forwarding. Option D is wrong because the session limit being reached would show a session count at the maximum configured limit in the exhibit, but the exhibit shows dataplane utilization at 100% without indicating the session limit is hit; session limits are a separate resource constraint that triggers specific 'max-session' drops, not general performance degradation from dataplane exhaustion.

52
MCQeasy

An administrator is configuring a new PA-3220 firewall and needs to allow DNS queries from the internal network to an external DNS server. The internal network is in the Trust zone, and the external DNS server is reachable via the Untrust zone. Which type of security policy rule should be created to permit this traffic?

A.A universal rule allowing UDP port 53 regardless of zone
B.An interzone rule from Trust to Untrust allowing UDP port 53
C.An intrazone rule from Trust to Trust allowing UDP port 53
D.An intrazone rule from Untrust to Untrust allowing UDP port 53
AnswerB

Traffic from the internal network (Trust zone) to the external DNS server (Untrust zone) is interzone traffic. A security policy rule with source zone Trust and destination zone Untrust, application dns, and service application-default will permit DNS queries. This correctly allows the required traffic while maintaining zone-based segmentation.

Why this answer

DNS queries from the internal network to an external server traverse from the Trust zone to the Untrust zone, which is interzone traffic. A security policy rule that specifies source zone Trust and destination zone Untrust, with the DNS application or UDP port 53, will correctly permit this traffic while enforcing zone-based security.

Exam trap

The trap here is selecting an intrazone rule when the traffic crosses between two different zones, which requires an interzone rule.

53
MCQmedium

Refer to the exhibit. A security analyst reviews a traffic log entry in JSON format. Which firewall feature is responsible for including the 'user' field in the log?

A.Data Filtering
B.Captive Portal
C.GlobalProtect
D.User-ID
AnswerD

User-ID maps source IP addresses to directory usernames and writes that mapping into traffic logs, populating the 'user' field. Without User-ID enabled and mapped, the log would show only IP addresses, so this feature is responsible for the field's presence.

Why this answer

The 'user' field in a traffic log is populated by User-ID, which maps IP addresses to usernames by monitoring authentication events from Active Directory, LDAP, or terminal services agents. This allows the firewall to log and enforce policies based on user identity rather than just IP addresses.

Exam trap

The trap here is that candidates confuse Captive Portal (which authenticates users for web access) with User-ID (which passively maps IPs to usernames for logging and policy enforcement), leading them to choose Captive Portal instead of User-ID.

How to eliminate wrong answers

Option A is wrong because Data Filtering is a security profile that controls the transfer of sensitive data patterns (e.g., credit card numbers) in application traffic, not user identity mapping. Option B is wrong because Captive Portal is an authentication mechanism that intercepts HTTP traffic to enforce user login before granting network access, but it does not passively map IP-to-user for all traffic logs; User-ID handles that mapping. Option C is wrong because GlobalProtect is a remote access VPN solution that can provide user identity via its gateway, but the 'user' field in a traffic log is populated by the User-ID agent, not solely by GlobalProtect.

54
Multi-Selecthard

A security administrator at a company with a PA-5220 running PAN-OS 10.2 must ensure that configuration backups can be restored to a replacement firewall of the same model. The administrator plans to use scheduled configuration exports and also wants to retain a copy of the running configuration before a major change. Which TWO actions will satisfy these requirements? (Choose two.)

Select 2 answers
A.Export only the device state under Device > Setup > Operations, since the device state contains all security policy and object definitions.
B.Configure a scheduled log export to the same SCP server so that configuration and logs are stored together for restoration.
C.Create a scheduled configuration export under Device > Setup > Operations that saves a full configuration snapshot to an external SCP server on a recurring basis.
D.Enable configuration versioning under Device > Setup > Management so the firewall automatically pushes each commit to an external repository.
E.Use the 'Save named configuration snapshot' option under Device > Setup > Operations to capture the current configuration before making changes.
AnswersC, E

Scheduled configuration exports capture the full running configuration, including policies, objects, and network settings, and store it externally. This satisfies the need for recurring, restorable backups that survive hardware loss. Because the snapshot is complete, it can be loaded onto a replacement firewall of the same model, provided the software version is compatible.

