Courseiva

Palo Alto Networks Certified Network Security Engineer PCNSE (PCNSE) — Questions 1–75

319 questions total · 5pages · All types, answers revealed

Page 1 of 5

Page 2
1
MCQhard

A network security engineer is deploying a Palo Alto Networks firewall in a high-availability (HA) active/passive configuration. The engineer wants to ensure that the passive firewall takes over seamlessly if the active firewall fails. Which of the following is a requirement for HA active/passive configuration?

A.The active firewall must have a higher priority value than the passive firewall.
B.Both firewalls must be configured with the same management IP address.
C.Both firewalls must have identical hardware models and software versions.
D.The passive firewall must have a separate security policy that blocks all traffic.
AnswerC

For HA active/passive, both firewalls must be the same hardware model and run the same PAN-OS software version. This ensures that the passive firewall can take over without compatibility issues. If the models or software versions differ, the HA pair may not form, or failover may not work correctly. Identical hardware and software also ensure consistent performance and feature support. While some platforms allow mixed models in HA, it is not recommended and may not be supported. For seamless failover, identical configurations are essential.

Why this answer

For HA active/passive, both firewalls must be identical in hardware model and PAN-OS software version to ensure compatibility and seamless failover. The passive firewall synchronizes configuration from the active firewall, so security policies are the same. Each firewall needs a unique management IP for separate management.

Priority values are used for election but are not required to be higher on the active firewall. The passive firewall does not have a separate blocking policy.

Exam trap

The trap here is thinking that the active firewall must have a higher priority, but priority is only used for election and does not define the active/passive role.

2
Multi-Selecthard

Which THREE of the following are key differences between the Palo Alto Networks Next-Generation Firewall and Cloud-Delivered Security Services (CDSS)?

Select 3 answers
A.CDSS performs full application-level packet inspection.
B.CDSS offers services like DNS Security and WildFire that require an internet connection to the cloud.
C.CDSS provides cloud-based threat analysis and signature updates, while the firewall is the enforcement point.
D.CDSS is a replacement for the firewall's local threat prevention functionality.
E.CDSS can automatically share threat intelligence across all subscribed firewalls.
AnswersB, C, E

CDSS services such as DNS Security and WildFire run in Palo Alto Networks' cloud, so the firewall needs outbound internet connectivity to query them. This satisfies the scenario's requirement for a key difference: these subscriptions are cloud-delivered rather than fully on-box.

Why this answer

Option B is correct because CDSS subscriptions such as DNS Security and WildFire are cloud-hosted services that the firewall must reach over the internet to submit files/URLs and retrieve verdicts, unlike purely on-box inspection. Option C is correct because the architectural split is that CDSS performs cloud-based threat analysis and delivers dynamic signature/content updates, while the NGFW remains the inline enforcement point that applies policy and blocks traffic. Option E is correct because CDSS aggregates telemetry from all subscribed firewalls and pushes newly derived threat intelligence back out globally, giving every firewall protection from threats seen anywhere.

Option A is not correct because full application-level packet inspection is done by the NGFW's App-ID engine on the firewall itself, not by CDSS. Option D is not correct because CDSS augments rather than replaces the firewall's local threat prevention (e.g., antivirus, anti-spyware, vulnerability protection) capabilities.

Exam trap

The trap here is assuming CDSS replaces local firewall functions (like packet inspection or threat prevention) rather than understanding it as a complementary cloud service that enhances, not substitutes, the firewall's core enforcement capabilities.

3
MCQmedium

A security engineer is troubleshooting why a web application is not being identified correctly. The firewall shows the session as 'ssl' instead of the specific application. The engineer has verified that the traffic is using TLS 1.3. What is the most likely reason for the misidentification?

A.The application uses a non-standard port.
B.The security policy does not allow the application.
C.SSL decryption is not configured for the traffic.
D.The firewall does not support TLS 1.3 inspection.
AnswerC

Without SSL decryption, the firewall cannot inspect the encrypted payload and can only identify the traffic as ssl based on the port or protocol. To identify the specific application inside TLS, the firewall must decrypt the traffic. This is especially true for TLS 1.3, where more of the handshake is encrypted, making it harder to identify the application without decryption.

Why this answer

SSL decryption is required to inspect encrypted traffic and identify the application inside. Without decryption, the firewall can only classify the session as ssl based on the protocol, not the specific application. This is particularly relevant for TLS 1.3, where more of the handshake is encrypted, making decryption even more critical for accurate App-ID.

Exam trap

The trap here is assuming that App-ID can identify applications inside encrypted traffic without decryption, but encryption hides the application signatures, so only ssl is identified.

4
MCQeasy

A help desk ticket reports that a user cannot access the firewall's web management interface (HTTPS) from the management network. The management interface is on a dedicated MGMT network. Which setting must be enabled on the firewall to allow this access?

A.Enable IKE on the management interface.
B.Enable User-ID on the management interface.
C.Configure a service route to redirect management traffic to a dataplane interface.
D.Under Device > Setup > Management, add the user's IP or subnet to 'Permitted IP Addresses' for HTTPS.
AnswerD

Adding the user's subnet to Permitted IP Addresses under Device > Setup > Management restricts HTTPS management access to explicitly listed sources, satisfying the dedicated MGMT network constraint. Without this entry, the firewall silently drops management-plane traffic from unlisted addresses, so the help desk user is denied despite correct routing and policy.

Why this answer

The firewall's management interface enforces an access control list for HTTPS (and other management protocols) under Device > Setup > Management. By default, no IP addresses are permitted, so even if the user is on the same MGMT network, the firewall will drop HTTPS requests unless the user's IP or subnet is explicitly added to the 'Permitted IP Addresses' list. This setting is a fundamental security measure to restrict management access to trusted sources only.

Exam trap

The trap here is that candidates often confuse management access control with service routes or dataplane features, assuming that being on the same MGMT network is sufficient, but the firewall explicitly blocks all management protocol access by default unless the source IP is permitted.

How to eliminate wrong answers

Option A is wrong because IKE (Internet Key Exchange) is used for IPsec VPN tunnel negotiation, not for controlling access to the web management interface; enabling IKE on the management interface does not grant HTTPS access. Option B is wrong because User-ID is a feature for mapping IP addresses to usernames for policy enforcement, typically on dataplane interfaces, and enabling it on the management interface does not affect HTTPS management access. Option C is wrong because service routes are used to redirect management traffic (e.g., syslog, SNMP, RADIUS) to a specific dataplane interface for outbound communication, but they do not control inbound HTTPS access to the management interface; the management interface itself must have the correct permitted IP list.

5
MCQhard

A security operations center (SOC) uses Panorama to monitor all firewalls. They notice that some log entries show a severity of 'critical' but the alerting system does not fire. The log forwarding profile on Panorama is configured to send syslog alerts for severity 'critical'. The syslog server receives other logs from Panorama but not these critical logs. The administrator checks the Panorama configuration and finds that the log forwarding profile is applied to the correct log types. What is the most likely issue?

A.The log forwarding profile on Panorama is not applied to the managed firewalls.
B.The critical logs are generated on the firewall and not forwarded to Panorama.
C.The Panorama's log collector is not processing the logs correctly.
D.The syslog server is filtering out the critical logs based on the source IP.
AnswerB

Panorama only forwards logs it receives from managed firewalls. If critical logs are generated locally on a firewall and never sent to Panorama, Panorama's log forwarding profile cannot forward them, explaining why the syslog server receives other logs but not these.

Why this answer

The most likely issue is that the critical logs are generated on the firewall but not forwarded to Panorama. Panorama can only forward logs it has received from its managed firewalls; if the firewall’s log forwarding or logging settings (e.g., log severity threshold, log buffering, or connectivity to the Log Collector) prevent those critical logs from reaching Panorama, then Panorama’s syslog forwarding profile will never see them. The fact that other logs arrive at the syslog server indicates Panorama’s forwarding works, so the gap must be upstream at the firewall-to-Panorama log collection stage.

Exam trap

The trap here is that candidates assume Panorama’s log forwarding profile is the only configuration needed, overlooking that logs must first be collected from the firewall via the Log Collector, and that the firewall’s own logging settings or connectivity can prevent critical logs from reaching Panorama.

How to eliminate wrong answers

Option A is wrong because the log forwarding profile on Panorama is applied to the correct log types and the syslog server receives other logs, proving the profile is active; the issue is not about the profile being applied to firewalls but about logs not reaching Panorama. Option C is wrong because if the Log Collector were not processing logs correctly, other logs would also be missing or corrupted, but the syslog server receives other logs from Panorama, indicating the collector is functioning. Option D is wrong because the syslog server receives other logs from Panorama, so it is not filtering based on source IP; the problem is that the critical logs never leave Panorama, not that they are dropped by the syslog server.

6
MCQeasy

An administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions that are active on the firewall. The administrator wants to see details such as source and destination IP addresses, application, and security policy applied. Which CLI command should the administrator use?

A.show running session all
B.show session info
C.show session all
D.show session table
AnswerC

The 'show session all' command displays all active sessions on the firewall, including source and destination IP addresses, application, security policy, and other details. It is the primary command for viewing the session table. This command provides a comprehensive list, which can be filtered further if needed. Therefore, it meets the administrator's requirement to view current sessions with the specified details.

Why this answer

The 'show session all' command is the correct CLI command to display all active sessions on a Palo Alto Networks firewall, including source and destination IP addresses, application, and the security policy applied. It provides the detailed session information the administrator needs to troubleshoot or monitor current traffic.

Exam trap

The trap here is confusing similar-sounding commands like 'show session info' with 'show session all', where the former only provides summary statistics and not detailed session listings.

7
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?

A.In the IKE Gateway configuration, enable 'Perfect Forward Secrecy' and select group14.
B.In the IKE Crypto profile, set the DH Group to group14.
C.In the IPsec Crypto profile, set the DH Group to group14.
D.In the IPsec Tunnel configuration, enable 'Perfect Forward Secrecy' and select group14.
AnswerC

The IPsec Crypto profile is used for IKE phase 2 and includes the DH Group setting for PFS. By setting the DH Group to group14 in the IPsec Crypto profile, the firewall will propose PFS with group14 during phase 2, ensuring that the IPsec SA uses PFS with the specified group.

Why this answer

Perfect Forward Secrecy for IKE phase 2 is configured in the IPsec Crypto profile. The DH Group field in this profile specifies the Diffie-Hellman group used for PFS during phase 2. Setting it to group14 ensures that the IPsec SA uses PFS with group14.

The IKE Crypto profile controls phase 1, while the IPsec Crypto profile controls phase 2.

Exam trap

The trap here is confusing the IKE Crypto profile with the IPsec Crypto profile, or thinking that PFS is configured at the gateway or tunnel level.

8
MCQhard

A company uses Panorama to manage multiple firewalls. An administrator pushes a template that includes a new Security Profiles group, but the firewalls do not receive the profile group. What is the most likely cause?

A.The profile group references a profile that does not exist in the template.
B.The push was performed to device groups instead of templates.
C.The firewalls are not assigned to the template that contains the profile group.
D.The commit was not selected to include the new profiles.
AnswerC

Template membership governs which firewalls receive pushed configuration objects. A Security Profiles group defined in a template only reaches firewalls explicitly assigned to that template; unassigned devices keep their existing configuration, so the group never appears on them.

Why this answer

Panorama pushes templates to firewalls based on template assignment. If a firewall is not assigned to the template that contains the Security Profiles group, the firewall will never receive that configuration, regardless of the push operation. Template assignment is a prerequisite for any template-based configuration to be applied to a managed firewall.

Exam trap

The trap here is that candidates often confuse the push operation for device groups with the push for templates, assuming that a single push covers all configuration, when in fact Panorama requires separate pushes for templates and device groups, and template assignment is a prerequisite for receiving any template-based configuration.

How to eliminate wrong answers

Option A is wrong because if a profile group references a profile that does not exist in the template, Panorama would generate a validation error during a commit or push, preventing the push from succeeding entirely — the firewalls would not partially receive the group without the missing profile. Option B is wrong because Panorama pushes templates and device groups separately; a push to device groups does not affect template content, and the administrator would need to push templates to deliver the profile group. Option D is wrong because the commit operation is not a per-object selection; when a commit is performed on Panorama, all pending changes in the selected template or device group are included — there is no option to selectively exclude new profiles from a commit.

9
Multi-Selecthard

A security engineer is designing a Palo Alto Networks firewall deployment for a multi-tenant environment. The engineer needs to ensure that each tenant's traffic is isolated and that security policies can be applied per tenant. The engineer plans to use Virtual Systems (vsys) to achieve this. Which two statements about Virtual Systems (vsys) are true? (Choose two.)

Select 2 answers
A.Virtual Systems can be assigned dedicated physical interfaces or share interfaces using VLANs.
B.Virtual Systems share the same management interface and IP address.
C.Virtual Systems require a separate license for each vsys instance.
D.Virtual Systems share the same global routing table and cannot have separate virtual routers.
E.Each vsys has its own set of security policies, zones, and interfaces.
AnswersA, E

In a vsys deployment, physical interfaces can be assigned to a specific vsys, or they can be shared across vsys using VLAN tags. This flexibility allows for efficient use of physical resources while maintaining isolation. Each vsys can have its own Layer 3 interfaces or VLAN interfaces, enabling separate routing and policy enforcement. This statement accurately describes how vsys can be deployed in a multi-tenant environment.

