Courseiva

Palo Alto Networks Certified Network Security Engineer PCNSE (PCNSE) — Questions 76–150

319 questions total · 5pages · All types, answers revealed

Page 1

Page 2 of 5

Page 3
76
MCQeasy

A company needs to deploy a firewall in transparent inline mode to filter traffic between two switches without requiring any IP address changes on existing devices. Which interface type should be configured?

A.Virtual Wire
B.Tap
C.Layer3
D.Layer2
AnswerA

Virtual Wire binds two interfaces into a transparent pair that forwards traffic without MAC or IP addressing, so existing switches and devices keep their addresses unchanged. It filters inline between the switches while remaining invisible at layer three.

Why this answer

Virtual Wire (VWire) is the correct interface type because it allows the firewall to operate in transparent inline mode without requiring any IP address changes on existing devices. In VWire mode, the firewall acts as a Layer 2 bump in the wire, forwarding traffic between two interfaces based on MAC addresses without participating in routing or requiring IP configuration on the firewall interfaces themselves.

Exam trap

The trap here is that candidates confuse Layer2 interfaces with Virtual Wire, assuming any transparent mode works the same, but Layer2 interfaces require bridge groups or VLAN configuration and do not provide the same zero-touch inline deployment as Virtual Wire.

How to eliminate wrong answers

Option B (Tap) is wrong because a Tap interface is used for passive monitoring only; it receives a copy of traffic but cannot actively filter or block traffic inline between switches. Option C (Layer3) is wrong because Layer3 interfaces require IP addresses and routing, which would necessitate IP address changes on existing devices and break the transparent requirement. Option D (Layer2) is wrong because while Layer2 interfaces can operate transparently, they require a VLAN tag or bridge configuration and do not inherently provide the same zero-configuration, bump-in-the-wire behavior as Virtual Wire, which is specifically designed for transparent inline deployment without any IP or VLAN changes.

77
MCQhard

A firewall receives traffic with IP options enabled. How does the firewall handle this traffic by default?

A.It drops the traffic
B.It forwards the traffic normally
C.It logs and alerts
D.It strips the IP options and forwards
AnswerA

By default, PAN-OS drops packets carrying IP options rather than forwarding them, since these options can be abused for reconnaissance or routing manipulation. This default behaviour satisfies the scenario's constraint of unconfigured handling, so the traffic is discarded before any policy evaluation.

Why this answer

By default, Palo Alto Networks firewalls drop traffic with IP options enabled because IP options can be used to bypass security controls or evade inspection. The firewall treats such packets as a potential security risk and discards them to prevent IP option-based attacks, such as source routing or timestamp manipulation.

Exam trap

The trap here is that candidates may assume the firewall forwards or strips IP options like a router, but Palo Alto Networks firewalls prioritize security by default and drop such packets to prevent IP option-based attacks.

How to eliminate wrong answers

Option B is wrong because forwarding traffic with IP options normally would allow potential evasion of security policies and is not the default behavior. Option C is wrong because while logging and alerting may be configured, the default action is to drop, not just log. Option D is wrong because stripping IP options and forwarding is not a default behavior; the firewall does not modify IP headers by default and instead drops the packet.

78
MCQmedium

A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?

A.Generate a new self-signed certificate on the firewall and assign it as the Forward Trust certificate.
B.Create a certificate signing request (CSR) for the Forward Trust certificate, have it signed by the internal CA, and import the signed certificate.
C.Assign the internal CA certificate directly as the Forward Trust certificate without generating a CSR.
D.Import the internal CA's private key and certificate into the firewall and designate it as the Forward Trust certificate.
AnswerB

This is the correct process: the firewall generates a CSR for the Forward Trust certificate, which is then signed by the internal CA. The signed certificate is imported and designated as the Forward Trust certificate. This ensures that the firewall can dynamically sign website certificates that clients trust because the internal CA is already trusted by them.

Why this answer

For SSL Forward Proxy decryption, the firewall must have a Forward Trust certificate that is trusted by internal clients. This certificate is typically a subordinate certificate signed by the organization's internal CA. The firewall generates a CSR, the CA signs it, and the resulting certificate is imported and configured as the Forward Trust certificate.

This allows the firewall to dynamically generate certificates for external sites that clients will trust.

Exam trap

The trap here is assuming that the internal CA certificate itself can be used as the Forward Trust certificate, when in fact a separate subordinate certificate must be generated and signed by the CA.