Why this answer

Scheduled configuration exports provide recurring off-box full configuration snapshots that can be loaded onto a replacement firewall, satisfying disaster recovery. Named configuration snapshots taken before a major change provide a local rollback point on the same device. Together they cover both off-box retention and quick local recovery, while log exports and device state exports do not contain the full configuration.

Exam trap

The trap here is treating device state exports or log exports as configuration backups, when only a full configuration export or snapshot contains the policies and objects needed to rebuild a firewall.

55
MCQhard

An administrator is configuring a Palo Alto Networks firewall to use an external LDAP server for administrator authentication. The administrator wants to ensure that only members of the 'NetworkAdmins' group can log in with read-write privileges. Which configuration steps are required?

A.Create an LDAP server profile and an authorization profile that maps the 'NetworkAdmins' group to a read-write admin role. No authentication profile is needed.
B.Create an authentication profile and an authorization profile. The authorization profile should map all LDAP users to a read-write role, and then use a security policy to restrict access to the 'NetworkAdmins' group.
C.Create an LDAP server profile and an authentication profile. Assign the authentication profile directly to the admin role 'superuser'.
D.Create an LDAP server profile, an authentication profile, and an authorization profile that maps the 'NetworkAdmins' group to a read-write admin role.
AnswerD

To authenticate administrators via LDAP, you need an LDAP server profile, an authentication profile that references it, and an authorization profile that maps LDAP groups to admin roles. This ensures that only members of the specified group receive the read-write role. This is the correct and complete configuration.

Why this answer

Configuring LDAP administrator authentication requires three components: an LDAP server profile to define the server connection, an authentication profile to specify how users authenticate, and an authorization profile to map LDAP groups to administrative roles. By mapping only the 'NetworkAdmins' group to a read-write role, you ensure that only members of that group receive the appropriate privileges.

Exam trap

The trap here is overlooking the need for an authorization profile to map groups to roles, and instead assuming that authentication alone can enforce group-based access.

56
Drag & Dropmedium

Drag and drop the steps to configure a GlobalProtect portal and gateway on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

GlobalProtect requires portal, gateway, security policy, assignment, and testing.

57
Multi-Selecteasy

Which TWO are best practices for securing management access to a Palo Alto firewall? (Select two)

Select 2 answers
A.Use HTTPS with self-signed certificates
B.Use SNMP v1 for monitoring
C.Use a dedicated management subnet
D.Disable ping on the management interface
E.Restrict management access to specific IP addresses
AnswersC, E

Segregates management traffic from production.

Why this answer

Using a dedicated management subnet (out-of-band management) isolates management traffic from production data traffic, reducing the attack surface and ensuring management access remains available even if the data plane is compromised. This is a foundational security best practice for any network device, including Palo Alto firewalls.

Exam trap

The trap here is that candidates often confuse 'disabling ping' (a minor, non-critical hardening step) with the core best practices of network segmentation and access control, leading them to select Option D instead of the more impactful Options C and E.

58
MCQhard

Refer to the exhibit. What is the default gateway of the firewall?

A.10.0.0.1
B.ethernet1/1
C.10.0.0.0
D.0.0.0.0
AnswerA

10.0.0.1 is the next-hop address the firewall uses to reach destinations outside its local subnets, matching the default route entry in the virtual router's forwarding table shown in the exhibit. This satisfies the stem's requirement for the firewall's default gateway rather than an interface address or management path.

Why this answer

The default gateway for a firewall is the IP address of the next-hop router that the firewall uses to reach networks not directly connected. In the exhibit, the route with destination 0.0.0.0/0 (the default route) points to next-hop 10.0.0.1, making 10.0.0.1 the default gateway. This is the standard behavior in PAN-OS: the default gateway is defined by the static default route, not by an interface IP.