Why this answer

Virtual Systems (vsys) provide logical isolation on a single firewall, each with its own policies, zones, and interfaces. They can be assigned dedicated physical interfaces or share interfaces via VLANs. They can also have separate virtual routers for independent routing.

Licensing is based on the total number of vsys enabled, not per instance. These characteristics make vsys suitable for multi-tenant deployments.

Exam trap

The trap here is assuming that vsys share all resources or require individual licenses, when in fact they can be isolated with dedicated interfaces and routing, and licensing is based on total count.

10
MCQeasy

A security administrator notices that traffic to a specific website is being denied. The traffic log shows that the application is 'ssl' and the action is 'deny' with the rule being 'Allow-SSL'. What is the most likely cause?

A.The destination IP is in a blacklist.
B.The security rule is placed too low in the rulebase.
C.The security rule 'Allow-SSL' has 'service' set to 'application-default' but the website uses port 8443.
D.The SSL certificate is expired.
AnswerC

With 'application-default' as the service, the rule permits only the standard ports for ssl (443). Traffic on port 8443 is not application-default, so it fails the service match and is denied despite the rule name.

Why this answer

The security rule 'Allow-SSL' is configured with 'service' set to 'application-default', which means it only permits traffic on the default port for SSL (TCP 443). Since the website uses port 8443, the traffic is denied because the rule does not match the non-standard port. The firewall's application identification still correctly identifies the traffic as 'ssl', but the service constraint prevents the rule from applying, resulting in a deny action.

Exam trap

The trap here is that candidates assume the 'Allow-SSL' rule should match all SSL traffic regardless of port, but Palo Alto Networks tests the nuance that 'application-default' restricts the rule to only the default port for that application, causing a deny on non-standard ports like 8443.

How to eliminate wrong answers

Option A is wrong because a blacklist would cause traffic to be denied by a different rule (e.g., a block rule based on IP), not by a rule named 'Allow-SSL' that is explicitly allowing SSL traffic. Option B is wrong because the rule is being matched (the log shows rule 'Allow-SSL'), so its position in the rulebase is irrelevant; the issue is that the rule's service condition is not satisfied. Option D is wrong because an expired SSL certificate would cause browser warnings or TLS handshake failures, but the firewall would still allow the traffic if the rule matches; the firewall does not validate certificate expiration at the rule enforcement level.

11
MCQeasy

A network engineer notices that traffic from an internal user to a web application is being incorrectly identified as 'web-browsing' instead of the custom application 'my-app'. The engineer has already created a custom application 'my-app' with the correct signature. What is the most likely reason for the misidentification?

A.The custom application is not activated in the security policy rule.
B.The application override is not configured.
C.The vulnerability protection profile is dropping the traffic.
D.The decryption policy is blocking the traffic.
AnswerB

Application override forces traffic on specified ports to be treated as the custom application, bypassing standard App-ID signature matching. Without it, the firewall continues classifying the session as web-browsing, so the custom my-app signature never applies to that traffic.

Why this answer

When a custom application is created with a signature, the firewall uses App-ID to identify the traffic based on the signature. However, if the traffic is still being misidentified as 'web-browsing', it means the firewall is matching the default HTTP/HTTPS application before the custom signature can be evaluated. An application override is required to explicitly tell the firewall to skip App-ID processing for that traffic and instead use the custom application 'my-app'.

Without the override, the firewall's default App-ID logic continues to classify the traffic based on its standard signatures.

Exam trap

The trap here is that candidates often think creating a custom application with a signature is sufficient for identification, but they overlook the need for an application override to bypass the default App-ID classification for traffic on standard ports like 80 or 443.

How to eliminate wrong answers

Option A is wrong because the custom application does not need to be 'activated' in a security policy rule; it is automatically available once created and committed, and the issue is about identification, not policy enforcement. Option C is wrong because a vulnerability protection profile drops traffic based on threats, not misidentification; it would not cause the traffic to be seen as 'web-browsing' instead of 'my-app'. Option D is wrong because the decryption policy controls whether traffic is decrypted or not, but it does not affect how App-ID classifies the application; misidentification occurs before decryption decisions are applied.

12
MCQhard

An organization uses User-ID with agent-based mapping on a Palo Alto Networks firewall. Users authenticate to a domain but some user-to-IP mappings are not showing up in the firewall's user cache. The firewall can reach the domain controllers. What is the most likely cause?

A.Panorama must be used to distribute User-ID configurations.
B.The firewall's DNS settings are incorrect, preventing user lookup.
C.The user-id mapping timeout is set too low.
D.The User-ID agent is not configured with the correct domain credentials or domain name.
AnswerD

Agent-based User-ID requires valid domain credentials and the correct domain name to query Active Directory and build user-to-IP mappings. Without them, the agent cannot resolve users even though network connectivity to the domain controllers exists.

Why this answer

The User-ID agent requires valid domain credentials and the correct domain name to query Active Directory for user-to-IP mappings. If these are misconfigured, the agent cannot authenticate to the domain controllers, and no mappings will be populated in the firewall's user cache, even though network connectivity exists.

Exam trap

The trap here is that candidates often assume connectivity issues (like DNS or reachability) are the cause, but the question explicitly states the firewall can reach the domain controllers, narrowing the focus to authentication and configuration of the User-ID agent itself.

How to eliminate wrong answers

Option A is wrong because Panorama is not required for User-ID configuration; User-ID can be configured directly on the firewall or via a separate User-ID agent. Option B is wrong because DNS settings affect hostname resolution, not the user-to-IP mapping process, which relies on the User-ID agent querying domain controllers via LDAP or NetAPI. Option C is wrong because a low timeout would cause mappings to expire prematurely, not prevent them from appearing initially.

13
MCQmedium

A company is experiencing intermittent connectivity issues between two branch offices connected via an IPSec tunnel. Users report that they can access resources for a few minutes, then lose connectivity, and after a short time it comes back. Which troubleshooting step should be taken first?

A.Check the traffic logs for any denial events
B.Check the IPSec tunnel status and IKE/IPSEC SA rekey timers
C.Reboot the firewall to clear any stale sessions
D.Verify the routing table on both firewalls
AnswerB

Intermittent drops that recover after minutes typically indicate IKE or IPSec security association rekeying failures or mismatched lifetimes. Checking tunnel status and rekey timers first confirms whether SAs expire and fail to renegotiate, directly addressing the recurring loss of connectivity described.

Why this answer

The intermittent connectivity pattern (works for a few minutes, drops, then recovers) strongly indicates a phase 2 (IPsec SA) rekey failure. When the IPsec SA lifetime expires and the rekey fails, traffic stops until the SA is re-established, causing the described symptoms. Checking the IKE/IPsec SA rekey timers is the first logical step because it directly addresses the most likely root cause without introducing unnecessary changes.

Exam trap

The trap here is that candidates often jump to routing or security rule checks, but the periodic nature of the outage is a classic symptom of IPsec SA rekey failure, not a routing or policy issue.

How to eliminate wrong answers

Option A is wrong because traffic logs showing denial events would indicate persistent blocking (e.g., by security rules), not the periodic connectivity pattern described; intermittent rekey failures do not generate consistent denial log entries. Option C is wrong because rebooting the firewall is a disruptive, non-diagnostic step that clears all sessions and logs, potentially destroying evidence of the rekey failure and delaying resolution. Option D is wrong because verifying the routing table checks for static or dynamic route stability, but routing is typically stable in a site-to-site VPN; the periodic nature of the issue points to a VPN rekey problem, not a routing change.

14
MCQmedium

A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?

A.SSL Decryption Exclusion list with the specific domain of the banking website.
B.SSL Forward Proxy setting with 'Strip TLS 1.3' enabled.
C.Decryption profile with 'Block sessions with untrusted issuers' enabled.
D.Decryption policy rule with action 'no-decrypt' and a URL category of 'financial-services'.
AnswerA

The SSL Decryption Exclusion list allows administrators to specify domains that should never be decrypted, based on the server certificate's CN or SAN. Adding the specific banking website's domain ensures that traffic to that site bypasses decryption, addressing privacy concerns. This is the most granular method for excluding individual sites without affecting others.

Why this answer

The SSL Decryption Exclusion list is designed to bypass decryption for specific domains based on the server certificate's CN or SAN. Adding the banking website's domain ensures that traffic to that site is not decrypted, addressing privacy concerns without affecting other traffic. Other options either apply too broadly, block traffic incorrectly, or do not provide selective exclusion.

Exam trap

The trap here is confusing the SSL Decryption Exclusion list with decryption policy rules; the exclusion list is specifically for excluding sites by domain without creating a policy rule.

15
MCQeasy

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?

A.SSL inbound certificate
B.Forward untrust certificate
C.Forward trust certificate
D.Root CA certificate
AnswerC

The forward trust certificate is used by the firewall to sign the certificates it presents to internal clients when decrypting outbound SSL traffic. It must be a CA certificate and be trusted by the clients. This certificate enables the firewall to act as a proxy and establish separate SSL connections with the client and the server.

Why this answer

The forward trust certificate is specifically designed for SSL Forward Proxy decryption. It is a CA certificate that the firewall uses to sign the certificates presented to internal users. Clients must trust this certificate to avoid errors.

The forward untrust certificate is used for untrusted server certificates, and the SSL inbound certificate is for inbound inspection.

Exam trap

The trap here is confusing the forward trust certificate with the forward untrust certificate or the SSL inbound certificate, which serve different purposes in decryption.

16
MCQhard

An organization is implementing SSL Forward Proxy decryption to inspect outbound HTTPS traffic. They want to exclude traffic to specific internal applications that cannot handle decryption due to certificate pinning. The firewall is configured with a decryption policy that decrypts all traffic from the internal network to the internet. To exclude the pinned applications, which approach is best practice?

A.Create a custom URL category for the applications and add it to a decryption policy rule with action 'no-decrypt'.
B.Configure an SSL/TLS Service Profile with an exception list for the destination IPs.
C.Use GlobalProtect client settings to bypass decryption for the pinned applications.
D.Reduce the SSL/TLS protocol version on the decryption policy to cause fail-closed for those applications.
AnswerA

A custom URL category listing the pinned applications, referenced by a no-decrypt rule placed above the decrypt-all rule, excludes them cleanly. This satisfies the certificate-pinning constraint without weakening decryption coverage for all other outbound HTTPS traffic.

Why this answer

Creating a custom URL category for the pinned applications and referencing it in a decryption policy rule with action 'no-decrypt' is the best practice for excluding specific traffic from SSL Forward Proxy decryption. This approach allows the firewall to selectively bypass decryption based on the destination URL, which is more granular and manageable than IP-based exceptions, and it aligns with the decryption policy's ability to match traffic by URL category.

Exam trap

The trap here is that candidates often confuse the SSL/TLS Service Profile's exception list (used for inbound decryption) with forward proxy decryption, leading them to select Option B, but the exception list does not apply to outbound SSL Forward Proxy policies.

How to eliminate wrong answers

Option B is wrong because an SSL/TLS Service Profile's exception list is used to exclude specific destination IPs from SSL/TLS termination for inbound decryption (e.g., for SSL Inbound Inspection), not for outbound SSL Forward Proxy decryption; it does not apply to forward proxy scenarios. Option C is wrong because GlobalProtect client settings control VPN tunnel behavior and client-level security policies, but they cannot bypass firewall-level decryption policies; decryption is enforced at the firewall, not the client. Option D is wrong because reducing the SSL/TLS protocol version on the decryption policy would cause the firewall to fail to negotiate a secure connection with the server, potentially breaking all HTTPS traffic to those applications, not just excluding them; it does not provide a selective 'no-decrypt' mechanism.

17
MCQeasy

Refer to the exhibit. The firewall's disk usage is at 85% overall, and the /opt/panlogs partition is at 92%. The administrator wants to free up space without losing important log data. Which action should be taken first?

A.Configure log auto-deletion in the Log Settings to purge logs older than a specified period
B.Add an external storage device to the firewall
C.Delete configuration files from /opt/pancfg
D.Delete the /opt/panlogs directory and recreate it
AnswerA

Auto-deletion targets the /opt/panlogs partition directly, purging the oldest logs first to reclaim space while retaining recent entries. It satisfies the constraint of freeing space without losing important log data, and is non-destructive compared with manual deletion or reformatting.

Why this answer

Configuring log auto-deletion in the Log Settings allows the administrator to automatically purge older logs based on a specified retention period, freeing up disk space on the /opt/panlogs partition without manually deleting important log data. This is the safest and most controlled method, as it respects the firewall's log management policies and ensures compliance with data retention requirements.

Exam trap

Palo Alto Networks often tests the misconception that deleting configuration files or directories is a valid troubleshooting step, when in fact the correct approach is to use built-in log management features like auto-deletion to safely reclaim space without data loss.

How to eliminate wrong answers

Option B is wrong because adding an external storage device does not free up existing disk space; it only provides additional capacity, and the immediate issue of 92% usage on /opt/panlogs remains unresolved. Option C is wrong because deleting configuration files from /opt/pancfg would remove critical firewall configuration data, potentially causing operational failures or loss of policy settings, and it does not address the log partition issue. Option D is wrong because deleting the /opt/panlogs directory and recreating it would permanently remove all log data, which violates the requirement to not lose important log data, and may also disrupt logging services until the directory is properly recreated with correct permissions.