79
MCQmedium

Based on the exhibit, what is the impact of the current HA state on the network?

A.Configuration changes are not synchronized
B.The passive firewall will preempt the active when the active fails
C.Sessions will not be preserved during a failover
D.The HA pair cannot perform a failover
AnswerC

HA2 is down, causing session synchronization to fail. Consequently, existing sessions are lost during a failover.

Why this answer

The exhibit shows that the HA pair's session synchronization is not synchronized (for example, the HA2 data link is down or session synchronization is disabled). In active/passive HA, session preservation requires session synchronization. Because sessions are not synchronized between the peers, a failover will drop existing sessions, so sessions will not be preserved.

Exam trap

PCNSE HA questions require reading the exhibit carefully: distinguish between configuration synchronization (HA1 control link) and session synchronization (HA2 data link). A failed HA2 link or disabled session sync means sessions are not preserved on failover, but a failed HA1 link means configuration changes are not synchronized. Candidates must identify which link/state the exhibit actually shows before selecting an answer.

How to eliminate wrong answers

Option A is wrong because configuration changes are typically synchronized in HA regardless of session state, unless there is a synchronization issue. Option B is wrong because preemption is a configured behavior, not an impact of the current state; the passive firewall will only preempt if preemption is enabled and the active fails. Option D is wrong because the HA pair can still perform a failover; the state might affect session preservation but not the ability to failover.

80
MCQmedium

A company has a firewall with multiple virtual systems (vsys). The administrator wants to delegate management of one vsys to a junior administrator, allowing them to configure security policies but not access system settings or other vsys. Which administrative role should be assigned?

A.Virtual System Admin
B.Superuser
C.Device Admin
D.Role-Based Admin
AnswerA

A Virtual System Admin role scopes permissions to a single vsys, granting full policy configuration within it while denying access to system settings and other vsys. This satisfies the delegation constraint of policy-only rights without broader device administration.

Why this answer

A Virtual System Admin role is specifically designed to delegate administrative access to a single virtual system (vsys) within a Palo Alto Networks firewall. This role allows the junior administrator to configure security policies and objects within their assigned vsys, while explicitly preventing access to system settings, device-level configurations, or other virtual systems. This matches the requirement exactly.

Exam trap

The trap here is that candidates often confuse 'Virtual System Admin' with 'Role-Based Admin', thinking they need to create a custom role, when the predefined Virtual System Admin role is the exact fit for delegating per-vsys management.

How to eliminate wrong answers

Option B (Superuser) is wrong because a Superuser has full read-write access to all virtual systems and all system settings, which would grant the junior administrator access to other vsys and device-level configurations, violating the requirement. Option C (Device Admin) is wrong because a Device Admin has full access to the device's system settings and all virtual systems, again providing broader access than intended. Option D (Role-Based Admin) is wrong because it is a generic category for custom roles, but the specific predefined role that matches the requirement is Virtual System Admin; assigning a custom Role-Based Admin would require manually creating a role with the exact permissions, which is less direct and not the standard answer for this scenario.

81
MCQmedium

During an HA failover, the new active firewall's session table is empty, causing all existing connections to be dropped. Which configuration change would prevent this?

A.Configure HA3 for stateful inspection.
B.Increase HA1 keepalive timer.
C.Enable config sync on HA1.
D.Enable session sync on HA2.
AnswerD

Session sync replicates the active firewall's session table to the passive peer over the HA2 link, so after failover existing flows are already known and continue without re-establishment. Without HA2 session synchronisation, the newly active device has no state and drops all established connections.

Why this answer

Enabling session sync on the HA2 link ensures that session state information is continuously replicated from the active firewall to the standby firewall. During a failover, the new active firewall already has the session table populated, so existing connections are preserved and not dropped. Without session sync, the standby firewall starts with an empty session table, causing all existing TCP/UDP sessions to be torn down.

Exam trap

The trap here is confusing configuration synchronization (config sync) with session state synchronization (session sync), leading candidates to incorrectly select config sync on HA1 as the solution for preserving active connections during failover.

How to eliminate wrong answers

Option A is wrong because HA3 is the management link used for control-plane traffic like configuration synchronization and keepalives, not for session state synchronization; stateful inspection is a firewall feature unrelated to HA session sync. Option B is wrong because increasing the HA1 keepalive timer only affects how quickly the firewall detects a peer failure, but does not prevent session loss after failover; it may actually delay failover detection. Option C is wrong because config sync on HA1 synchronizes configuration objects (policies, objects) between peers, not dynamic session state; session tables are not part of configuration sync.