Exam trap

Palo Alto Networks often tests the distinction between the default route's destination (0.0.0.0/0) and the next-hop IP address, causing candidates to mistakenly select 0.0.0.0 as the gateway.

How to eliminate wrong answers

Option B is wrong because ethernet1/1 is an interface name, not an IP address; the default gateway must be an IP address of a next-hop router. Option C is wrong because 10.0.0.0 is the network address of the subnet, not a usable host address for a gateway. Option D is wrong because 0.0.0.0 is the destination prefix for the default route, not the next-hop gateway address.

59
MCQeasy

An administrator at a branch office with a PA-440 needs to allow the firewall itself to resolve external hostnames and to forward DNS queries from internal clients to public resolvers. The administrator wants to configure a DNS proxy on the firewall so clients use the firewall's interface IP as their DNS server. Which configuration step is required to enable this behavior?

A.Enable DNS resolution under Device > Setup > Services and add the public resolvers to the firewall's DNS server list; clients will be automatically redirected to the firewall.
B.Configure an Application Override policy for DNS on port 53 so the firewall inspects and answers queries on behalf of clients.
C.Create a NAT rule translating TCP and UDP port 53 from the internal zone to a public resolver, which will cause the firewall to act as a DNS proxy.
D.Configure a DNS Proxy object under Network > DNS Proxy and assign it to the ingress interface, then create a security policy rule allowing DNS from the internal zone to the untrust zone.
AnswerD

A DNS Proxy object defines the interface where clients send queries and the upstream DNS servers the firewall forwards to. After assigning it to an interface, a security policy permitting UDP/TCP 53 from the client zone toward the upstream zone is still required for the proxied traffic. This combination lets internal clients use the firewall as their resolver while the firewall performs the outbound lookups.

Why this answer

DNS Proxy is a Network configuration object bound to an interface where client queries arrive, with upstream servers the firewall forwards to. Enabling it requires both the proxy object assignment and a security policy allowing DNS from the client zone to the upstream zone, because proxied traffic is still evaluated by policy. The firewall's own DNS server list is separate and only affects management-plane lookups.

Exam trap

The trap here is conflating the firewall's own DNS resolver settings under Device > Setup > Services with the DNS Proxy feature under Network, which serves clients.

60
MCQeasy

Which of the following is NOT a valid method for upgrading PAN-OS software on a Palo Alto firewall?

A.Using an FTP server
B.Using the CLI
C.Using the Web GUI
D.Using Panorama
AnswerA

PAN-OS upgrades are performed from the management plane using Panorama, the web interface, or SCP/HTTPS retrieval from the update server; FTP is not a supported transport. This makes FTP the invalid method the question asks for, since no upgrade path relies on it.

Why this answer

PAN-OS software upgrades on Palo Alto firewalls are supported via the CLI, the Web GUI, and Panorama. FTP is not a supported method because the firewall's upgrade mechanism relies on HTTP/HTTPS for downloading images from the Palo Alto Networks update server or a local web server; FTP protocol is not implemented in the upgrade process.

Exam trap

The trap here is that candidates may assume FTP is a valid method because it is a common file transfer protocol, but Palo Alto Networks explicitly does not support FTP for PAN-OS upgrades, only HTTP/HTTPS-based downloads.

How to eliminate wrong answers

Option B is wrong because the CLI is a valid upgrade method using commands like 'request system software upgrade'. Option C is wrong because the Web GUI provides a graphical interface under Device > Software to download and install updates. Option D is wrong because Panorama can push PAN-OS upgrades to managed firewalls via the 'Software' tab in the Device Group or Template context.

61
MCQmedium

An administrator wants to ensure that only the firewall administrator's workstation at 203.0.113.45 can reach the web management interface on a PA-3220 running PAN-OS 10.2. The workstation is on the trust zone, and management access is currently allowed from any address on the management interface. Which configuration object should the administrator create and apply to the management interface?