18
MCQmedium

A security engineer is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for inspection. The firewall is deployed in a forward proxy mode. The engineer wants to ensure that the firewall can decrypt traffic without generating certificate errors on client browsers. Which configuration is required to achieve this?

A.Install the forward trust certificate on the firewall and distribute the forward untrust certificate to all client devices.
B.Install the forward untrust certificate on the firewall and distribute the forward trust certificate to all client devices.
C.Install the forward trust certificate on the firewall and distribute it to all client devices as a trusted root CA certificate.
D.Install the forward trust certificate on the firewall and configure the clients to use the firewall as a proxy server for all SSL connections.
AnswerC

For SSL forward proxy decryption, the firewall uses the forward trust certificate to generate a certificate for each server and sign it. For clients to trust this dynamically generated certificate, the forward trust certificate must be installed as a trusted root CA on the client devices. This prevents certificate errors and allows decryption to occur seamlessly.

Why this answer

In SSL forward proxy decryption, the firewall acts as a man-in-the-middle, decrypting traffic, inspecting it, and re-encrypting it. To prevent certificate warnings, the firewall uses a forward trust certificate to sign the certificates it presents to clients. For clients to trust these certificates, the forward trust certificate must be installed as a trusted root CA on each client device.

This is a fundamental requirement for transparent SSL decryption without user disruption.

Exam trap

The trap here is confusing the roles of the forward trust and forward untrust certificates; the forward trust certificate must be trusted by clients, while the forward untrust certificate is used when the server certificate is untrusted.

19
MCQmedium

An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?

A.The user's browser is set to reject all cookies.
B.The LDAP server is overloaded and timing out.
C.The captive portal page is not being cached by the browser.
D.The session timeout on the captive portal authentication profile is set too low (e.g., 5 minutes).
AnswerA

Correct. If the browser rejects cookies, the initial authentication may succeed (the captive portal page often does not require a cookie for login), but subsequent HTTP requests lack the session cookie, causing the firewall to re-prompt for credentials on each request.

Why this answer

Captive portal authentication relies on a browser cookie to maintain the authenticated session after the initial login. If the user's browser rejects all cookies, the portal cannot store the session token, so each subsequent request appears unauthenticated and the user is prompted to log in again. The initial login succeeds because credentials are validated, but the session cannot persist without the cookie.

Exam trap

PCNSE often tests whether candidates overlook client-side browser settings (like cookie rejection) and instead blame server-side timeouts or LDAP issues, even when the symptoms clearly point to session persistence failure.

How to eliminate wrong answers

Option B is wrong because an overloaded LDAP server would cause authentication failures or timeouts, not repeated prompts after a successful login. Option C is wrong because caching the captive portal page is unrelated to session persistence; the issue is cookie storage, not page caching. Option D is wrong because the question states the session timeout is 60 minutes, and the prompts occur every few minutes, so a low timeout is not the cause (and the stated timeout is not low).

20
Multi-Selecthard

Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)

Select 3 answers
A.Dead peer detection interval
B.IKE encryption algorithm
C.IKE authentication algorithm
D.Local certificate
E.IKE version (v1 or v2)
AnswersB, C, E

IKE encryption algorithm must match because it secures Phase 1 negotiation itself; mismatched ciphers cause the peers to reject each other's proposals before any tunnel forms. This satisfies the stem's requirement that both peers agree on identical Phase 1 parameters for successful IPsec establishment.

Why this answer

Option B (IKE encryption algorithm) is correct because both peers must agree on the same Phase 1 encryption algorithm (e.g., AES-256) in their IKE proposals; a mismatch causes the ISAKMP/IKE SA negotiation to fail. Option C (IKE authentication algorithm) is correct because the Phase 1 integrity/hash algorithm (e.g., SHA-256) must match on both peers for the IKE SA to be established. Option E (IKE version v1 or v2) is correct because IKEv1 and IKEv2 are incompatible protocols; peers must run the same version to negotiate the tunnel.

Option A (dead peer detection interval) is not required to match, since DPD timers are locally significant and can differ between peers without preventing tunnel establishment. Option D (local certificate) is not required to match, because each peer presents its own identity credential; certificates need only be trusted/validated, not identical.

Exam trap

The trap here is that candidates often confuse 'factors that must match' with 'factors that can be different'—DPD intervals and certificate requirements are not mandatory for tunnel establishment, while IKE version, encryption, and authentication algorithms are non-negotiable.

21
MCQhard

Refer to the exhibit. An administrator notices that HTTPS traffic to a specific website is being denied. What is the most likely cause?

A.The HTTPS traffic is being identified as web-browsing instead of ssl, so it does not match rule 2 and is denied by rule 3.
B.Rule 2 does not have a service set to application-default, so it cannot match the traffic.
C.The traffic is from trust to trust, matching rule 4, but still denied.
D.The traffic requires a specific service other than application-default.
AnswerA

When HTTPS uses no SNI or the firewall cannot inspect it, App-ID classifies the session as web-browsing on port 443 rather than ssl. The rule expecting ssl does not match, so the session falls through to the deny rule, explaining the denial.

Why this answer

When App-ID identifies HTTPS traffic as web-browsing (HTTP over port 443) instead of ssl, the traffic does not match rule 2 (which requires the 'ssl' application). Consequently, it falls through to rule 3, which denies the traffic. This misidentification often occurs when the SSL handshake is incomplete or when decryption is not configured, causing the firewall to classify the traffic based on the port rather than the application signature.

Exam trap

A common trap is to assume that the service setting (application-default) is required for App-ID to match traffic, when the real issue is application misidentification due to incomplete SSL inspection or port-based fallback.

How to eliminate wrong answers

Option B is wrong because rule 2 does not need a service set to application-default; the service setting is used for port-based matching, but App-ID can match applications regardless of the service if the application is correctly identified. Option C is wrong because the traffic is from trust to untrust (as indicated by the exhibit showing source zone trust and destination zone untrust), not trust to trust, so rule 4 does not apply. Option D is wrong because the issue is not about requiring a specific service; the traffic is being denied because App-ID misclassifies it as web-browsing, not because of a missing service definition.

22
MCQhard

A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?

A.Create a decryption profile that excludes the failing domains
B.Disable SSL decryption for all traffic
C.Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule
D.Replace the firewall's internal CA certificate with a publicly trusted certificate
AnswerC

Decryption policy rules are evaluated top-down, so the global decrypt rule above the exclusions matches first and decrypts the banking traffic anyway. Moving the exclusion rules above it lets those domains bypass SSL Forward Proxy, resolving the certificate errors caused by pinned or untrusted certificates.

Why this answer

Palo Alto Networks decryption policy rules are evaluated in top-down order, and the first matching rule is applied. Since the exclusion rules are placed below the global decrypt rule that decrypts all SSL traffic, the global rule matches first and decrypts the traffic, causing certificate errors on sites that require specific handling. Reordering the exclusion rules above the global rule ensures they are evaluated first, allowing the affected domains to bypass decryption and load correctly.

Exam trap

The trap here is that candidates often confuse decryption profiles with decryption policy rules, thinking a profile can exclude domains, when in fact domain exclusion is strictly a function of rule ordering in the decryption policy.

How to eliminate wrong answers

Option A is wrong because a decryption profile can control cipher strength or block expired certificates, but it cannot exclude domains from decryption; domain exclusion is handled by decryption policy rules, not profiles. Option B is wrong because disabling SSL decryption for all traffic would break the security inspection for all HTTPS traffic, which is an overreaction and not necessary when only a few specific sites are affected. Option D is wrong because replacing the internal CA certificate with a publicly trusted certificate would not resolve certificate errors caused by decryption of sites that pin certificates or use client certificates; the issue is policy ordering, not CA trust.

23
Multi-Selecthard

A Palo Alto Networks firewall administrator is troubleshooting why a session was terminated with the flag 'tcp-rst-from-client'. The administrator wants to identify possible causes for this termination flag. Which two factors can cause a session to be terminated with 'tcp-rst-from-client'? (Choose two.)

Select 2 answers
A.The client application was closed abruptly, causing the operating system to send a RST.
B.The firewall's security policy blocked the traffic, causing the client to send a RST.
C.The client's TCP window size was reduced to zero, triggering a RST from the client.
D.The client's TCP stack received a SYN-ACK for a connection that it did not initiate, prompting a RST.
E.The client received a packet that was out of order and sent a RST in response.
AnswersA, D

When a client application is closed abruptly (e.g., killed via Task Manager), the operating system may send a TCP RST to tear down the connection instead of a normal FIN. This results in a session termination with 'tcp-rst-from-client'. This is a common cause and should be considered when troubleshooting such flags.

Why this answer

The 'tcp-rst-from-client' flag indicates that the client sent a TCP RST packet. Common causes include the client application being closed abruptly, leading the OS to send a RST, or the client receiving a SYN-ACK for a connection it did not initiate, which triggers a RST. Other options like out-of-order packets or zero window do not cause RSTs.

Security policy blocks would result in a different flag. Therefore, the correct factors are abrupt application closure and unexpected SYN-ACK.

Exam trap

The trap here is assuming that any abnormal termination involves a RST, when in fact RSTs are specific to certain TCP state violations or application closures.

24
MCQmedium

During an audit, it is discovered that some traffic from a legacy application is being incorrectly identified as 'ssl' because the application uses a custom encryption scheme over TCP port 443. The engineer has created a custom application signature that matches the legacy application's handshake. What additional configuration is needed to ensure the legacy application is correctly identified?

A.Create an application override rule to force the identification.
B.Create a security policy rule that explicitly allows the custom application.
C.Change the default port of the custom application from 443 to a different port.
D.Disable SSL decryption for that traffic.
AnswerA

An application override rule forces the firewall to classify matching traffic as the specified custom application, bypassing App-ID's signature-based inspection entirely. Since the legacy application's custom encryption on port 443 causes App-ID to misidentify it as 'ssl', the override satisfies the requirement to correctly identify this traffic by explicitly binding it to the custom signature.

Why this answer

An application override rule forces App-ID to classify traffic based on the custom signature, bypassing the default identification that incorrectly flags the legacy application's custom encryption over TCP 443 as 'ssl'. Without the override, App-ID may still match the traffic to the built-in 'ssl' application due to port-based heuristics, even with a custom signature defined. The override ensures the custom application is applied to the session, overriding any conflicting App-ID results.

Exam trap

The trap here is that candidates assume creating a custom signature alone is sufficient to reclassify traffic, but they overlook that App-ID's port-based heuristics for well-known ports like 443 can override signature matches unless an explicit application override is configured.

How to eliminate wrong answers

Option B is wrong because creating a security policy rule that explicitly allows the custom application does not change how App-ID identifies the traffic; the traffic would still be misidentified as 'ssl' and might be blocked or logged incorrectly. Option C is wrong because changing the default port of the custom application from 443 to a different port does not address the misidentification; the legacy application still uses TCP 443, and App-ID would continue to see the traffic on that port, potentially matching 'ssl' again. Option D is wrong because disabling SSL decryption does not affect App-ID identification; decryption is a separate function that inspects encrypted payloads, but the custom encryption scheme is not SSL/TLS, so decryption would fail or be irrelevant, and the traffic would still be misidentified as 'ssl'.

25
MCQeasy

When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?

A.The certificate is expired
B.The portal authentication profile requires both certificate and password
C.The client certificate does not match the username
D.The root CA certificate is not imported into the firewall
AnswerB

The portal authentication profile governs which credential factors the client must supply. If it is set to require both certificate and password, the client prompts for credentials even when a valid certificate is present. Removing the password requirement restores certificate-only authentication.

Why this answer

When a GlobalProtect portal authentication profile is configured to require both certificate and password, the client will prompt for username and password even if a valid certificate is present. This is because the authentication profile explicitly enforces multi-factor authentication, meaning the certificate alone is insufficient for portal authentication. The client must satisfy all configured authentication factors before proceeding.

Exam trap

The trap here is that candidates often assume a valid certificate alone should suffice for authentication, overlooking that the portal authentication profile can be configured to require additional factors like a password, which forces the client to prompt for credentials regardless of certificate validity.

How to eliminate wrong answers

Option A is wrong because an expired certificate would typically result in an authentication failure or error message, not a prompt for username and password; the client would reject the certificate outright. Option C is wrong because a certificate that does not match the username would cause a certificate validation failure or mismatch error, not a username/password prompt; the client would not fall back to credential-based authentication. Option D is wrong because if the root CA certificate is not imported into the firewall, the firewall cannot validate the client certificate, leading to a certificate validation failure, not a prompt for credentials; the connection would be rejected.

26
MCQmedium

Refer to the exhibit. A user at 10.1.1.10 is trying to connect to a web server at 203.0.113.5 on port 443. The session shows 'State: DROP' with reason 'policy-deny'. However, the administrator has a security policy rule that allows SSL traffic from the source zone to the destination zone. What is the most likely cause of the drop?

A.The source NAT rule is missing, so the private IP cannot reach the internet.
B.The security policy rule that allows SSL is in a different rulebase or zone than the traffic.
C.The SSL application is not correctly identified because the traffic is encrypted.
D.The firewall is configured to block SSL sessions that use weak ciphers.
AnswerB

A policy-deny drop despite an apparent allow rule indicates the matching rule sits in a different rulebase or zone context than the traffic traversing the firewall. Zone and rulebase membership determine which rules are evaluated for a given session.