82
MCQmedium

Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?

A.rule4
B.rule3
C.rule1
D.rule2
AnswerD

Rule2 allows SSL for anyone, so it matches the HTTPS traffic.

Why this answer

Rule2 is correct because it is the first rule in the security policy that matches the traffic from the trust zone (source zone trust) to the external server (destination zone untrust) for HTTPS (destination port 443). Palo Alto Networks firewalls evaluate rules in top-down order, and rule2 explicitly permits HTTPS traffic from trust to untrust, while rule1 only permits HTTP (port 80). Rule3 and rule4 do not match because they are either for different zones or deny the traffic.

Exam trap

Palo Alto Networks often tests the first-match rule evaluation order, where candidates mistakenly think a deny rule later in the policy (rule4) will block traffic, forgetting that a preceding permit rule (rule2) already matched and allowed the session.

How to eliminate wrong answers

Option A is wrong because rule4 denies all traffic from trust to untrust, but since rule2 matches first and permits the HTTPS traffic, rule4 is never evaluated. Option B is wrong because rule3 applies to traffic from the DMZ zone, not the trust zone, so it does not match the user's traffic. Option C is wrong because rule1 only permits HTTP (port 80), not HTTPS (port 443), so it does not match the HTTPS request.

83
MCQhard

A company needs to authenticate remote users accessing internal web applications via GlobalProtect portal and wants to use SAML with Azure AD for MFA. Which component must be configured on the firewall?

A.LDAP server profile for user lookup
B.Server certificate for the portal
C.Authentication profile referencing the SAML IdP profile
D.SSL decryption rule
AnswerC

An authentication profile binds the SAML IdP profile to the GlobalProtect portal, enabling the firewall to redirect users to Microsoft Entra ID for MFA. The IdP profile alone holds the certificate and metadata but cannot be referenced directly by the portal; the authentication profile is the required linking object.

Why this answer

SAML authentication for GlobalProtect requires an authentication profile that references a SAML identity provider (IdP) profile. The firewall uses this profile to redirect users to Azure AD for SAML-based MFA, then validates the SAML assertion returned. Without this profile, the firewall cannot initiate or complete the SAML exchange.

Exam trap

The trap here is that candidates often confuse the need for a server certificate (required for TLS) with the authentication method itself, or assume LDAP is needed for user identity, but SAML authentication is configured solely through the authentication profile and SAML IdP profile, not through LDAP or SSL decryption.

How to eliminate wrong answers

Option A is wrong because an LDAP server profile is used for direct user lookup or authentication against an LDAP directory, not for SAML-based authentication with Azure AD; SAML relies on token exchange, not LDAP binds. Option B is wrong because a server certificate for the portal is required for TLS encryption of the GlobalProtect portal, but it does not enable SAML authentication or MFA; it secures the transport layer only. Option D is wrong because SSL decryption rules are used to inspect encrypted traffic, not to configure authentication methods; they have no role in SAML or MFA integration.

84
MCQmedium

An engineer is troubleshooting a security policy that is not matching traffic as expected. The traffic is from source IP 10.1.1.10 to destination 172.16.0.1 port 443. The policy has source zone 'Internal', destination zone 'DMZ', source address '10.1.1.0/24', destination address '172.16.0.0/24', application 'ssl'. The firewall shows the traffic hitting a different rule. What is the most likely cause?

A.The source zone is incorrectly assigned; traffic is coming from a different zone.
B.The destination address is not in the specified subnet due to NAT.
C.The application 'ssl' does not match because the traffic is actually using TLS 1.3.
D.The traffic is being matched by an earlier rule with broader criteria.
AnswerD

Rule order matters; a prior rule with broader source/destination/application may match before the intended rule.

Why this answer

The most likely cause is that an earlier rule in the security policy rulebase matches the traffic before the intended rule. Palo Alto Networks firewalls evaluate security rules in sequential order from top to bottom, and the first rule that matches all criteria (source/destination zone, source/destination address, application, etc.) is applied. If a rule with broader criteria (e.g., any/any or a less specific application) appears earlier, it will match the traffic, preventing the intended rule from being hit.

Exam trap

Palo Alto Networks often tests the misconception that application signatures are version-specific (e.g., TLS 1.3 vs. SSL), but Palo Alto Networks uses generic application signatures that match all versions of a protocol, so candidates incorrectly eliminate the correct answer due to a misunderstanding of application identification.