A.A Management Interface ACL applied to the trust zone interface, permitting only 203.0.113.45.
B.An Interface Management profile with HTTPS enabled and the permitted IP address 203.0.113.45/32, applied to the management interface.
C.A Security policy rule from the trust zone to the management zone allowing only 203.0.113.45, with a default deny rule after it.
D.An Authentication profile bound to the management interface, allowing only the user account associated with 203.0.113.45.
AnswerB

Interface Management profiles control which management services are enabled on an interface and can restrict access to specific permitted IP addresses. By enabling HTTPS and listing only 203.0.113.45/32, the administrator ensures that only that workstation can reach the web UI on the management interface, satisfying the requirement precisely without affecting other management services.

Why this answer

Interface Management profiles are the correct mechanism to control which management services (HTTPS, SSH, SNMP, etc.) are enabled on an interface and to restrict those services to specific permitted IP addresses. By creating a profile with HTTPS enabled and only 203.0.113.45/32 as a permitted address, the administrator ensures that the web management interface is reachable only from the intended workstation, directly meeting the stated requirement.

Exam trap

The trap here is assuming that Security policy rules control access to the firewall's own management interface, when in fact management-plane access is governed by Interface Management profiles and permitted IP addresses.

62
MCQmedium

A company requires automatic daily backups of the firewall configuration. Which method should be used?

A.Backup the config using TFTP from the CLI
B.Schedule a configuration backup under Device > Setup > Operations
C.Write a script using the PAN-OS API to copy the running config
D.Use the 'Export Device State' feature manually
AnswerB

Scheduling a configuration backup under Device > Setup > Operations uses the firewall's built-in export mechanism to write configuration exports to a defined location on a recurring daily schedule, satisfying the automatic backup requirement without external scripting.

Why this answer

The PAN-OS web interface provides a built-in scheduler under Device > Setup > Operations that allows administrators to automate daily configuration backups without external scripts or manual intervention. This method is the simplest and most reliable way to ensure consistent backups, as it leverages the firewall's native scheduling capability.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing API scripting or manual export, failing to recognize that PAN-OS includes a native, straightforward scheduling mechanism for configuration backups that meets the requirement without additional complexity.

How to eliminate wrong answers

Option A is wrong because TFTP is not a secure protocol and is not recommended for automated daily backups; it also requires an external TFTP server and manual CLI commands, lacking native scheduling. Option C is wrong because writing a script using the PAN-OS API is a valid but unnecessarily complex method for a simple daily backup requirement, and it introduces potential scripting errors and maintenance overhead. Option D is wrong because the 'Export Device State' feature is a manual operation that requires administrator intervention each time, making it unsuitable for automatic daily backups.

63
MCQmedium

A security administrator notices that a user's traffic is being blocked unexpectedly. The user's IP is 10.1.1.100, and the traffic is destined to a web server at 192.168.2.10. The administrator has already verified that there are no security rules explicitly denying the traffic. Which Log Viewer query should the administrator use to quickly identify the cause?

A.Search Traffic logs with filters for source 10.1.1.100 and destination 192.168.2.10
B.Search Threat logs for the destination IP
C.Search Config logs for any rule changes
D.Search System logs for the user's IP
AnswerA

Filtering Traffic logs by source 10.1.1.100 and destination 192.168.2.10 isolates the exact flow, revealing the implicit deny or policy match causing the block. Since no explicit deny rule exists, the session detail exposes which rule or default action dropped it.

Why this answer

Traffic logs capture every session that passes through the firewall, including allowed and denied connections. By filtering for the specific source IP (10.1.1.100) and destination IP (192.168.2.10), the administrator can quickly see the exact session details, including the action taken (e.g., deny, drop) and the reason (e.g., no matching rule, application override). This is the most direct method to identify why traffic is being blocked when no explicit deny rule exists.