Why this answer

The session shows 'policy-deny' with a DROP state, which indicates that the traffic matched a deny rule or did not match any allow rule in the security policy. Even though the administrator believes an SSL allow rule exists, the most common cause is that the rule is in a different rulebase (e.g., pre-rulebase or post-rulebase) or the traffic is traversing a different zone pair than the one the rule applies to. The firewall evaluates rules in a specific order (pre-rulebase, then rulebase, then post-rulebase), and if the rule is not in the correct location for the traffic's ingress and egress zones, it will not be matched, resulting in a policy-deny drop.

Exam trap

The trap here is that candidates assume a security policy rule exists globally, but the PCNSE exam tests the understanding that rules are zone-specific and rulebase-specific, so a rule in the wrong zone pair or rulebase will not be matched, leading to a policy-deny drop.

How to eliminate wrong answers

Option A is wrong because a missing source NAT rule would cause a different symptom: the session would show a 'nat-ip-alloc' failure or a 'no-route' drop, not a 'policy-deny' drop. Option C is wrong because the firewall can still match a security policy rule based on the destination port (443) and IP addresses even if the application is encrypted; SSL decryption is not required for policy matching. Option D is wrong because blocking weak ciphers is a function of SSL decryption profiles or SSL Forward Proxy settings, not a direct cause of a 'policy-deny' drop; such a block would result in a 'decrypt' or 'ssl' related drop reason, not 'policy-deny'.

27
MCQmedium

A network security engineer is deploying a PA-5220 firewall in a data center. The firewall must inspect traffic between two internal segments (trust and dmz) and also provide security for outbound internet access. The engineer wants to ensure that when a packet arrives, the firewall properly identifies the application and enforces security policies. Which component is responsible for identifying the application regardless of port, protocol, or encryption?

A.Content-ID
B.App-ID
C.SSL Decryption
D.User-ID
AnswerB

App-ID is the Palo Alto Networks traffic classification engine that identifies applications traversing the firewall by analyzing multiple attributes such as protocol, port, and behavior, even if the application uses non-standard ports or encryption. It enables policy enforcement based on the actual application, not just port. In this scenario, App-ID ensures accurate identification for both internal and internet-bound traffic.

Why this answer

App-ID is the core technology that identifies applications by analyzing traffic characteristics, not just ports. It is essential for enforcing application-based security policies. Content-ID, User-ID, and SSL Decryption are supporting technologies that operate after or alongside App-ID but do not perform application identification themselves.

Therefore, App-ID is the correct component for application identification.

Exam trap

The trap here is confusing App-ID with Content-ID or SSL Decryption, thinking that decryption or content inspection alone can identify applications.

28
Multi-Selectmedium

A security engineer is troubleshooting a traffic drop issue on a Palo Alto Networks firewall. The traffic is allowed by the security policy, but the session is being terminated. Which two features could cause this behavior? (Choose two.)

Select 2 answers
A.DoS Protection
B.User-ID
C.SSL Decryption
D.URL Filtering
E.Zone Protection Profile
AnswersA, E

DoS Protection can actively terminate sessions exceeding thresholds.

Why this answer

A DoS Protection profile can terminate sessions that exceed configured thresholds for rate, connection count, or other attack-related criteria, even if the security policy explicitly allows the traffic. When the firewall detects that a session matches a DoS Protection rule and the traffic rate or concurrent session count surpasses the defined threshold, it will drop the session to mitigate the attack, overriding the allow action from the security policy.

Exam trap

The trap here is that candidates often assume only security policy rules control traffic flow, forgetting that additional security features like DoS Protection and Zone Protection Profiles can override an allow action by terminating sessions based on rate limits or attack signatures.

29
MCQmedium

A security engineer is configuring a security policy to allow only the specific business application 'salesforce' while blocking all other applications that use HTTPS. The firewall is not performing SSL decryption. What will be the result of the security policy?

A.The policy will allow all HTTPS traffic because salesforce is not identifiable.
B.The policy may not work as intended because salesforce traffic will be identified as ssl or web-browsing without decryption.
C.The policy will correctly allow salesforce and block other HTTPS applications.
D.The policy will block all HTTPS traffic because salesforce cannot be identified.
AnswerB

Without SSL decryption, the firewall cannot inspect the encrypted payload to identify salesforce. The traffic will likely be identified as 'ssl' or 'web-browsing', not 'salesforce'. As a result, the security policy allowing salesforce will not match, and the traffic may be blocked or allowed by other rules, leading to unintended behavior.

Why this answer

Without SSL decryption, App-ID cannot see inside the encrypted HTTPS session to identify the specific application. The traffic will be classified as 'ssl' or 'web-browsing', so a policy that allows 'salesforce' will not match. This means the policy will not work as intended, and the engineer must either enable decryption or adjust the policy to account for the limited visibility.

Exam trap

The trap here is believing that App-ID can identify all applications even when encrypted; in reality, many SaaS applications require decryption to be accurately identified.

30
MCQhard

A network engineer is configuring a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party VPN peer. The engineer wants to ensure that the firewall can establish the tunnel even if the peer initiates the connection. Which configuration is required on the Palo Alto Networks firewall?

A.Configure the IKE gateway with a static peer IP address and enable 'Passive' mode.
B.Configure the IPsec tunnel with 'Auto Key' and enable 'Responder Only' mode.
C.Configure the IKE gateway with a dynamic peer IP address and enable 'Aggressive' mode.
D.Configure the IKE gateway with a static peer IP address and ensure that the pre-shared key and proposals match the peer.
AnswerD

For the firewall to establish a tunnel, the IKE gateway must be configured with the peer IP address (static or dynamic) and the correct pre-shared key and proposals. The firewall will respond to IKE requests from the peer if the gateway configuration matches. No special mode is required to accept peer-initiated connections; the firewall can initiate or respond by default.

Why this answer

In Palo Alto Networks, an IKE gateway configured with a static peer IP address and matching pre-shared key and proposals will accept IKE requests from that peer. The firewall does not require a special mode to respond to peer-initiated connections; it can act as both initiator and responder. The key is that the gateway configuration must match the peer's settings.

Exam trap

The trap here is thinking that a special mode like 'Passive' or 'Responder Only' is needed for the firewall to accept peer-initiated connections, when actually the standard gateway configuration suffices.

31
MCQmedium

A security engineer wants to identify applications in SSL/TLS encrypted traffic without decrypting the payload. Which method can be used?

A.Deploy a network tap to capture traffic
B.Use App-ID's encrypted traffic detection capabilities
C.Configure the firewall to trust all certificates
D.Implement SSL Forward Proxy decryption
AnswerB

App-ID inspects TLS handshake metadata — server name indication, certificate fields and JA3 fingerprints — plus packet patterns, identifying the application without decrypting payload. This satisfies the requirement to classify encrypted traffic while preserving privacy and avoiding decryption overhead.

Why this answer

App-ID's encrypted traffic detection capabilities allow the firewall to identify applications within SSL/TLS encrypted flows without decrypting the payload. It uses techniques such as server name indication (SNI) inspection, certificate field analysis, and JA3/JA3S fingerprinting to match traffic to known applications, even when the content is encrypted.

Exam trap

The trap here is that candidates often assume application identification in encrypted traffic always requires decryption, overlooking that metadata from the TLS handshake can be used for identification without breaking encryption.

How to eliminate wrong answers

Option A is wrong because deploying a network tap only captures raw packets; it does not provide application identification without additional decryption or deep packet inspection. Option C is wrong because configuring the firewall to trust all certificates would bypass certificate validation, creating a security vulnerability and still not enabling application identification without decryption. Option D is wrong because SSL Forward Proxy decryption explicitly decrypts the payload to inspect it, which the question states should be avoided.

32
Multi-Selecthard

Which THREE factors should be considered when designing an authentication policy for a multi-zone environment with varied security requirements? (Choose THREE.)

Select 3 answers
A.Source zone
B.User-ID
C.Schedule
D.Application ID
E.Destination zone
AnswersA, C, E

Source zone is a key condition in authentication policies.

Why this answer

A is correct because source zone is a critical factor in authentication policy design, as it determines which traffic entering from specific zones (e.g., Untrust, DMZ) must be authenticated. In a multi-zone environment, different zones have varying trust levels, so authentication policies must be scoped to source zones to enforce access controls appropriately. Without source zone consideration, traffic from low-trust zones could bypass authentication, violating security requirements.

Exam trap

The trap here is that candidates often confuse User-ID as a design factor for authentication policies, when in fact User-ID is a post-authentication mapping mechanism, not a condition that defines when authentication is triggered.

33
MCQhard

An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?

A.The source address 10.0.0.0/8 is not included in the source zone.
B.The destination address is set to 'any', which is not valid.
C.The traffic is intra-zone, not inter-zone.
D.A rule with a 'deny' action appears earlier in the security policy.
AnswerD

Palo Alto Networks evaluates security policy top-down and stops at the first matching rule. A deny rule positioned above the intended allow rule matches the traffic first, so the allow rule never appears in the log as a hit, explaining the observed denial.

Why this answer

The most likely reason the inter-zone rule is not matched is that a preceding rule with a 'deny' action is matching the traffic first. In Palo Alto Networks firewalls, security rules are evaluated in order from top to bottom, and the first matching rule determines the action. If an earlier rule denies the traffic, the later allow rule will never be evaluated, even if it would otherwise match.

Exam trap

The trap here is that candidates often assume the rule itself is misconfigured (e.g., source or destination issues) rather than recognizing that a higher-priority deny rule is preempting the intended allow rule.

How to eliminate wrong answers

Option A is wrong because the source address 10.0.0.0/8 is a prefix, not a zone; the source zone is 'Trust', and the rule's source address is independent of whether the address is included in the zone definition. Option B is wrong because 'any' is a valid destination address in a security rule, meaning all destinations are matched. Option C is wrong because the traffic is explicitly described as inter-zone (Trust to Untrust), and intra-zone traffic would involve the same zone, which is not the case here.

34
Multi-Selecteasy

Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?

Select 2 answers
A.Decryption Broker
B.SSL Forward Proxy
C.SSL Termination
D.SSH Proxy
E.SSL Inbound Inspection
AnswersB, E

Correct: SSL Forward Proxy decrypts outbound traffic from internal clients to external servers.

Why this answer

B is correct because SSL Forward Proxy allows the firewall to decrypt outbound traffic from internal clients to external servers by acting as an intermediary, generating a new certificate on the fly to inspect the session. E is correct because SSL Inbound Inspection enables the firewall to decrypt inbound traffic destined for protected servers, typically by importing the server's private key, allowing inspection of encrypted payloads.

Exam trap

The trap here is that candidates often confuse 'SSL Termination' (a load-balancer concept) with 'SSL Inbound Inspection' (a firewall decryption feature), or mistakenly think 'Decryption Broker' is a Palo Alto Networks feature when it is actually a third-party architecture.

35
MCQeasy

Refer to the exhibit. What does the uptime indicate?

A.The firewall license is about to expire.
B.The firewall is in active-passive HA mode.
C.The firewall has high memory usage.
D.The firewall has been restarted approximately 3 hours ago.
AnswerD

The uptime counter resets to zero whenever the dataplane restarts, so a value near three hours indicates the firewall was rebooted roughly that long ago. It reflects process restart time, not total device age or configuration commit history.

Why this answer

The uptime displayed in the exhibit shows the firewall has been running for approximately 3 hours. This directly indicates that the firewall was restarted or rebooted about 3 hours ago, making option D correct. Uptime is a measure of time since the last system boot, not related to licensing, HA mode, or memory usage.

Exam trap

The trap here is that candidates may confuse uptime with license expiration or HA status, but uptime is solely a measure of system runtime since last boot and has no bearing on licensing, HA mode, or memory usage.

How to eliminate wrong answers

Option A is wrong because license expiration is shown under 'License' or 'Device > Licenses', not in the uptime field; uptime only reflects system runtime since last boot. Option B is wrong because active-passive HA mode is indicated by HA configuration and state (e.g., 'active-passive' in HA settings), not by uptime; uptime values are independent of HA role. Option C is wrong because high memory usage is monitored via 'Device > Resources' or CLI commands like 'show system resources', not by uptime; uptime does not correlate with memory consumption.

36
MCQeasy

A SOC analyst reports that a critical security policy rule denying traffic from the 'Untrust' zone to the 'DMZ' zone is not generating any traffic logs, even though the analyst sees a high volume of denied traffic in other tools. The administrator confirms that the rule is correctly configured to deny and that logging is enabled at the rule level. What is the most likely reason for the missing logs?

A.The 'Untrust' zone is not configured to log traffic, and zone-level logging overrides rule-level logging.
B.The security policy rule is not being matched because the traffic is being denied by a different rule or a default rule with logging disabled.
C.The firewall's log storage is full, so new logs are being dropped.
D.The firewall is in a high-availability active-passive pair, and logs are only generated on the active device.
AnswerB

If the traffic is not matching the specific deny rule, it could be denied by an earlier rule or the default interzone/intrazone rule, which may not have logging enabled. The default rules often do not log by default. This would explain why the analyst sees denied traffic elsewhere but not from this rule. The administrator should check the session browser or traffic logs to see which rule is actually denying the traffic.