How to eliminate wrong answers

Option A is wrong because the traffic is from source IP 10.1.1.10, which is within the 10.1.1.0/24 subnet, and the policy specifies source zone 'Internal'; if the zone were incorrectly assigned, the traffic would not match any rule with that zone, but the firewall shows it hitting a different rule, not failing to match. Option B is wrong because NAT does not change the destination address in the security policy match; the firewall evaluates the pre-NAT destination address (172.16.0.1) against the destination address object (172.16.0.0/24), and 172.16.0.1 is within that subnet, so this is not a mismatch. Option C is wrong because the application 'ssl' in Palo Alto Networks is a generic signature that matches SSL/TLS traffic regardless of the TLS version (e.g., TLS 1.3), as the firewall identifies the application by protocol behavior and handshake patterns, not by the specific TLS version number.

85
MCQhard

Two firewalls in an active/passive HA configuration are not synchronizing sessions. The 'show high-availability state' command shows both peers as 'active' and 'passive' correctly, but session synchronization is not working. What is the most likely cause?

A.The HA3 link is not configured or is misconfigured.
B.The HA2 link is down.
C.The passive firewall does not have management API access.
D.The logging settings on both firewalls are different.
AnswerB

Correct. The HA2 link is responsible for session synchronization in active/passive mode. If it is down, sessions will not sync.

Why this answer

In an active/passive HA configuration on PAN-OS, session synchronization occurs over the HA2 link (control link). If the HA2 link is down, session synchronization will not work even though the HA state shows 'active' and 'passive' correctly. The HA3 link is used for packet forwarding in active/active mode, not for session sync in active/passive mode.

Exam trap

The trap here is that candidates often confuse the HA2 link (control link) with the HA3 link (session sync link), assuming that if HA state is correct and HA2 is up, session synchronization must also be working.

How to eliminate wrong answers

Option B is wrong because the HA2 link is used for control traffic (keepalives, configuration sync) and not for session synchronization; a down HA2 link would cause HA state issues, not just session sync failure. Option C is wrong because management API access on the passive firewall is unrelated to session synchronization; it controls administrative access, not data-plane session replication. Option D is wrong because differing logging settings between firewalls do not impact session synchronization; logging is a separate function from session table replication.

86
MCQeasy

A firewall shows session logs with application 'incomplete' for many SSL connections. Which action should be taken to improve App-ID accuracy?

A.Disable application identification for SSL traffic.
B.Enable HTTP/2 protocol decoding.
C.Enable SSL decryption for the traffic.
D.Allow sessions with application 'incomplete' in policy.
AnswerC

App-ID identifies applications by inspecting payload; encrypted SSL traffic exposes only the certificate and handshake, so sessions remain 'incomplete'. Enabling SSL decryption lets the firewall read the application data and match signatures, improving identification accuracy.

Why this answer

The 'incomplete' application label indicates that the firewall could not fully identify the application because the traffic was encrypted. Enabling SSL decryption allows the firewall to inspect the decrypted payload, which is necessary for App-ID to accurately classify the application. Without decryption, App-ID can only rely on metadata like IP addresses and ports, which is often insufficient for SSL connections.

Exam trap

The trap here is that candidates may think enabling HTTP/2 decoding (Option B) will solve the issue, but HTTP/2 is a transport protocol, not a decryption mechanism; without SSL decryption, the firewall still cannot see the encrypted payload regardless of the HTTP version.

How to eliminate wrong answers

Option A is wrong because disabling application identification for SSL traffic would prevent any App-ID analysis, leaving all SSL sessions as 'incomplete' and defeating the purpose of improving accuracy. Option B is wrong because HTTP/2 protocol decoding is a feature for parsing HTTP/2 traffic, but it does not address the root cause of encryption; without decryption, the firewall still cannot inspect the payload to identify the application. Option D is wrong because allowing sessions with application 'incomplete' in policy does not improve App-ID accuracy; it merely bypasses security controls, leaving the traffic unidentified and potentially risky.

87
MCQmedium

A network security administrator is investigating a suspicious session on a PA-3220 firewall. The administrator needs to determine the exact security policy rule that permitted the session to be established. Which action should the administrator take to accomplish this goal?