Exam trap

The trap here is that candidates may assume a block must be due to a threat or misconfiguration, leading them to check Threat or Config logs, but the correct approach is to examine Traffic logs where the firewall records all session dispositions, including implicit denials.

How to eliminate wrong answers

Option B is wrong because Threat logs record intrusion prevention system (IPS) and antivirus events, not basic traffic denials; a block due to missing rules would not appear there. Option C is wrong because Config logs track administrative changes to the firewall configuration, not real-time traffic decisions; they would not show why current traffic is blocked. Option D is wrong because System logs contain system-level events (e.g., reboots, license expirations) and do not include per-session traffic details; they cannot reveal why a specific flow is denied.

64
MCQeasy

Refer to the exhibit. A firewall administrator is reviewing a Panorama template configuration. What is the purpose of the 'profile' statement under the interface?

A.It applies a security rule.
B.It applies a QoS profile.
C.It applies a Zone Protection profile.
D.It applies an interface management profile.
AnswerD

The 'profile' statement under an interface references an interface management profile, which controls which management services (HTTPS, SSH, ping, SNMP) are permitted on that interface. This satisfies the scenario's requirement to define administrative access methods per interface within the Panorama template, rather than applying security or QoS settings.

Why this answer

The 'profile' statement under an interface in Panorama template configuration is used to apply an interface management profile. This profile controls which management services (e.g., HTTPS, SSH, SNMP, ping) are permitted on that interface, thereby securing administrative access. It does not apply security rules, QoS, or zone protection, which are configured elsewhere.

Exam trap

The trap here is that candidates often confuse the 'profile' statement with a security profile (like Anti-Virus or Vulnerability Protection) or a Zone Protection profile, but in the context of interface configuration, it specifically refers to the interface management profile that controls administrative access.

How to eliminate wrong answers

Option A is wrong because security rules are applied via Security policy rules in Panorama, not through an interface's 'profile' statement. Option B is wrong because QoS profiles are configured under the QoS policy or interface QoS settings, not via the 'profile' statement under the interface. Option C is wrong because Zone Protection profiles are applied to zones, not directly to interfaces; the 'profile' statement under the interface specifically refers to management access control.

65
MCQhard

A security administrator is configuring a Palo Alto Networks firewall to send syslog messages to an external syslog server at 203.0.113.10. The syslog server is reachable only through the ethernet1/1 interface, which is in the untrust zone. The administrator has configured the syslog server under Device > Server Profiles > Syslog and attached it to a log forwarding profile. However, syslog messages are not being received by the server. What is the most likely cause?

A.The syslog server is not configured to accept messages from the firewall's management IP address.
B.The syslog server profile is not assigned to the correct log forwarding profile.
C.A security policy rule is blocking syslog traffic from the firewall to the syslog server.
D.A service route for syslog is not configured to use ethernet1/1 as the source interface.
AnswerD

Service routes determine the source interface for outbound management traffic, including syslog. If the syslog server is reachable only via ethernet1/1, a service route must be configured to use that interface. Without it, the firewall may use the management interface, which cannot reach the server, causing syslog messages to be dropped. This is the most likely cause.

Why this answer

Syslog messages are sent from the management plane, and their source interface is determined by service routes. When the syslog server is only reachable via a specific interface, a service route must be configured to use that interface. Without it, the firewall may attempt to send syslog messages from the management interface, which cannot reach the server, resulting in no messages being received.

Exam trap

The trap here is assuming that security policy rules apply to syslog traffic, when in fact service routes control the source interface for management-plane syslog.

66
MCQmedium

An administrator manages a PA-3220 running PAN-OS 10.2 with two virtual routers: VR-A for the internal network and VR-B for the internet. The firewall must send SNMP traps, syslog, and email alerts to servers reachable only through VR-B. Which setting directly controls which virtual router the firewall uses to egress that management-plane traffic?