Why this answer

The most likely reason is that the traffic is being denied by a different rule, such as a default rule or an earlier rule in the policy, which does not have logging enabled. The administrator should verify which rule is actually matching the traffic by checking the session browser or traffic logs. This is a common oversight when a specific deny rule does not seem to be logging, despite being configured to do so.

Exam trap

The trap here is assuming that because a rule is configured to deny and log, it must be the rule that is matching the traffic, when in fact another rule or default rule could be denying the traffic without logging.

37
Multi-Selecthard

Which TWO configurations are required for User-ID to work using the Windows User-ID Agent (WUA) in a distributed environment?

Select 2 answers
A.The User-ID Agent must have permissions to query Active Directory domain controllers.
B.Firewalls must be configured to send User-ID data to the Agent via Server Monitoring.
C.An Application Override policy must be created for User-ID traffic.
D.The firewall must be able to reach the User-ID Agent's IP address on TCP port 5007.
E.The User-ID Agent must be in the same Layer 2 subnet as the users.
AnswersA, D

User-ID Agent queries DCs for user logon events.

Why this answer

The Windows User-ID Agent (WUA) must have permissions to query Active Directory (AD) domain controllers to retrieve user login events (e.g., security event ID 4624). Without these permissions, the agent cannot map IP addresses to usernames, which is the core function of User-ID in a distributed environment.

Exam trap

The trap here is that candidates often confuse the direction of data flow, thinking the firewall sends data to the agent (Option B), or assume the agent must be on the same subnet as users (Option E), when in fact the agent only needs network reachability and AD query permissions.

38
MCQeasy

A company wants to authenticate users who are accessing internal applications from the internet through a firewall. The users should be prompted once per session. Which authentication solution best meets this requirement?

A.SAML authentication with single sign-on.
B.LDAP authentication with a timeout.
C.Captive Portal with session cookie.
D.RADIUS authentication with one-time passwords.
AnswerA

SAML authentication with single sign-on satisfies the once-per-session constraint by issuing a signed assertion after the initial Microsoft Entra ID login, which the firewall validates for subsequent application requests without re-prompting. This differs from per-request authentication methods such as captive portal or client certificate checks that re-authenticate each connection.

Why this answer

SAML authentication with single sign-on (SSO) allows users to authenticate once per session via an external identity provider (IdP). The firewall validates the SAML assertion and maintains the session, so users are not prompted again until the session expires or is terminated. This meets the requirement of a single prompt per session without re-authentication.

Exam trap

The trap here is that candidates often confuse 'session cookie' (Option C) with single sign-on, but Captive Portal cookies only cover the firewall's own session tracking and do not provide federated authentication across multiple applications, whereas SAML SSO does.

How to eliminate wrong answers

Option B is wrong because LDAP authentication with a timeout does not inherently provide single sign-on; it requires the firewall to prompt for credentials on each new session or after timeout, not once per session. Option C is wrong because Captive Portal with session cookie still prompts the user for credentials at the start of each new TCP connection or after cookie expiration, and it does not provide true session-level single sign-on across applications. Option D is wrong because RADIUS authentication with one-time passwords (OTP) requires a new OTP for each authentication attempt, which would prompt the user multiple times per session, not once.

39
MCQhard

A GlobalProtect gateway is configured as shown. Remote users report that they can connect to the gateway but cannot authenticate. The users are using the GlobalProtect client with certificate authentication. What is the most likely cause?

A.The IPSec crypto profile is too strong for the clients.
B.The IP pool is exhausted.
C.The DNS server is misconfigured, causing authentication failure.
D.The gateway does not have a root CA certificate imported for validating client certificates.
AnswerD

Without a trusted root CA certificate, the gateway cannot build a chain to validate the client certificates presented during the TLS handshake. Certificate authentication therefore fails after the tunnel connects, matching the reported symptom of connecting but not authenticating. Importing the issuing root CA under Device > Certificate Management resolves this.

Why this answer

For certificate-based authentication, the GlobalProtect gateway must trust the certificate presented by the client. This requires the gateway to have the root CA certificate that issued the client certificate imported into its trusted CA list. Without this root CA, the gateway cannot validate the client's certificate chain, causing authentication to fail even though the initial connection (e.g., IPSec tunnel establishment) succeeds.

Exam trap

The trap here is that candidates assume the connection success (tunnel established) means authentication should work, but certificate authentication requires a separate trust validation step that fails if the root CA is not imported on the gateway.

How to eliminate wrong answers

Option A is wrong because an IPSec crypto profile that is 'too strong' would prevent the client and gateway from agreeing on security parameters, causing the tunnel to fail entirely—not just authentication. Option B is wrong because an exhausted IP pool would prevent the client from obtaining an IP address after authentication, but the user would still be able to authenticate successfully. Option C is wrong because a misconfigured DNS server would affect name resolution (e.g., for portal/gateway FQDN) but does not directly impact the certificate validation process during authentication.

40
Multi-Selecthard

A network administrator is configuring a new Palo Alto Networks firewall in a high-availability active/passive setup. The firewall will be placed in Layer 3 mode. Which THREE steps are required to ensure proper operation? (Choose three.)

Select 3 answers
A.Configure a virtual router and assign interfaces
B.Configure the HA1 link and HA1 backup link
C.Enable aggregate Ethernet on all interfaces
D.Set up a management profile for each interface
E.Configure a floating IP for the active firewall
AnswersA, B, E

Virtual router is required for Layer 3 routing.

Why this answer

In Layer 3 mode, a virtual router must be configured to enable the firewall to participate in IP routing. The virtual router handles route learning, static routes, and route redistribution, and each Layer 3 interface must be assigned to a virtual router to forward traffic. Without this, the firewall cannot route packets between zones.

Exam trap

The trap here is that candidates often think aggregate Ethernet or management profiles are mandatory for HA or Layer 3 operation, but they are optional features that do not affect basic routing or HA failover functionality.

41
Multi-Selectmedium

An organization has configured an active/passive high availability pair of Palo Alto Networks firewalls. During a maintenance window, the active firewall was rebooted. After the reboot, the passive firewall became active, but the session table on the original active firewall is incomplete. The administrator notices that session synchronization is not working properly. Which two configuration checks should the technician perform to resolve this issue?

Select 2 answers
A.Check that the session synchronization encryption is disabled to reduce latency.
B.Validate that the heartbeat hold timer is set to a value greater than the failover delay.
C.Confirm that the HA1 link is using the correct IP address and is in the same subnet.
D.Verify that the HA2 link is operational and has sufficient bandwidth.
E.Ensure that the HA firewalls have the same software version and that session synchronization is enabled in the HA configuration.
AnswersD, E

The HA2 link is dedicated to session synchronization; if it is down or congested, sync fails.

Why this answer

Session synchronization in an active/passive HA pair uses the HA2 link (or HA2 backup) to replicate session tables between firewalls. If the HA2 link is down, has insufficient bandwidth, or is misconfigured, session synchronization will fail, causing the newly active firewall to have an incomplete session table after a failover. Verifying that the HA2 link is operational and has sufficient bandwidth is therefore a critical first step in troubleshooting this issue.

Exam trap

The trap here is that candidates often confuse the HA1 and HA2 link roles, assuming that checking the HA1 link (used for heartbeats and configuration sync) will resolve session synchronization issues, when in fact session replication relies exclusively on the HA2 link.

42
MCQeasy

A security administrator is reviewing traffic logs and notices that a known application is being identified as 'web-browsing' instead of its correct App-ID. The application uses HTTP and is not encrypted. The administrator confirms that the application is not a custom application. What is the most likely cause of this misidentification?

A.The firewall's App-ID database is outdated and does not have the signature for the application.
B.The application's traffic is being tunneled over HTTP and the firewall cannot distinguish it from web-browsing.
C.The application uses standard HTTP and does not have a unique signature, so the firewall defaults to 'web-browsing'.
D.The firewall is configured with an Application Override for HTTP that forces all HTTP traffic to be identified as web-browsing.
AnswerC

If an application uses standard HTTP and does not have a distinct signature, the firewall may identify it as 'web-browsing' because it matches the web-browsing App-ID. This is the correct answer because App-ID relies on unique patterns; without them, the firewall falls back to the generic web-browsing classification. This is a common scenario for applications that are essentially web-based but lack specific signatures.

Why this answer

App-ID identifies applications based on unique traffic patterns. If an application uses standard HTTP and lacks a distinct signature, the firewall may classify it as 'web-browsing' because it matches that generic App-ID. This is the most likely cause in the absence of custom configurations.

Other options involve less probable scenarios like outdated databases or overrides.

Exam trap

The trap here is assuming that all HTTP applications have unique App-ID signatures, when many web-based applications are simply classified as web-browsing.

43
MCQeasy

A medium-sized enterprise recently deployed a PA-5250 firewall in a data center as the primary internet gateway. The network team configured the security policies to allow all outbound web traffic (HTTP/HTTPS) from the internal trust zone to the untrust zone, with URL filtering and threat prevention enabled. After the deployment, users complain that some legitimate websites, such as banking and healthcare portals, are being blocked. The team checks the URL filtering logs and sees that these sites are categorized as 'web-hosting' or 'dynamic-dns', which are in the block list. The company's compliance requires that all web traffic be inspected. What should the network engineer do to resolve the issue without reducing security?

A.Add the specific URLs to the 'Allow List' in the URL filtering profile
B.Set the URL filtering profile action for 'web-hosting' to 'alert' instead of 'block'
C.Create a URL category override for each legitimate site to reclassify it as 'business-economy' or 'health-medicine'
D.Remove the 'web-hosting' and 'dynamic-dns' categories from the block list
AnswerC

Override changes the category for specific URLs, so they are no longer blocked by the 'web-hosting' or 'dynamic-dns' categories, while still being subject to other security checks.

Why this answer

URL category overrides allow you to reclassify specific URLs into a more appropriate category (e.g., 'health-medicine') without altering the global block action for 'web-hosting' or 'dynamic-dns'. This preserves the security posture by keeping the broad categories blocked for unknown or risky sites, while permitting the legitimate sites that were miscategorized by the Palo Alto Networks URL filtering database.

Exam trap

The trap here is that candidates often choose to add URLs to an allow list (Option A) without realizing that this bypasses all security inspections, failing the compliance requirement for full traffic inspection.

How to eliminate wrong answers

Option A is wrong because adding specific URLs to the 'Allow List' in the URL filtering profile would bypass all URL filtering and threat prevention for those URLs, violating the compliance requirement that all web traffic be inspected. Option B is wrong because setting the action for 'web-hosting' to 'alert' would allow all sites in that category, including potentially malicious ones, reducing security by permitting unvetted traffic. Option D is wrong because removing 'web-hosting' and 'dynamic-dns' from the block list would globally allow all sites in those categories, including malicious ones, which undermines the security policy and compliance requirements.

44
Multi-Selecteasy

Which TWO statements about active/active HA mode are true compared to active/passive mode? (Choose two.)

Select 2 answers
A.Active/active eliminates the need for failover
B.Active/active requires enabling asymmetric routing support
C.Active/active allows both firewalls to process traffic simultaneously
D.Active/active automatically synchronizes configuration changes
E.Active/active is the default and most commonly deployed mode
AnswersB, C

In active/active HA, both firewalls simultaneously hold sessions and forward traffic, so return packets may traverse a different device than the original flow. Enabling asymmetric routing support lets each peer forward such traffic without dropping it, a requirement absent in active/passive.

Why this answer

In active/active HA mode, both firewalls can process traffic simultaneously, which requires enabling asymmetric routing support to handle traffic that may arrive at either firewall for the same session. This is necessary because active/active mode does not enforce a single path for traffic, unlike active/passive mode where only one firewall actively processes traffic.

Exam trap

The trap here is that candidates often assume active/active mode eliminates the need for failover or is the default mode, but in reality, failover is still required and active/passive is the default; the key differentiator is the need for asymmetric routing support in active/active mode.

45
MCQeasy

A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?

A.The firewall's forward trust certificate is not trusted by the client, causing a certificate warning that prevents access.
B.The website's certificate is not trusted by the firewall, so the firewall blocks the connection.
C.The website requires TLS 1.3, which the firewall cannot decrypt.
D.The decryption policy rule is misconfigured to not decrypt the website.
AnswerA

When the firewall decrypts SSL traffic, it presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, the browser will show a certificate warning and may block access. This is a common issue when the forward trust CA is not imported into the client's trusted root store. The self-signed nature of the website's certificate may trigger the firewall to use the forward untrust certificate, but the client trust of the firewall's certificate is the critical factor.

Why this answer

The most likely cause is that the client does not trust the firewall's forward trust certificate. When SSL Forward Proxy decryption is enabled, the firewall re-signs the website's certificate with its forward trust certificate. If the client does not trust the CA that issued the forward trust certificate, it will display a warning and may block access.

This is a common oversight when deploying decryption.

Exam trap

The trap here is assuming that the self-signed certificate of the website is the direct cause, when the real issue is the client's trust of the firewall's forward trust certificate.

46
MCQhard

A security administrator is investigating why a session was terminated with the flag 'tcp-rst-from-server' in the traffic logs. The administrator has confirmed that the server is reachable and responding to pings. Which of the following is the most likely cause for this session termination?