A.Use the 'show session all' CLI command and look for the policy name in the output.
B.Use the Session Browser in the web interface and view the 'Policy' column for the specific session.
C.Check the Traffic log and filter by the session's source and destination IP addresses.
D.Use the 'test security-policy-match' CLI command with the source and destination IP addresses and ports.
AnswerB

The Session Browser displays active sessions and includes a 'Policy' column that shows the name of the security policy rule that matched the session. By locating the specific session, the administrator can directly see which rule permitted the traffic, providing the exact policy name without needing to infer it.

Why this answer

To identify the exact security policy rule that allowed a specific session, the administrator can use the Session Browser in the web interface, which shows the policy name for each active session. This real-time view is more direct than checking logs or using simulation commands, especially if the session is ongoing or logging is incomplete.

Exam trap

The trap here is assuming that the Traffic log always contains the policy name for every session, but logging may be disabled or the session may still be active, so the log might not have the entry.

88
Multi-Selecthard

Which TWO are prerequisites for using Authentication Policy? (Choose two.)

Select 2 answers
A.User-ID is configured
B.The firewall is in transparent mode
C.SSL decryption is enabled
D.A security policy rule exists with user attributes
E.An authentication profile is configured
AnswersA, E

Authentication Policy enforces user- and group-based rules, so it requires User-ID to map source IP addresses to directory identities before any policy can match. Without User-ID configured, the firewall cannot resolve usernames or groups, leaving the policy unevaluable. This satisfies the stem's prerequisite constraint directly.

Why this answer

Authentication Policy in PAN-OS requires User-ID to be configured (option A) because the policy matches traffic based on user and group mappings that User-ID provides; without an active User-ID source (such as an agent, syslog listener, or server monitoring), the firewall has no user-to-IP mapping to enforce authentication rules. It also requires an authentication profile (option E), since the Authentication Policy references an authentication profile to define the authentication method (e.g., LDAP, RADIUS, SAML, Kerberos, or local database) and the authentication portal settings used to challenge users. Option B is incorrect because transparent mode is not required—Authentication Policy works in L3, L2, virtual wire, and tap modes.

Option C is incorrect because SSL decryption is not a prerequisite; it is only needed to identify users in encrypted traffic, not to use Authentication Policy itself. Option D is incorrect because a security policy rule with user attributes is not required to create or use Authentication Policy; Authentication Policy is evaluated before security policy and generates the user mapping that security rules may later reference.

Exam trap

The trap here is that candidates often confuse prerequisites with features that enhance security (like SSL decryption) or confuse the order of configuration steps, thinking a security rule with user attributes must exist before the authentication policy can be used.

89
MCQmedium

A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?

A.Create a custom App-ID for custom-db-sync using the Application Object and define the appropriate signatures.
B.Enable unknown application identification in the security rule.
C.Use the default application override for port 4444 to allow traffic.
D.Change the security rule to use 'application-default' as the service to rely on port-based identification.
AnswerA

Creating a custom App-ID with signatures is the only way App-ID can recognise a proprietary protocol; no built-in decoder exists for it. Because the rule currently permits any application on TCP 4444, the firewall cannot classify the session, so defining the signature in the Application Object satisfies the identification constraint.

Why this answer

App-ID relies on application signatures to identify traffic, not just port numbers. Since custom-db-sync uses a proprietary protocol over TCP 4444, the firewall cannot match it to any built-in App-ID. Creating a custom App-ID with appropriate signatures (e.g., protocol decoders, pattern matches) allows the firewall to correctly identify this custom application, enabling policy enforcement beyond port-based rules.

Exam trap

The trap here is that candidates often confuse 'application override' (which bypasses App-ID) with 'custom App-ID' (which enhances App-ID), leading them to choose option C, thinking it will force identification when it actually disables App-ID for that traffic.

How to eliminate wrong answers

Option B is wrong because enabling unknown application identification only allows the firewall to treat unidentified traffic as 'unknown-tcp' or 'unknown-udp', but it does not create a specific signature to identify custom-db-sync; the traffic would still not be recognized as that custom application. Option C is wrong because an application override bypasses App-ID entirely, forcing the firewall to treat all traffic on port 4444 as a specified application, which defeats the purpose of using App-ID to correctly identify the custom protocol. Option D is wrong because using 'application-default' as the service only changes the port binding to the default port for the identified application, but since custom-db-sync is not identified at all, this action does not enable its recognition; App-ID must first identify the application before 'application-default' can be relevant.

90
MCQhard

During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?