A.A static route in VR-A pointing to the SNMP, syslog, and SMTP servers
B.A Policy-Based Forwarding (PBF) rule matching the firewall's own management traffic
C.The Management Interface's default gateway under Device > Setup > Interfaces
D.The Service Route Configuration under Device > Setup > Services
AnswerD

Service Route Configuration lets the administrator bind each management service (SNMP, Syslog, Email, HTTP, etc.) to a specific source interface and virtual router. Selecting VR-B's egress interface for these services ensures traps, logs, and alerts leave through VR-B, satisfying the requirement precisely.

Why this answer

Firewall-originated management services such as SNMP, syslog, and email do not follow dataplane routing by default; they are steered by Service Route Configuration. Binding each service to an interface in VR-B forces that egress path, which is exactly what the scenario requires. Other mechanisms either affect only transit traffic or the dedicated management port.

Exam trap

The trap here is assuming that dataplane static routes or PBF rules steer the firewall's own management-plane services, when Service Route Configuration actually governs that egress.

67
MCQmedium

A security analyst notices that a legitimate application is being incorrectly identified as a different application by the firewall. What is the best first step to resolve this issue?

A.Reboot the firewall to refresh the application cache
B.Disable the application override and use port-based rules
C.Verify the application signature in the App-ID database and submit a false-positive report if needed
D.Create a custom App-ID to override the incorrect identification
AnswerC

App-ID misidentification stems from signature or decoder mismatches, so verifying the application signature in the App-ID database confirms whether the firewall's identification is genuinely wrong. Submitting a false-positive report then lets Palo Alto Networks correct the signature, addressing the root cause rather than applying workarounds.

Why this answer

The first step in resolving an application misidentification is to verify the application signature in the App-ID database. If the signature is incorrect or missing, submitting a false-positive report allows Palo Alto Networks to update the database, ensuring accurate identification without manual overrides. This aligns with the principle of using the built-in App-ID engine as the primary identification method.

Exam trap

The trap here is that candidates may think creating a custom App-ID is the quickest fix, but the exam emphasizes that the proper workflow is to first verify the database and report false positives, as custom overrides bypass the automated identification process and can lead to security gaps.

How to eliminate wrong answers

Option A is wrong because rebooting the firewall does not refresh the application cache in a way that fixes signature-based misidentification; the cache is rebuilt from the same App-ID database, so the error persists. Option B is wrong because disabling the application override and using port-based rules defeats the purpose of App-ID, reducing security by relying on port numbers that can be easily spoofed. Option D is wrong because creating a custom App-ID should be a last resort after verifying the database and submitting a false-positive report, as it adds administrative overhead and may not align with the official signature.

68
MCQmedium

An administrator notices that the firewall's time is incorrect. Based on the exhibit, what is the most likely cause?

A.DNS proxy is running
B.Management service is down
C.SNMP is running
D.Syslog is running
E.NTP service is stopped
AnswerE

A stopped NTP service means the firewall cannot synchronise with its configured time source, so its clock drifts and shows an incorrect time. Restarting or reconfiguring the NTP service restores synchronisation, addressing the most likely cause shown in the exhibit.

Why this answer

The firewall's time is incorrect because the NTP service is stopped. NTP (Network Time Protocol) is responsible for synchronizing the system clock with an external time source. Without NTP, the firewall relies on its internal hardware clock, which can drift over time, leading to an incorrect time.

Exam trap

The trap here is that candidates may confuse services like DNS, SNMP, or Syslog with time synchronization, but only NTP directly manages the system clock.

How to eliminate wrong answers

Option A is wrong because DNS proxy resolves domain names to IP addresses and does not affect system time synchronization. Option B is wrong because the management service being down would prevent administrative access, but it does not directly cause time drift. Option C is wrong because SNMP is used for network monitoring and management, not for time synchronization.

Option D is wrong because Syslog is used for logging system events, not for setting or maintaining the system clock.

69
MCQeasy

A network security administrator needs to back up the firewall configuration before making changes. The administrator wants to store the backup on an external SCP server at 198.51.100.10 using the account 'backupuser'. Which sequence of steps should the administrator take in the web interface?