A.The server's TCP window size was set to zero, causing the firewall to send a RST.
B.The firewall's security policy blocked the traffic, causing the server to send a RST.
C.The server's operating system crashed and rebooted, sending a RST upon recovery.
D.The server's TCP stack sent a RST packet because the application was not listening on the requested port.
AnswerD

When a server receives a TCP SYN for a port where no application is listening, it typically responds with a RST packet. This results in a session termination with 'tcp-rst-from-server'. The server being reachable via ping only confirms IP connectivity, not that the specific service is running. Therefore, the most likely cause is that the application is not listening on the port, leading to the RST.

Why this answer

A session terminated with 'tcp-rst-from-server' indicates that the server sent a TCP RST packet. This commonly occurs when the server receives a connection attempt for a port where no service is listening. While the server may respond to ICMP pings, that does not guarantee the application is available.

Other causes like security policy blocks or zero window would produce different flags. Therefore, the correct answer is that the application is not listening on the port.

Exam trap

The trap here is equating basic IP reachability with application availability, overlooking that a RST often signals a closed port.

47
MCQhard

A medium-sized enterprise has two Palo Alto Networks PA-5250 firewalls configured in an active/passive HA pair with session synchronization and configuration synchronization enabled. The HA1 link is a direct copper cable, and the HA2 link is also a direct copper cable. The firewalls are connected to two upstream routers (R1 and R2) and two downstream switches (S1 and S2). The network uses OSPF for dynamic routing. The active firewall (FW-A) is connected to R1 and S1, while the passive firewall (FW-P) is connected to R2 and S2. The OSPF cost is set symmetrically on both sides. During a maintenance window, the network team shuts down the HA1 and HA2 links on both firewalls to test failover behavior. After the links are brought back up, the firewalls are in a state of 'non-functional' and 'suspended'. The team suspects the HA configuration is broken. What is the most likely cause and the best course of action to restore HA?

A.Upgrade both firewalls to the same software version and then re-initialize HA
B.Change the HA mode to active/active and enable asymmetric routing
C.Reboot both firewalls after verifying the HA configuration and that the links are operationally up
D.Configure a dedicated management interface for HA1 communication and ensure HA2 is on a different subnet
AnswerC

Rebooting recovers from suspended state; links are up now.

Why this answer

When both HA1 and HA2 links are simultaneously shut down on both firewalls, the active/passive pair loses all communication and session synchronization. Upon restoration, the firewalls enter a 'non-functional' and 'suspended' state because the HA control plane cannot re-establish a quorum or verify the peer's state without a full reset of the HA state machine. Rebooting both firewalls after verifying the HA configuration and that the links are operationally up forces a clean initialization of the HA process, clearing the suspended state and allowing the pair to renegotiate roles correctly.

Exam trap

The trap here is that candidates assume re-establishing the HA links alone will automatically restore the HA pair, but PAN-OS requires a full reboot of both firewalls to clear the suspended state after a simultaneous HA link failure, as the state machine does not have a built-in recovery mechanism for this scenario.

How to eliminate wrong answers

Option A is wrong because upgrading software versions is irrelevant to the immediate issue; the firewalls were already running the same version before the test, and the problem is a state machine lockup, not a version mismatch. Option B is wrong because changing to active/active mode does not resolve a suspended state caused by HA link disruption; it would require a different configuration and does not address the core issue of HA state recovery. Option D is wrong because dedicating a management interface for HA1 or changing subnets does not fix the current suspended state; HA1 and HA2 were already on direct copper cables, and the problem is not about subnet overlap but about the HA process needing a full restart after simultaneous link loss.

48
MCQhard

An administrator wants to ensure that all traffic from the 'Trust' zone to the 'Untrust' zone is inspected by WildFire. Which configuration is required?

A.Create a separate WildFire rule.
B.Enable WildFire on the security rule.
C.Configure a WildFire profile and attach it to the security rule.
D.Enable WildFire globally under Device > Setup.
AnswerC

Attaching a WildFire profile to the security rule enforces inspection for traffic matching that rule, satisfying the Trust-to-Untrust requirement. WildFire profiles are applied per-rule, so the profile analyses eligible file types inline or submits them for cloud sandboxing, providing verdicts without altering zone-based policy logic.

Why this answer

WildFire inspection is applied via a security rule using a WildFire Analysis profile. The profile defines the file types and verdict actions (e.g., alert, block) for files submitted to WildFire. Attaching this profile to the security rule that governs Trust-to-Untrust traffic ensures all matching traffic is inspected by WildFire.

Exam trap

The trap here is that candidates confuse WildFire's global registration settings (Device > Setup > WildFire) with the per-rule profile attachment required for actual traffic inspection, leading them to select the global enablement option.

How to eliminate wrong answers

Option A is wrong because WildFire does not use separate rules; it is a profile-based feature attached to security rules. Option B is wrong because there is no toggle to 'enable WildFire on the security rule' directly; you must configure and attach a WildFire Analysis profile. Option D is wrong because WildFire is not enabled globally under Device > Setup; global settings for WildFire are configured under Objects > WildFire Analysis Profiles or Device > WildFire, but the inspection itself requires profile attachment to a security rule.

49
MCQmedium

A firewall's traffic logs are being forwarded to a Panorama appliance for centralized retention. An administrator notices that logs from one specific firewall are missing from Panorama even though the same firewall's logs appear locally. The firewall is managed by Panorama and shows as connected. Which cause is most likely?

A.The firewall's local log quota is full and is overwriting entries before Panorama can retrieve them.
B.The firewall's management interface certificate has expired, so the Panorama connection silently drops log traffic.
C.Panorama is in Panorma mode instead of management-only mode, so it cannot receive logs.
D.The log forwarding configuration on the firewall is missing a Panorama server profile or the correct log forwarding profile attachment.
AnswerD

For logs to reach Panorama, the firewall needs a Panorama server profile referenced in the log forwarding configuration, and the relevant Log Forwarding profile must be attached to the policy rules generating the traffic. A missing or misconfigured profile means sessions are logged locally but never sent to Panorama, which matches the symptom precisely.

Why this answer

Centralized log collection requires the firewall to reference a Panorama server profile in its log forwarding configuration and to attach the appropriate Log Forwarding profile to the rules that generate the logs. When either piece is missing, traffic is still logged locally but never transmitted to Panorama, exactly matching a single firewall whose logs are absent centrally.

Exam trap

The trap here is assuming that a connected management relationship also means logs are being forwarded, when log forwarding requires its own server profile and profile attachment.

50
MCQhard

An administrator is configuring GlobalProtect with certificate authentication. The portal is configured to use a certificate profile that validates client certificates against a trusted CA. Users report that authentication fails with the error 'Certificate validation failed'. The administrator has verified that the client certificates are issued by the correct CA and are not expired. What is the most likely cause of the failure?

A.The certificate revocation list (CRL) is not configured in the certificate profile.
B.The certificate profile is not configured to allow the certificate's extended key usage (EKU) for client authentication.
C.The client certificate is not installed in the user's personal certificate store.
D.The GlobalProtect portal is not configured with the correct SSL/TLS service profile.
AnswerB

In a certificate profile, you must specify the EKU that the client certificate must contain, such as 'clientAuth'. If the profile does not permit the EKU present in the certificate, validation fails. The error 'Certificate validation failed' often indicates this mismatch, even if the certificate is otherwise valid and from a trusted CA.

Why this answer

Certificate validation in GlobalProtect checks multiple attributes, including EKU. If the certificate profile does not allow the EKU present in the client certificate, validation fails even if the certificate is from a trusted CA and not expired. The error message 'Certificate validation failed' is a strong indicator of such a mismatch.

Exam trap

The trap here is focusing on CA trust and expiration while overlooking the extended key usage requirement in the certificate profile.

51
MCQmedium

A network security engineer is validating a newly deployed firewall. The security policy is configured to allow web traffic from the Trust zone to the Untrust zone. After a user reports that a website is unreachable, the engineer runs the CLI command 'show session all filter source 10.1.1.50' and sees no active sessions. Which CLI command should the engineer use next to determine why the session was not established?

A.show counter global filter delta yes
B.show running security-policy
C.test security-policy-match application ssl from Trust to Untrust source 10.1.1.50 destination 203.0.113.10 destination-port 443 protocol 6
D.show session info
AnswerC

This command simulates the policy lookup for a specific flow and returns the matching rule or the reason for denial, such as 'implicit deny' or 'no matching rule'. It is the correct next step because it directly tests the policy configuration without generating live traffic, helping the engineer pinpoint whether the security policy is the cause of the missing session.

Why this answer

The most direct way to determine why a session was not established is to simulate the policy lookup for the exact traffic flow. The 'test security-policy-match' command evaluates the five-tuple against the current ruleset and returns the matching rule or the reason for denial, such as implicit deny or no matching rule. This quickly identifies policy misconfigurations without generating live traffic, making it the correct choice for troubleshooting a missing session.

Exam trap

The trap here is assuming that viewing the security policy configuration is sufficient to diagnose why a session was not created, when in fact a policy simulation is needed to see the actual match result.

52
MCQeasy

An administrator needs to create a custom application for a proprietary database protocol that uses TCP port 7890. What is the first step in defining this application in App-ID?

A.Create a new application and define the default port.
B.Create a new application group.
C.Create a new custom application tag.
D.Create a new application filter.
AnswerA

Defining the application object and its default port establishes the App-ID signature's foundation before context, identification, and dependency criteria are added. The port anchors the proprietary protocol so subsequent traffic matching can be built around it.

Why this answer

To create a custom application for a proprietary database protocol using TCP port 7890, the first step is to create a new application and define the default port. In App-ID, custom applications are defined by specifying the application name, the protocol (TCP/UDP), and the default port number, which allows the firewall to identify traffic for that application based on the port. This is the foundational step before any additional properties like timeouts or advanced settings can be configured.

Exam trap

The trap here is that candidates often confuse the order of operations and think they need to first create an application group or tag to organize the custom application, but the actual first step is always to create the application object itself with its default port.

How to eliminate wrong answers

Option B is wrong because an application group is used to logically group multiple applications for policy enforcement, not to define a new application or its port. Option C is wrong because a custom application tag is a label for organizing applications, not a method to define the application itself or its port. Option D is wrong because an application filter is used to select applications based on predefined criteria (e.g., category, technology), not to create a new application with a specific port.

53
MCQmedium

Which of the following is required for SAML-based single sign-on to work with a Palo Alto Networks firewall acting as the service provider?

A.The identity provider's metadata must be imported into the firewall.
B.A certificate from a public CA for the SAML identity provider.
C.The firewall must be configured as a SAML identity provider.
D.User-ID must be configured to poll the SAML identity provider.
AnswerA

Importing the identity provider's metadata supplies the firewall with the IdP's signing certificate, entity ID and SSO endpoint, which it needs to validate SAML assertions and redirect authentication requests. Without this trust anchor, the service provider cannot verify responses, so the metadata import satisfies the SAML configuration requirement.

Why this answer

For SAML-based single sign-on (SSO) with a Palo Alto Networks firewall acting as the service provider (SP), the firewall must trust the identity provider (IdP). This trust is established by importing the IdP's SAML metadata (which includes the IdP's entity ID, single sign-on URL, and signing certificate) into the firewall. Without this metadata, the firewall cannot validate SAML assertions from the IdP, making authentication impossible.

Exam trap

The trap here is that candidates often assume a public CA certificate is required for SAML trust (Option B), but in reality, SAML uses a direct trust model where the SP explicitly trusts the IdP's self-signed certificate via metadata import, not through a public PKI hierarchy.

How to eliminate wrong answers

Option B is wrong because the certificate used for SAML signing by the IdP does not need to come from a public CA; it can be a self-signed certificate, as the trust is established via the metadata import, not via a public CA chain. Option C is wrong because the firewall is acting as the service provider (SP), not the identity provider (IdP); configuring it as an IdP would be for scenarios where the firewall itself authenticates users, not for SP-initiated SSO. Option D is wrong because User-ID does not need to poll the SAML IdP; SAML SSO provides user identity information directly in the SAML assertion, which the firewall can use to map to a User-ID without polling.

54
MCQhard

During a network incident, an engineer notices that after an HA failover, some sessions are not active on the new active firewall. The 'show session all' command shows the sessions with state 'half-closed'. What is the most likely cause?

A.The firewall failed to properly synchronize the TCP sessions before the failover
B.The HA2 link failover timer is set too low
C.The ARP timeout on the next-hop router is too short
D.Asymmetric routing is causing the firewall to see only one direction of traffic
AnswerA

Incomplete sync leads to half-closed sessions.

Why this answer

The 'half-closed' session state indicates that the firewall has only one side of the TCP handshake (FIN or RST) recorded, which typically occurs when session synchronization fails during an HA failover. In an active/passive HA pair, TCP session state information is synchronized via the HA2 link; if synchronization is incomplete or interrupted before the failover, the new active firewall will have partial session data, leading to half-closed sessions. This is a common symptom of a synchronization failure, not a timeout or routing issue.

Exam trap

The trap here is that candidates confuse 'half-closed' with 'incomplete' or 'asymmetric routing' symptoms, but 'half-closed' specifically indicates a TCP state where one side has initiated closure, which in an HA context points to incomplete session synchronization rather than a routing or ARP issue.