A.The firewall's SSL/TLS service profile does not include the cipher suites used by the client or server.
B.The firewall does not support decryption of that traffic.
C.The decryption certificate is not trusted by the client.
D.The decryption rule is not matching the traffic.
AnswerA

The error indicates a cipher suite mismatch: the negotiated algorithm is absent from the firewall's SSL/TLS service profile. Adding the required cipher suites to that profile, or aligning it with the endpoints' supported suites, resolves the failed handshakes.

Why this answer

The 'ssl_decrypt_unsupported_cipher' error indicates that the firewall's SSL/TLS proxy cannot negotiate a common cipher suite with the client or server during the decryption handshake. This occurs when the cipher suites configured in the firewall's SSL/TLS service profile do not include the ciphers offered by the client or required by the server. The solution is to update the service profile to include the necessary cipher suites, such as those based on AES-GCM or CHACHA20-POLY1305, ensuring compatibility.

Exam trap

The trap here is that candidates often confuse cipher suite mismatch with certificate trust issues or rule misconfiguration, but the specific error message 'ssl_decrypt_unsupported_cipher' directly points to the cipher suite list in the SSL/TLS service profile.

How to eliminate wrong answers

Option B is wrong because the firewall does support decryption of that traffic; the error is specifically about cipher mismatch, not a lack of decryption capability. Option C is wrong because a certificate trust issue would generate errors like 'certificate validation failed' or 'untrusted issuer', not 'unsupported cipher'. Option D is wrong because if the decryption rule were not matching, the traffic would bypass decryption entirely, and no SSL decryption error would be logged.

91
MCQmedium

A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?

A.Service objects with TCP port ranges in the security policy
B.App-ID with application filters in the security policy
C.External Dynamic Lists (EDLs) with IP addresses of the SaaS provider
D.URL filtering profiles with custom URL categories
AnswerB

App-ID identifies the application regardless of port or IP, and application filters allow grouping applications by characteristics such as category, subcategory, technology, and risk. This enables precise control over the SaaS application while blocking others, even with dynamic ports and changing IPs. App-ID is the core technology for application-based policy enforcement on Palo Alto Networks firewalls.

Why this answer

App-ID with application filters allows the firewall to identify the SaaS application by its unique traffic characteristics, not by port or IP. This ensures that only the desired application is allowed, even when it uses dynamic ports or changes IP addresses. Application filters further refine policy by grouping applications based on attributes like category and risk, providing granular control.

Exam trap

The trap here is assuming that a port-based service object or IP-based EDL can reliably control an application that uses dynamic ports and changing IPs, but only App-ID can identify the application regardless of those factors.

92
MCQmedium

A company has two Palo Alto Networks firewalls in an active/passive high availability pair. The firewalls are configured with a virtual IP (VIP) for the internal network. Recently, the passive firewall was upgraded to a new PAN-OS version. After the upgrade, the active firewall is still running the old version. The administrator wants to perform a failover to make the upgraded firewall active. However, when the administrator attempts to manually failover, the new passive firewall does not become active. The HA synchronization status shows 'synchronized' but the preemption is disabled. The administrator checks the HA configuration and finds that the peer's version is not compatible. What should the administrator do to successfully failover to the upgraded firewall?

A.Disable HA, then reconfigure HA on both firewalls
B.Upgrade the active firewall to the same PAN-OS version as the passive firewall
C.Force the failover via the CLI using 'request high-availability state suspend' on the active firewall
D.Downgrade the passive firewall back to the old version
AnswerB

PAN-OS requires both HA peers to run identical versions for failover; the incompatible peer version blocks the passive firewall from taking over. Upgrading the active firewall to match restores version parity, satisfying the compatibility constraint so failover can proceed.

Why this answer

PAN-OS requires both firewalls in an active/passive HA pair to run the same major version to form a compatible HA connection. Even if synchronization status shows 'synchronized', the version mismatch prevents failover from succeeding. Upgrading the active firewall to match the passive firewall's version restores version compatibility and allows the failover to proceed.

Exam trap

The trap here is that candidates assume 'synchronized' status means HA is fully functional and failover will work, but they overlook that version compatibility is a prerequisite for stateful failover, not just configuration sync.