A.Device > Configuration > Export, then select SCP and enter the server details.
B.Device > Setup > Operations > Export named configuration snapshot, then select SCP and enter the server details.
C.Device > Setup > Management > Export configuration, then select SCP and enter the server details.
D.Device > Setup > Services > Export configuration, then select SCP and enter the server details.
AnswerB

The Operations tab under Device > Setup provides export options for configuration snapshots. Selecting 'Export named configuration snapshot' allows the administrator to choose SCP as the export method and specify the server IP, username, and path. This directly creates a backup on the external SCP server, fulfilling the requirement.

Why this answer

In PAN-OS, configuration backups to external servers are performed via Device > Setup > Operations. The 'Export named configuration snapshot' option allows selection of SCP, FTP, or TFTP as the export protocol, and prompts for server address, username, and path. This is the standard method to store a configuration backup on an external SCP server, ensuring the configuration is preserved before changes are made.

Exam trap

The trap here is confusing the Operations tab with the Management or Services tabs under Device > Setup, where configuration export options are not available.

70
MCQeasy

A security administrator needs to restrict access to the firewall's web management interface to only the IP address 10.1.1.100. The administrator logs into the firewall and navigates to Device > Setup > Management. Which configuration should be modified?

A.Device > Setup > Services: Configure a security policy rule to allow only 10.1.1.100 to the management interface.
B.Administrative Accounts: Create a new admin role with read-only access for 10.1.1.100.
C.Management Interface Settings: Add 10.1.1.100/32 to the Permitted IP Addresses list.
D.Management Interface Settings: Enable HTTP and HTTPS on the management interface.
AnswerC

The Permitted IP Addresses list under Management Interface Settings allows you to specify which IP addresses can access the management interface. Adding 10.1.1.100/32 restricts access to only that IP. This is the correct place to enforce such a restriction. Other settings do not control management access at the interface level.

Why this answer

The Permitted IP Addresses list under Device > Setup > Management > Management Interface Settings is specifically designed to restrict management access to specified IP addresses. Adding 10.1.1.100/32 ensures only that host can connect to the web interface. Other settings, such as admin roles or service ports, do not provide IP-based restriction.

Exam trap

The trap here is confusing management plane access restrictions with security policy rules, which apply only to data plane traffic.

71
MCQhard

A security engineer is deploying a PA-5220 firewall in a high-availability active/passive pair. The engineer wants to ensure that the management interface of the passive firewall is reachable for out-of-band management. The firewalls are configured with HA1 and HA2 links. Which statement accurately describes the management interface behavior in this HA configuration?

A.The management interface on the passive firewall is disabled and can only be accessed by failing over the active firewall.
B.The management interface on the passive firewall remains active and can be accessed independently, provided it has a unique IP address and is configured with a default gateway.
C.The management interface on the passive firewall only allows traffic if the HA1 link is down, as a fallback mechanism.
D.The management interface IP address is shared between the active and passive firewalls, and traffic is redirected to the active firewall.
AnswerB

In an active/passive HA configuration, the management interface of the passive firewall remains operational and can be accessed independently. Each firewall's management interface should have a unique IP address, and a default gateway must be configured for out-of-band management. This allows administrators to manage the passive device directly, which is essential for troubleshooting and maintenance.

Why this answer

In an active/passive HA pair, the management interface of the passive firewall remains active and independently accessible, provided it has a unique IP and a default gateway. This allows out-of-band management of both firewalls. The management IP is not shared, and its availability does not depend on HA link status.

Thus, the passive firewall's management interface can be used for direct administrative access.

Exam trap

The trap here is assuming that the passive firewall's management interface is disabled or shares an IP with the active firewall, when in reality it remains independently accessible.

72
Matchingmedium

Match each Palo Alto Networks feature to its category.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Threat Prevention

Decryption

User-ID

App-ID

Why these pairings

App-ID belongs to Network Security as it identifies applications. WildFire is a Threat Prevention feature for malware analysis. GlobalProtect enables Remote Access.

