Courseiva

PCNSA · topic practice

Device Management and Services practice questions

This domain covers day-to-day firewall operations on PAN-OS: software upgrades, HA synchronization, time/NTP configuration, and interface modes such as virtual wire. Questions are scenario-based, asking you to diagnose a failed upgrade or sync, identify a misconfiguration from an exhibit, or select valid configuration steps.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Device Management and Services

What the exam tests

What to know about Device Management and Services

Be able to upgrade PAN-OS in the correct order, keep HA peers on matching versions, fix time/NTP issues, and configure a virtual wire end to end. The single most important thing: verify both HA peers run the same PAN-OS version before expecting sync to succeed.

PAN-OS upgrade paths, base image installation, and HA active/passive sync requirements after upgrade

Virtual wire configuration: assigning interfaces, zones, and security policy for transparent traffic

NTP and timezone settings that keep logs, certificates, and HA timestamps consistent

Valid versus invalid methods for installing PAN-OS software and content updates

Watch out for

Common Device Management and Services exam traps

  • ▸Upgrading the passive HA peer without matching the active peer's PAN-OS version, breaking config sync
  • ▸Assuming any upload method installs PAN-OS; only supported paths like the web UI or SCP work
  • ▸Forgetting that vwire interfaces need zones and policy before traffic passes, not just interface assignment

Practice set

Device Management and Services questions

20 questions · select your answer, then reveal the explanation

During a firewall upgrade from PAN-OS 9.1 to 10.0, the administrator receives an error that the upgrade cannot proceed because there is a pending commit. The administrator checks the commit status and sees that a commit was initiated but has not completed. What is the best course of action?

An administrator needs to back up the firewall configuration before making changes. Which method creates a complete backup that can be restored to the same or a different firewall?

Which TWO of the following are valid methods to upgrade the PAN-OS version on a Palo Alto Networks firewall?

Which TWO of the following are valid methods to collect a technical support file from a Palo Alto Networks firewall?

Refer to the exhibit. A user at 10.1.1.50 is unable to connect to 192.168.1.100 on TCP port 443. The traffic log shows no entries for that source IP. Which security rule is expected to match this traffic?

Exhibit

Refer to the exhibit.

admin@PA-3020> show running security-policy

rulebase security rules
  rule 1 name "Allow-Sales"
    source [ 10.1.1.0/24 ]
    destination [ 192.168.1.0/24 ]
    application [ ms-sql ]
    service [ tcp-1433 ]
    action allow
    log-start no
  rule 2 name "Allow-HR"
    source [ 10.1.2.0/24 ]
    destination [ 192.168.2.0/24 ]
    application [ web-browsing ]
    service [ application-default ]
    action allow
    log-start yes

admin@PA-3020> show session id 12345
Source IP: 10.1.1.50
Destination IP: 192.168.1.100
Application: ssl
Service: tcp-443

admin@PA-3020> show log traffic | match 10.1.1.50
... no results ...

A company has two Palo Alto Networks firewalls in an active/passive HA pair (PA-5250) running PAN-OS 10.1. The HA configuration uses dedicated HA1 (control link) and HA2 (data link) interfaces. The network team recently replaced a failed switch that connected the HA1 interfaces. After the switch replacement, the HA pair is not forming. The administrator logs into the active firewall and runs 'show high-availability state' which shows the local state as 'active' and the peer state as 'unknown'. The HA1 interface status shows 'link down'. The administrator checks the physical connections and confirms the cables are connected and the switch ports are up. What is the most likely cause and the best course of action?

A network administrator notices that a specific user behind a PA-820 firewall is unable to reach a critical SaaS application, while other users can access it without issues. The administrator checks the traffic logs and sees the session is being denied. Which step should the administrator take next to identify the root cause?

A security engineer needs to ensure that all traffic from the internal network to the internet is inspected by the firewall. The firewall is deployed in virtual wire mode (Layer 2) with subinterfaces. Which configuration is required to achieve this?

A network administrator wants to allow FTP traffic from the internal network to a specific external server. The administrator creates a security policy rule with source zone 'internal', destination zone 'external', destination IP of the server, and application 'ftp'. However, the traffic is still blocked. What is the most likely reason?

A security administrator notices that a security policy rule is not matching traffic that should be allowed. The rule specifies source address as 10.0.1.0/24, destination address as 192.168.2.0/24, and application 'web-browsing'. The traffic originates from 10.0.1.5 to 192.168.2.10 using HTTPS. The traffic log shows that another rule with higher priority is matching and denying the traffic. What should the administrator check first?

Question 11mediummulti select
Review the full routing breakdown →

Which TWO of the following are required when configuring a new virtual router on a Palo Alto Networks firewall?

Refer to the exhibit. A firewall has the configuration shown. A security policy allows traffic from the internal zone to the external zone. However, users on the internal network (192.168.1.0/24) cannot reach the internet. What is the most likely cause?

Exhibit

> show system info

hostname: PA-5250
model: PA-5250
sw-version: 10.1.3
app-version: 8340-5987
threat-version: 8340-5987

> show running ip-route

destination: 0.0.0.0/0
nexthop: 10.0.0.1
interface: ethernet1/1

> show interface ethernet1/1

interface: ethernet1/1
state: up
ip address: 10.0.0.2/24
zone: external

> show interface ethernet1/2

interface: ethernet1/2
state: down
ip address: 192.168.1.1/24
zone: internal

A security administrator manages a Palo Alto Networks firewall with multiple virtual systems (vsys). The firewall is configured to use Panorama for centralized management. The administrator notices that after committing a configuration change on Panorama, the firewall's vsys2 is not receiving the updated configuration. The firewall can reach Panorama, and other vsys are updated correctly. The administrator verifies that Panorama's device group hierarchy includes the firewall and that the vsys2 template stack is correctly assigned. What is the most likely cause of this issue?

Drag and drop the steps to configure a security policy on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Palo Alto Networks feature to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Identifies applications regardless of port

Maps IP addresses to usernames

Inspects files and data for threats

Cloud-based malware analysis

VPN client for remote access

Match each protocol to its default port used by Palo Alto Networks.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

443

22

N/A (ICMP)

161

A security admin wants to allow network engineers to log in to the firewall using their existing Active Directory credentials while maintaining a local admin account for emergency access. What should be configured?

After a new zero-day exploit is discovered, a firewall must receive the latest threat prevention signature immediately. What is the most effective method to ensure the firewall gets the update as soon as it is released?

An administrator makes several changes to the firewall configuration and commits. However, after the commit, users report connectivity issues. The administrator wants to revert to the previous configuration quickly without losing the changes that were made earlier in the day but not yet committed. What should the administrator do?

Question 20mediummultiple choice
Read the full network assurance explanation →

An enterprise wants to receive SNMP traps from their firewalls for critical events such as HA state changes and high CPU usage. They have an SNMP trap receiver at 10.1.1.100. What configuration steps are required?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Device Management and Services sessions

Start a Device Management and Services only practice session

Every question in these sessions is drawn from the Device Management and Services domain — nothing else.

Related practice questions

Related PCNSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSA exam test about Device Management and Services?
Be able to upgrade PAN-OS in the correct order, keep HA peers on matching versions, fix time/NTP issues, and configure a virtual wire end to end. The single most important thing: verify both HA peers run the same PAN-OS version before expecting sync to succeed.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Device Management and Services questions in a focused session?
Yes — the session launcher on this page draws every question from the Device Management and Services domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSA topics?
Use the topic links above to move to related areas, or go back to the PCNSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSA exam covers. They are not copied from any real exam or dump site.