How to eliminate wrong answers

Option B is wrong because the HA2 link failover timer controls how quickly the passive firewall detects a failure of the active firewall, not the synchronization of session states; a low timer might cause premature failover but does not directly cause half-closed sessions. Option C is wrong because the ARP timeout on the next-hop router affects layer 2 reachability and could cause traffic black-holing after failover, but it does not impact the TCP session state stored on the firewall; half-closed sessions are a session table issue, not an ARP issue. Option D is wrong because asymmetric routing would cause the firewall to see only one direction of traffic, leading to sessions in a 'half-baked' or 'incomplete' state (not 'half-closed'), and it is not directly related to HA failover synchronization; asymmetric routing is a network design problem, not a post-failover session state issue.

55
MCQeasy

A network engineer is troubleshooting an HA pair where both firewalls show as 'active' in the HA state. What is this condition called?

A.Link failure
B.Active/Active
C.Passive/Passive
D.Split brain
AnswerD

Both peers believing they are active defines split brain, caused by loss of the HA heartbeat link while dataplane traffic still flows. Each firewall independently assumes the active role, producing duplicate sessions and conflicting state. The stem's symptom of two simultaneous 'active' states is precisely this condition.

Why this answer

In a Palo Alto Networks active/passive HA configuration, if the heartbeat fails, both firewalls assume the other is down and both transition to 'active' state. This unintended condition is called split brain. It is not a valid configuration like Active/Active, which is intentionally configured and requires separate virtual routers or security zones.

Exam trap

The trap is that candidates may think both firewalls being active indicates Active/Active mode, but in an active/passive pair, this is a split-brain failure condition.

How to eliminate wrong answers

Option A is wrong because a link failure is a potential cause of split brain, not the condition itself. Option C is wrong because passive/passive is not a valid HA state in Palo Alto Networks firewalls; the supported modes are active/passive and active/active (for specific use cases). Option D is wrong because split brain is the correct term for both firewalls being active simultaneously, not a separate option.

56
MCQmedium

A network engineer is troubleshooting why a Palo Alto Networks firewall is not generating any traffic logs for sessions that match a security policy rule set to allow. The engineer confirms that the rule is hit and traffic passes successfully. Which of the following is the most likely reason for the absence of logs?

A.The log forwarding profile is misconfigured, preventing logs from being written to local storage.
B.The security policy rule does not have the 'Log at Session End' option enabled.
C.The traffic is being offloaded to hardware and thus bypasses logging.
D.The firewall's log storage is full and is dropping new logs.
AnswerB

By default, security policy rules do not log traffic at session end unless explicitly configured. Enabling 'Log at Session End' ensures that a traffic log is generated when the session terminates. Since the rule is hit and traffic passes, the absence of logs is likely because this option is not selected. This is a common configuration oversight in troubleshooting log generation issues.

Why this answer

The absence of traffic logs for allowed sessions is typically due to the security policy rule not having the 'Log at Session End' option enabled. Even if the rule is hit and traffic passes, without this setting, the firewall will not generate a traffic log. Other potential causes like log storage issues or offloading would have broader effects or different symptoms.

Therefore, checking the rule's logging configuration is the first step.

Exam trap

The trap here is assuming that all allowed traffic is automatically logged, when in fact logging must be explicitly enabled per rule.

57
MCQhard

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates from the active firewall. The HA2 link is up, and the HA1 link is healthy. The engineer checks the HA configuration and sees that the HA2 interface is configured with an IP address, and session synchronization is enabled. What is the most likely cause of the synchronization failure?

A.Session synchronization is disabled on the active firewall.
B.The HA2 interface is configured in a different subnet on each firewall.
C.The HA2 interface is not assigned to a security zone.
D.The HA2 interface is configured as a Layer 2 interface instead of Layer 3.
AnswerB

For HA2 synchronization to work, the HA2 interfaces on both firewalls must be in the same subnet. If they are in different subnets, they cannot communicate directly, and session synchronization will fail. This is a common misconfiguration that can prevent the passive firewall from receiving session updates.

Why this answer

The HA2 interfaces must be in the same subnet for session synchronization to occur. If they are in different subnets, the firewalls cannot establish a direct connection for synchronization, even if the link is physically up. This is a common configuration error that leads to synchronization failure.

Exam trap

The trap here is overlooking the subnet requirement for HA2; engineers often focus on link status and session sync enablement but forget that IP addressing must be in the same subnet.

58
Multi-Selecthard

Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?

Select 2 answers
A.Decryption is applied globally to all traffic; selective decryption is not possible.
B.The firewall can decrypt all TLS sessions regardless of client certificate authentication.
C.When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.
D.Traffic using Server Name Indication (SNI) in TLS must be decrypted at the firewall or it will be dropped.
E.The firewall uses a decryption policy to determine which traffic to decrypt.
AnswersC, E

SSL Forward Proxy requires the firewall to present a forged certificate to the client, signed by a trusted Forward Trust CA, so it can decrypt and inspect traffic before re-encrypting. This per-session certificate generation is intrinsic to the proxy mechanism, satisfying the design consideration that the firewall impersonates the destination server for every decrypted session.

Why this answer

Option C is correct because SSL Forward Proxy works by having the firewall act as a man-in-the-middle: it intercepts the client's TLS session, presents a certificate it generates (signed by a Forward Trust certificate) for the requested server, and then establishes a separate TLS session to the actual server, so a certificate must be generated for each decrypted session to re-encrypt traffic to the client. Option E is correct because decryption in Palo Alto Networks firewalls is governed by a Decryption policy, which lets administrators selectively define which traffic (by source, destination, user, URL category, service, etc.) is decrypted, forwarded, or excluded from decryption. Option A is incorrect because decryption is not global; the Decryption policy enables granular, selective decryption and exclusions.

Option B is incorrect because SSL Forward Proxy cannot decrypt sessions that use client certificate authentication (mutual TLS), since the firewall cannot present the client's private key. Option D is incorrect because SNI is not a requirement that forces decryption; traffic with SNI can pass through undecrypted, and the firewall does not drop it merely for using SNI.

Exam trap

The trap here is that candidates often assume SSL Forward Proxy can decrypt all TLS traffic, including sessions with client certificate authentication, but the firewall cannot possess the client's private key and thus must skip decryption for such sessions.

59
MCQeasy

A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?

A.The GlobalProtect portal is not configured to push the correct routes to the clients.
B.The GlobalProtect gateway is not configured with a certificate for SSL/TLS.
C.The security policy allowing traffic from the GlobalProtect zone to the internal zone is missing or misconfigured.
D.The LDAP authentication profile is not properly mapped to the GlobalProtect gateway.
AnswerC

After a user connects via GlobalProtect, traffic from the user is placed in a security zone (typically the GlobalProtect zone). A security policy must explicitly allow traffic from that zone to the internal resources. If the policy is missing or incorrect, the user can connect but cannot access resources. This is a common oversight.

Why this answer

In GlobalProtect, after a user connects, their traffic is subject to security policies. The GlobalProtect zone is typically used for incoming VPN traffic. A security policy must allow traffic from the GlobalProtect zone to the internal zone or resources.

Without this policy, the user can authenticate and establish a tunnel but cannot access internal resources.

Exam trap

The trap here is focusing on authentication or routing issues when the user can already connect, overlooking the need for a security policy to permit access to internal resources.

60
MCQeasy

A network administrator needs to verify that the firewall is receiving dynamic updates for applications and threats. Which command should they use from the CLI to check the current update status and schedule?

A.show jobs all
B.show system update-server
C.show system info
D.show system dynamic-updates
AnswerD

The command 'show system dynamic-updates' displays the current versions of the installed dynamic updates, including applications, threats, and antivirus, as well as the schedule for future updates. This is the correct command to verify update status and schedule from the CLI.

Why this answer

The CLI command 'show system dynamic-updates' provides a summary of the currently installed dynamic update versions and the configured update schedule. This allows administrators to quickly verify that the firewall is up to date with the latest applications and threats content.

Exam trap

The trap here is confusing commands that show general system information or job status with the specific command that displays dynamic update versions and schedule.

61
MCQeasy

A security administrator is configuring a new Palo Alto Networks firewall and needs to enable App-ID to identify applications traversing the network. The administrator wants to ensure that App-ID can correctly identify applications even when they use non-standard ports or encryption. Which feature must be enabled to allow App-ID to inspect encrypted traffic?

A.SSL decryption
B.User-ID
C.Content-ID
D.Application override
AnswerA

SSL decryption allows the firewall to decrypt SSL/TLS traffic, enabling App-ID to inspect encrypted applications. Without decryption, App-ID can only identify applications based on metadata such as certificate information or IP addresses, which is less accurate. Enabling SSL decryption ensures that App-ID can see inside encrypted sessions and apply appropriate security policies based on the actual application.

Why this answer

SSL decryption is required to inspect encrypted traffic, allowing App-ID to identify applications accurately. Without decryption, App-ID relies on heuristics and metadata, which may misidentify applications. User-ID, Content-ID, and application override serve different purposes and do not decrypt traffic.

Enabling SSL decryption ensures that App-ID can see inside encrypted sessions and enforce policies based on the true application.

Exam trap

The trap here is assuming that Content-ID or other security subscriptions can inspect encrypted traffic without SSL decryption enabled.

62
MCQmedium

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates. The engineer runs 'show high-availability state' on both firewalls and sees that the HA2 link is down. Which action should the engineer take first to resolve the issue?

A.Restart the HA services on both firewalls.
B.Verify that the HA2 interface is configured with the correct IP address and is in the same subnet as the peer.
C.Ensure that the HA2 link is configured for encryption.
D.Check the physical cabling and switch port configuration for the HA2 link.
AnswerD

If the HA2 link is down, the most common cause is a physical connectivity issue, such as a bad cable, incorrect switch port configuration, or a failed interface. Checking the physical layer first is a logical troubleshooting step to quickly identify and resolve the problem.

Why this answer

When an HA2 link is down, the first step is to check the physical connectivity, including cables, switch ports, and interface status. This is because the most common causes of a down link are physical issues. Once the physical layer is verified, other configuration aspects can be checked.

Exam trap

The trap here is jumping to configuration or software fixes before verifying the physical layer, which is often the simplest cause.

63
MCQhard

A network engineer is configuring HA on a pair of PA-5220 firewalls. The HA1 link is configured over a dedicated interface, and HA1 backup is configured over the management interface. The engineer wants to ensure that HA1 control traffic is encrypted and authenticated. Which action should be taken?

A.Enable SSL/TLS on the HA1 interface.
B.Use SSH to tunnel HA1 traffic.
C.Enable HA1 encryption and authentication in the HA settings.
D.Configure IPsec on the HA1 interface.
AnswerC

HA1 encryption and authentication can be enabled in the HA configuration to secure control traffic. This ensures that HA1 packets are encrypted and authenticated, preventing unauthorized access and tampering. It is a best practice for HA1 links that traverse untrusted networks. The engineer should enable this feature in the HA1 configuration settings, which applies to both HA1 and HA1 backup links.

Why this answer

HA1 encryption and authentication is a built-in feature that secures control traffic between HA peers. It uses a pre-shared key to encrypt and authenticate HA1 packets, protecting against eavesdropping and tampering. This is the recommended method when HA1 traverses untrusted networks, such as when using the management interface as HA1 backup.

Other options like IPsec or SSH are not applicable to HA1.

Exam trap

The trap here is thinking that generic VPN or tunneling technologies are needed, but the firewall has a dedicated HA1 encryption option that is simpler and purpose-built.

64
MCQmedium

A network security engineer is designing a multi-vsys Palo Alto Networks firewall deployment to provide both advanced security and virtual routing separation for three different departments. Each department requires its own routing table and separate security policy enforcement. The engineer must decide which component is responsible for enforcing security policies and providing threat inspection across all virtual systems. Which component of the Palo Alto Networks Next-Generation Firewall performs this function?

A.The management plane
B.The control plane
C.The dataplane
D.The user-ID agent
AnswerC

The dataplane is responsible for all traffic processing, including security policy enforcement, application identification, and threat inspection. In a multi-vsys firewall, each vsys has its own dataplane resources, allowing separate security policies and routing. The dataplane ensures that traffic between departments is inspected and controlled according to the configured rules, providing the required security and separation.

Why this answer

The dataplane is the core processing engine that enforces security policies, performs application identification, and inspects traffic for threats. In a multi-vsys configuration, each virtual system has dedicated dataplane resources, ensuring that security policies are applied independently. The management plane, control plane, and User-ID agent support administration, routing, and user mapping but do not enforce security policies or inspect traffic.

Exam trap

The trap here is confusing the control plane with the dataplane, assuming that routing or management functions also enforce security policies.

65
MCQeasy

A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?

A.DNS resolution failure
B.Asymmetric routing
C.Security policy configured with service 'any'
D.Incomplete TCP three-way handshake
AnswerB

Asymmetric routing causes return traffic to bypass the firewall, so it never sees the full session and drops packets mid-flow. Sessions appear active in the table, yet the user times out, matching the intermittent connectivity symptom described.

Why this answer

Asymmetric routing causes the firewall to see only one direction of a TCP session, leading to session timeouts despite active session entries. When traffic from the client to the database server traverses one firewall and return traffic takes a different path, the firewall cannot properly track the TCP state, resulting in dropped packets and intermittent connectivity.