How to eliminate wrong answers

Option A is wrong because disabling and reconfiguring HA does not address the root cause—the version mismatch—and would cause unnecessary downtime and configuration loss. Option C is wrong because the 'request high-availability state suspend' command on the active firewall would force it to suspend, but the passive firewall still cannot become active due to the incompatible PAN-OS version, so failover would fail. Option D is wrong because downgrading the passive firewall back to the old version would revert the upgrade, defeating the purpose of making the upgraded firewall active, and is not a best practice for maintaining security and feature updates.

93
Multi-Selectmedium

A network engineer is troubleshooting high latency on the firewall. Which THREE commands from the CLI should be used to identify potential bottlenecks? (Choose three.)

Select 3 answers
A.show running resource-monitor
B.show session info
C.show log traffic
D.show system resources
E.show counter global
AnswersA, D, E

This command shows dataplane resource utilization, useful for identifying CPU/memory bottlenecks.

Why this answer

'show running resource-monitor' displays real-time CPU and memory utilization per dataplane or control plane process, which directly helps identify resource exhaustion causing latency. This command provides granular per-process metrics, unlike the aggregated 'show system resources', making it essential for pinpointing bottlenecks in high-latency scenarios.

Exam trap

The trap here is that candidates often choose 'show session info' thinking it reveals session table overload, but it only shows session details, not utilization percentages or drop counts, which are found in 'show counter global' and 'show running resource-monitor'.

94
MCQeasy

A security administrator wants to block traffic from IP address 192.168.1.100 to the internet. The firewall has a security policy that allows all outbound traffic. Which action should be taken to most efficiently block this specific host?

A.Configure a Zone Protection profile to block the IP.
B.Create a new security rule with source IP 192.168.1.100 and action 'deny', placed before the allow rule.
C.Apply a QoS policy to limit the bandwidth from that IP to zero.
D.Add the IP to an External Dynamic List and reference it in a security rule.
AnswerB

Security rules are evaluated top-down, so a deny rule matching source 192.168.1.100 placed above the broad allow rule blocks only that host while all other outbound traffic still matches the allow rule. This is more efficient than editing the existing allow rule.

Why this answer

The most efficient way to block a specific host in a Palo Alto Networks firewall is to create a security rule with a source IP of 192.168.1.100 and action 'deny', placed before the existing allow rule. Security rules are evaluated in order from top to bottom, and the first matching rule determines the action; placing the deny rule first ensures the host's traffic is blocked without affecting other traffic.

Exam trap

The trap here is that candidates may think a Zone Protection profile or QoS policy can block a specific host, but these features are designed for different purposes (threat prevention and traffic shaping, respectively) and do not provide the precise, rule-based blocking that a security rule offers.

How to eliminate wrong answers

Option A is wrong because Zone Protection profiles are used to protect against flood attacks, reconnaissance, and other network-based threats at the zone level, not to block specific IP addresses from accessing the internet; they operate on traffic patterns, not individual host policies. Option C is wrong because a QoS policy limits bandwidth but does not block traffic; setting bandwidth to zero would still allow the traffic to be processed and potentially dropped due to congestion, but it is not a reliable or efficient method to block a specific host. Option D is wrong because using an External Dynamic List (EDL) is an indirect method that requires additional configuration and external management, making it less efficient than a direct security rule for blocking a single static IP address.

95
MCQmedium

A network engineer is troubleshooting why a Palo Alto Networks firewall is not decrypting SSH traffic even though an SSL Forward Proxy decryption policy is configured for the internal zone. The engineer confirms that the SSH traffic matches the decryption policy and that the forward trust and untrust certificates are installed and valid. What is the most likely reason the SSH traffic is not being decrypted?

A.The decryption policy is not matching because the SSH application is not recognized due to encryption.
B.SSL Forward Proxy decryption does not support SSH; SSH decryption requires SSH Proxy.
C.The decryption policy is not applied because the SSH traffic is using a non-standard port.
D.The forward trust certificate is not trusted by the SSH client, so the firewall bypasses decryption.
AnswerB

SSH is not an SSL/TLS-based protocol, so SSL Forward Proxy cannot decrypt it. Palo Alto Networks firewalls provide SSH Proxy to decrypt and inspect SSH traffic. This requires a separate SSH Proxy decryption policy and a forward trust certificate. Since the engineer only configured SSL Forward Proxy, the SSH traffic remains encrypted and is not decrypted.

Why this answer

SSH is not an SSL/TLS protocol, so SSL Forward Proxy cannot decrypt it. Palo Alto Networks firewalls use SSH Proxy to decrypt and inspect SSH traffic, which requires a separate decryption policy and configuration. Since only SSL Forward Proxy is configured, the SSH traffic remains encrypted even if the policy matches.

