PCNSE Deploy and Configure Firewalls Practice Question
A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?
⚠ Common exam trap
Test-takers frequently confuse management access with outbound connectivity; a loopback or management interface alone does not provide a path for DNS queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Layer 3 interface with an IP address and a default route pointing to the next-hop gateway.
The firewall requires a Layer 3 interface with an IP address and a default route to send DNS queries to external servers. The interface provides the source IP, and the default route directs traffic to the next-hop gateway. Other interface types like loopback, virtual wire, or Layer 2 do not provide the necessary routable connectivity for outbound DNS resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Layer 2 interface with a VLAN interface configured for DNS.
Why it's wrong here
Layer 2 interfaces are used for switching and do not have IP addresses for routing. A VLAN interface can have an IP address, but it is typically used for inter-VLAN routing and management. However, for outbound DNS queries, the firewall would still need a default route via a Layer 3 interface. The scenario describes a Layer 3 deployment, so a Layer 2 interface is not appropriate for the firewall's own DNS traffic.
- ✗
A virtual wire interface pair with a management profile allowing DNS.
Why it's wrong here
Virtual wire interfaces operate at Layer 2 and do not have IP addresses assigned for traffic. They cannot be used as a source for outbound DNS queries because they lack an IP address. While a virtual wire can pass DNS traffic, the firewall itself cannot originate DNS queries from a virtual wire interface. Therefore, this configuration does not enable DNS resolution for the firewall.
- ✗
A loopback interface with a management profile allowing DNS.
Why it's wrong here
A loopback interface is used for management access and routing stability, but it does not provide outbound connectivity for DNS queries. The firewall uses a physical or logical interface with a default route to reach DNS servers. A management profile on a loopback would only control access to the interface itself, not outbound DNS resolution. Therefore, this does not enable DNS queries.
- ✓
A Layer 3 interface with an IP address and a default route pointing to the next-hop gateway.
Why this is correct
For the firewall to send DNS queries to external DNS servers, it needs a routable interface with an IP address and a default route to reach the internet. In Layer 3 mode, the firewall uses the interface's IP as the source for DNS queries. The default route ensures that traffic to unknown destinations, including DNS servers, is forwarded to the next-hop gateway. This is the standard configuration for outbound management traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.