Exam trap

The trap here is that candidates see 'active sessions' in the table and assume the firewall is working correctly, overlooking that asymmetric routing can leave stale entries while actual data flow is disrupted.

How to eliminate wrong answers

Option A is wrong because DNS resolution failure would prevent the initial connection entirely, not cause intermittent timeouts with active sessions in the table. Option C is wrong because a security policy with service 'any' would allow all traffic, not cause timeouts; it might increase security risk but does not disrupt established sessions. Option D is wrong because an incomplete TCP three-way handshake would prevent session establishment, not cause intermittent timeouts after sessions are already active in the table.

66
MCQeasy

A network administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions in real-time to identify which application is consuming the most bandwidth. Which command should the administrator use?

A.show running resource-monitor
B.show system statistics
C.show session all
D.show interface all
AnswerC

The 'show session all' command displays all current sessions on the firewall, including details such as source, destination, application, and bytes transferred. This allows the administrator to identify which application is consuming the most bandwidth by sorting or filtering the output. It is the primary command for real-time session monitoring.

Why this answer

To view current sessions and identify bandwidth-consuming applications, the 'show session all' command is the most direct method. It lists all active sessions with details including application and byte counts. Other commands like 'show running resource-monitor' or 'show system statistics' provide aggregate data but not per-session detail. 'show interface all' shows interface-level statistics, not application breakdown.

Thus, 'show session all' is the correct choice.

Exam trap

The trap here is confusing aggregate system statistics with detailed session information, leading to commands that lack application-level visibility.

67
MCQmedium

An administrator is reviewing the firewall's session table and notices many sessions in a 'discard' state. What is the most likely cause of this session state?

A.The firewall is experiencing high CPU utilization.
B.The session was denied by a security policy or a threat was detected and the session was reset.
C.The session is waiting for application identification to complete.
D.The firewall is performing SSL decryption and the session is temporarily paused.
AnswerB

Sessions in 'discard' state are typically those that have been denied by a security policy or have been reset due to a threat detection. When a security policy denies traffic, the firewall creates a session entry with the action 'deny' and the state may show as 'discard' until the session times out. Similarly, if a threat is detected and the action is 'reset-both' or 'drop', the session is marked for discard.

Why this answer

Sessions in 'discard' state indicate that the firewall has decided to drop the session, usually due to a security policy deny action or a threat detection with a reset or drop action. This state persists until the session times out. Understanding session states helps administrators quickly identify policy violations or security events.

Exam trap

The trap here is assuming 'discard' means the session is waiting for inspection, but it actually means the session is being terminated.

68
MCQeasy

A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?

A.Configure decryption settings per interface to distribute load.
B.Disable SSL decryption entirely to avoid performance issues.
C.Create decryption exclusion rules for traffic that is known to be low-risk and high-volume.
D.Enable decryption on all traffic to ensure complete visibility.
AnswerC

Excluding low-risk, high-volume traffic from decryption directly reduces the CPU load on the firewall's dataplane, since each TLS session otherwise consumes processing for handshake and inspection. This satisfies the stem's constraint of minimising SSL decryption performance impact while preserving decryption for genuinely risky traffic.

Why this answer

Creating decryption exclusion rules for low-risk, high-volume traffic (e.g., software updates, video streaming, or trusted CDN traffic) reduces the firewall's decryption workload, minimizing performance impact while still allowing decryption of sensitive or risky traffic. This aligns with Palo Alto Networks best practices to balance security and performance by excluding traffic that does not require inspection.

Exam trap

The trap here is that candidates may think distributing decryption per interface (Option A) is a valid load-balancing technique, but Palo Alto Networks firewalls do not support interface-level decryption configuration, and the correct approach is to use exclusion rules to selectively bypass decryption for low-risk traffic.

How to eliminate wrong answers

Option A is wrong because decryption settings are not configured per interface to distribute load; SSL decryption is applied globally via decryption policies, and load distribution is handled by the firewall's hardware architecture, not interface-level settings. Option B is wrong because disabling SSL decryption entirely eliminates visibility into encrypted threats, which defeats the purpose of a security firewall and is not a best practice for minimizing performance impact while maintaining security. Option D is wrong because enabling decryption on all traffic would cause unnecessary performance degradation and latency, especially for high-volume, low-risk traffic that does not require inspection, violating the principle of selective decryption.

69
MCQmedium

A company wants to forward logs from a firewall to a SIEM system with high reliability. Which log forwarding method ensures that logs are not lost if the SIEM is temporarily unreachable?

A.Email (SMTP) for each log.
B.Syslog over TCP with buffering enabled in the log forwarding profile.
C.Syslog over UDP with a log forwarding profile.
D.Syslog over SSL without optional buffering.
AnswerB

TCP provides session-oriented delivery with acknowledgements and retransmission, so the firewall detects an unreachable SIEM and holds logs in its buffer rather than dropping them. This directly satisfies the reliability constraint, unlike UDP-based syslog, which is fire-and-forget with no delivery guarantee.

Why this answer

Syslog over TCP with buffering enabled in the log forwarding profile ensures reliable delivery because TCP provides acknowledgment and retransmission of lost segments, while the buffering mechanism stores logs locally on the firewall when the SIEM is unreachable and retransmits them once connectivity is restored. This combination prevents log loss during temporary network or SIEM outages.

Exam trap

The trap here is that candidates often assume Syslog over TCP alone guarantees delivery, but without buffering enabled in the log forwarding profile, the firewall will drop logs if the TCP connection fails, making buffering the key differentiator for reliability.

How to eliminate wrong answers

Option A is wrong because email (SMTP) is not designed for high-volume, real-time log forwarding and can easily fail or queue indefinitely without reliable retransmission guarantees. Option C is wrong because Syslog over UDP is connectionless and inherently unreliable; logs are silently dropped if the SIEM is unreachable, with no buffering or retransmission. Option D is wrong because Syslog over SSL without optional buffering provides encryption but no local storage or retransmission mechanism; if the SIEM is unreachable, the TCP connection fails and logs are lost without buffering.

70
MCQeasy

An administrator needs to generate a report showing all traffic denied by the firewall over the past week. Which type of report in the firewall web interface should be used?

A.Application Report
B.Threat Report
C.URL Filtering Report
D.Traffic Report
AnswerD

The Traffic Report logs sessions the firewall allowed and denied, with details such as source, destination, application and rule. Filtering it to denied actions over the past week produces exactly the required list, which other report types do not capture.

Why this answer

The Traffic Report is the correct choice because it provides detailed logs of all traffic passing through the firewall, including both allowed and denied sessions. By filtering the report to show only denied traffic over the past week, the administrator can generate the exact report needed. Other report types focus on specific categories like applications, threats, or URLs, not general traffic denials.

Exam trap

The trap here is that candidates confuse 'denied traffic' with specific security features like threat prevention or URL filtering, but the Traffic Report is the only one that captures all policy-based denials regardless of the application or threat involved.

How to eliminate wrong answers

Option A is wrong because the Application Report focuses on application usage and bandwidth consumption, not on traffic that was denied by security policies. Option B is wrong because the Threat Report logs only traffic that triggered threat prevention signatures (e.g., exploits, malware), not all denied traffic (e.g., policy denials without threats). Option C is wrong because the URL Filtering Report logs only web traffic that was allowed or blocked based on URL categories, not all denied traffic (e.g., non-web traffic or policy-based denials).

71
MCQhard

A firewall administrator notices that traffic from a specific subnet is being unexpectedly dropped. The firewall log shows a 'flow_drop' reason of 'packet too long for interface MTU'. The interface MTU is set to 1500, and the packets are 1500 bytes. What is the most likely cause?

A.The route lookup for the destination requires a larger MTU.
B.The firewall is not performing TCP MSS clamping on the traffic.
C.The firewall is using jumbo frames on the internal interface.
D.The packet is being encapsulated (e.g., IPsec) after routing, increasing its size beyond 1500 bytes.
AnswerD

IPsec encapsulation adds outer headers after the original packet is routed, pushing a 1500-byte frame past the interface MTU and triggering the drop. This matches the logged reason exactly, since the original packet size alone equals the MTU.

Why this answer

When a packet is encapsulated (e.g., by IPsec) after the routing decision, the original packet's size remains 1500 bytes, but the encapsulation adds overhead (e.g., IPsec ESP headers/trailers, typically 50–60 bytes). This causes the resulting frame to exceed the interface MTU of 1500, triggering a 'packet too long for interface MTU' drop. The firewall logs the drop at the physical interface after encapsulation, not before.

Exam trap

The trap here is that candidates assume the firewall drops the packet before encapsulation because the original packet matches the MTU, but the drop occurs after encapsulation adds overhead, making the final frame too large.

How to eliminate wrong answers

Option A is wrong because the route lookup determines the next hop and outgoing interface, but it does not change the packet size; a larger MTU on the route would not cause a drop of a 1500-byte packet on a 1500-MTU interface. Option B is wrong because TCP MSS clamping reduces the TCP segment size to avoid fragmentation, but the drop occurs after routing/encapsulation, and MSS clamping would not prevent the encapsulation overhead from exceeding the MTU. Option C is wrong because jumbo frames (typically >9000 bytes) on an internal interface would allow larger packets, not cause drops; the issue is on the egress interface where the MTU is 1500.

72
Drag & Dropmedium

Arrange the steps to deploy a new Panorama template to a managed firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for deploying a new Panorama template to a managed firewall is: first, create the template; second, add configuration objects such as interfaces and zones; third, assign the template to the relevant device group; and finally, commit the template to push the configuration to the managed firewalls. This order ensures that the template exists, contains the desired settings, is linked to the correct devices, and is then applied.

73
MCQeasy

A company wants to enforce multi-factor authentication (MFA) for all administrative access to the Palo Alto Networks firewall. They have a RADIUS server configured with MFA capability (e.g., RSA SecurID). The firewall is currently using local authentication for admin accounts. What must be configured to enforce MFA for admin access?

A.Create a security policy to allow RADIUS traffic from the firewall to the RADIUS server.
B.Enable MFA in the User-ID agent configuration.
C.Create an authentication profile using RADIUS with MFA enabled and assign it to the admin accounts.
D.Configure an authentication enforcement rule in the authentication policy.
AnswerC

An authentication profile binds admin logins to the RADIUS server, so the firewall forwards credentials and the RSA SecurID challenge is enforced. Assigning it to admin accounts replaces local authentication, satisfying the requirement that all administrative access use MFA.

Why this answer

To enforce MFA for administrative access on a Palo Alto Networks firewall, you must create an authentication profile that uses RADIUS (or another MFA-capable server) and then assign that profile to the admin accounts. The authentication profile defines how the firewall authenticates administrators, and when it points to an MFA-enabled RADIUS server, the firewall will require the second factor. Assigning the profile to admin accounts ensures that all administrative logins go through MFA.

Exam trap

PCNSE often tests the difference between authentication profiles for administrative access and authentication policies for user traffic; candidates may incorrectly choose an authentication enforcement rule, which applies to user traffic, not admin access.

How to eliminate wrong answers

Option A is wrong because a security policy allowing RADIUS traffic is necessary for the firewall to communicate with the RADIUS server, but it does not enforce MFA for admin access; it only permits the traffic. Option B is wrong because MFA is not configured in the User-ID agent; the User-ID agent is used for mapping IP addresses to users, not for admin authentication. Option D is wrong because authentication enforcement rules are used in authentication policies for user traffic (e.g., for captive portal or web authentication), not for administrative access to the firewall itself.

74
MCQeasy

Refer to the exhibit. What is the primary cause of the 'non-functional' state?

A.The configuration sync operation has failed
B.One firewall is not running
C.HA1 link failure between 10.1.1.1 and 10.1.1.2
D.The configuration on the two firewalls is not identical
AnswerD

Identical configuration is mandatory for an active/passive HA pair to form and synchronise state. Any divergence in interfaces, zones or policies prevents the peer from reaching a functional state, directly causing the non-functional status shown.

Why this answer

The 'non-functional' state in a Palo Alto Networks HA pair indicates that the configuration synchronization (config sync) has failed because the configurations on the two firewalls are not identical. This is a prerequisite for HA operation; if the configurations differ, the HA pair cannot establish a functional sync state, even if HA1 and HA2 links are up.

Exam trap

The trap here is that candidates often confuse 'non-functional' with a link failure or peer down state, but the 'non-functional' state is uniquely tied to configuration synchronization issues, not connectivity or hardware failures.

How to eliminate wrong answers

Option A is wrong because a configuration sync operation failure is a symptom, not the primary cause; the root cause is the configuration mismatch itself. Option B is wrong because if one firewall were not running, the HA state would show 'down' or 'disconnected', not 'non-functional'. Option C is wrong because an HA1 link failure would result in a 'suspended' or 'down' state for the HA link, not a 'non-functional' state for the HA pair; the HA pair can still be functional with a single HA link if HA2 is available.

75
Drag & Dropmedium

Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for packet capture on a Palo Alto Networks firewall is: first configure the capture filter to define which traffic to capture, then start the capture, generate the traffic, stop the capture to finalize the data, and finally download the capture file. This order ensures that the desired traffic is captured cleanly and the file is ready for analysis.

Page 1 of 5

Page 2

All pages