Common confusions include mixing App-ID with threat prevention or Panorama with remote access.

73
Multi-Selecthard

Which THREE are required for Panorama to manage a firewall? (Select three)

Select 3 answers
A.A valid Panorama license
B.Panorama plugin installed on the firewall
C.Certificate-based mutual authentication (or pre-shared key)
D.Template and device group configuration in Panorama
E.Management IP reachability between Panorama and the firewall
AnswersC, D, E

Authentication is mandatory for secure communication.

Why this answer

Panorama and managed firewalls must establish a secure, authenticated connection using either certificate-based mutual authentication or a pre-shared key. This ensures that only authorized firewalls can register with Panorama and receive configuration updates, preventing unauthorized devices from joining the management domain.

Exam trap

The trap here is that candidates often assume a Panorama license is required on the firewall itself, but the license is only needed on Panorama, not on the managed firewall.

74
MCQeasy

Which license is required for the firewall to use URL filtering?

A.DNS Security
B.GlobalProtect
C.URL Filtering
D.WildFire
E.Threat Prevention
AnswerC

URL Filtering is a licensed subscription that activates the PAN-DB URL database on the firewall, enabling category-based and custom URL policy enforcement. Without this licence, the firewall cannot query PAN-DB, so the URL filtering profile cannot classify traffic. It directly satisfies the stem's requirement for the licence needed to use URL filtering.

Why this answer

URL filtering requires a dedicated URL Filtering license on Palo Alto Networks firewalls to enable the firewall to query the PAN-DB cloud or use a locally installed URL database for categorizing URLs. Without this license, the firewall cannot perform URL-based access control, even if other security subscriptions like Threat Prevention or WildFire are active.

Exam trap

The trap here is that candidates often assume Threat Prevention or WildFire includes URL filtering, but Palo Alto Networks separates these as distinct subscriptions, and only the URL Filtering license enables URL categorization and policy enforcement.

How to eliminate wrong answers

Option A is wrong because DNS Security is a separate subscription that provides protection against DNS-based threats, not URL categorization. Option B is wrong because GlobalProtect is a license for remote access VPN and mobile security, not for URL filtering. Option D is wrong because WildFire is a threat analysis service for unknown files and links, not for URL categorization.

Option E is wrong because Threat Prevention covers IPS, antivirus, and anti-spyware, but does not include URL filtering functionality.

75
MCQeasy

Refer to the exhibit. What is the effect of this configuration?

A.The firewall allows ping traffic through all interfaces.
B.The management profile allows SSH access.
C.The firewall responds to pings on the management interface.
D.The firewall cannot ping others.
AnswerC

The management interface permits ICMP, so the firewall replies to ping requests arriving on it. This satisfies the exhibit's effect: management-plane access is allowed for troubleshooting, while data-plane interfaces remain governed by their own security policies.

Why this answer

The configuration shown is a management profile applied to an interface. The 'ping' service is enabled under the management profile, which allows the firewall to respond to ICMP echo requests (pings) on that specific interface. This does not permit transit ping traffic through the firewall, nor does it enable SSH or allow the firewall to initiate pings.

Therefore, option C is correct.

Exam trap

Palo Alto Networks often tests the confusion between management plane services (like ping to the firewall) and data plane transit traffic (like ping through the firewall), leading candidates to incorrectly assume a management profile affects traffic forwarding.

How to eliminate wrong answers

Option A is wrong because the management profile only controls services for the firewall's own interface, not transit traffic; ping traffic through the firewall requires a security policy rule, not a management profile. Option B is wrong because the management profile shown does not list SSH as an enabled service; only ping is enabled. Option D is wrong because the configuration does not restrict the firewall from initiating outbound pings; it only controls responses to pings received on that interface.

Page 1 of 2 · 78 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Device Mgmt Services questions.