PCNSE Manage, Monitor and Operate Practice Question
A small business uses a single PA-220 firewall with PAN-OS 10.2. The administrator notices that the firewall is no longer receiving automatic threat updates. The License page shows the Threat Prevention license is active with 200 days remaining. The administrator can manually download updates from the Palo Alto Networks update server. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently assume a valid license guarantees automatic updates, overlooking that the update schedule is a separate configuration setting that must be explicitly enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The update schedule is disabled.
The most likely cause is that the update schedule is disabled. Even though the Threat Prevention license is active and manual downloads work, the firewall will not automatically check for or download updates if the scheduled update feature is turned off. In PAN-OS 10.2, the administrator must configure a recurring schedule under Device > Dynamic Updates for automatic updates to occur; otherwise, only manual downloads are possible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall is behind a proxy that blocks the update service.
Why it's wrong here
A proxy blocking the update service would also prevent the administrator's manual downloads, yet those succeed, so the update path itself works. It is tempting because proxies commonly break firewall update connectivity, and would be correct if manual downloads from the update server also failed.
- ✓
The update schedule is disabled.
Why this is correct
Dynamic updates require a configured schedule to poll the update server automatically. With the licence active and manual downloads working, connectivity and entitlement are fine, so a disabled update schedule is the only remaining cause of missed automatic threat updates.
- ✗
The firewall's system clock is incorrect.
Why it's wrong here
An incorrect clock skews certificate validation, so the firewall rejects the update server's TLS certificate and automatic retrieval fails while manual download still works. NTP synchronisation is the fix. Clock accuracy matters generally, but it is not the mechanism that governs update scheduling or licence enforcement.
- ✗
The DNS settings are misconfigured.
Why it's wrong here
Manual download works, so DNS is resolving correctly.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.