The correct solution is to configure SSH Proxy decryption for the SSH traffic.

Exam trap

The trap here is assuming that SSL Forward Proxy can decrypt any encrypted traffic, including SSH, without recognizing that SSH requires a distinct SSH Proxy decryption policy.

96
MCQeasy

A network administrator is setting up a new Palo Alto Networks firewall. The administrator needs to configure the firewall so that it can resolve domain names for its own management traffic, such as for updates and logging. Which type of interface should be configured with a default gateway to allow the firewall to reach external services?

A.Management interface
B.Layer 2 dataplane interface
C.Layer 3 dataplane interface
D.Virtual wire interface
AnswerA

The management interface is used for out-of-band management and for the firewall to communicate with external services such as DNS, NTP, and Palo Alto Networks update servers. To allow the firewall to resolve domain names and reach the internet for updates, the management interface must be configured with a default gateway. This is separate from dataplane interfaces and is essential for management connectivity.

Why this answer

The management interface is dedicated for out-of-band management and for the firewall to communicate with external services like DNS, NTP, and update servers. To allow the firewall to resolve domain names for its own management traffic, the management interface must have a default gateway configured. Dataplane interfaces, whether Layer 3, Layer 2, or virtual wire, are for user traffic and do not handle management traffic by default.

Exam trap

The trap here is assuming that any interface with a default gateway can provide management connectivity, when only the management interface is used for the firewall's own services.

97
MCQhard

A security administrator is configuring a Palo Alto Networks firewall to perform DNS sinkholing to detect and block malware callbacks. The firewall is deployed with a default route to the internet. The administrator wants to ensure that when an internal host attempts to resolve a known malicious domain, the firewall returns a sinkhole IP address (10.10.10.10) and logs the event. Which configuration is required to achieve this?

A.Create a NAT rule that redirects DNS queries for malicious domains to 10.10.10.10.
B.Enable DNS sinkholing in the firewall's DNS proxy settings and specify the sinkhole IP address.
C.Create an Anti-Spyware profile with DNS sinkhole enabled and set the sinkhole IPv4 address to 10.10.10.10, then apply it to a security policy rule.
D.Configure a custom URL category with the malicious domains and set the action to 'sinkhole' in a URL filtering profile.
AnswerC

DNS sinkholing is configured within an Anti-Spyware profile. The profile includes a DNS sinkhole setting where you specify the sinkhole IPv4 address. When the firewall detects a DNS query for a malicious domain (as identified by the threat signature), it responds with the sinkhole IP. Applying the profile to a security rule enables the feature for matching traffic. This is the correct method to implement DNS sinkholing.

Why this answer

DNS sinkholing is implemented through an Anti-Spyware profile. The profile's DNS sinkhole settings allow the firewall to respond to DNS queries for malicious domains with a specified sinkhole IP address. This enables detection and logging of malware callbacks.

Other methods like URL filtering, DNS proxy, or NAT do not provide the same selective inspection and response based on threat signatures.

Exam trap

The trap here is assuming that URL filtering or NAT can perform DNS sinkholing, when it is actually a function of the Anti-Spyware profile.

98
MCQmedium

A network security engineer is troubleshooting a Palo Alto Networks firewall that is dropping traffic to a critical internal server. The engineer runs 'show session all filter destination 10.1.1.50' and sees sessions in the 'discard' state. The engineer wants to determine why these sessions are being discarded. Which action should the engineer take next?

A.Run 'show session id <session-id>' to view detailed session information including the discard reason.
B.Run 'show running resource-monitor' to check if the firewall is under resource stress.
C.Run 'show counter global filter severity drop' to identify the global counters that are incrementing.
D.Run 'debug dataplane packet-diag set filter match destination 10.1.1.50' to capture packets and analyze them.
AnswerA

The 'show session id' command displays detailed information about a specific session, including the reason it was discarded, such as policy deny, application identified as unknown, or threat detection. This is the correct next step to diagnose why sessions are in the discard state.

Why this answer

The 'show session id' command provides detailed session information, including the discard reason, which is essential for troubleshooting why sessions are in the discard state. The other commands either provide aggregate data or require additional steps to correlate with the specific session, making them less efficient for this scenario.

Exam trap

The trap here is assuming that global counters or packet captures directly reveal the discard reason, when in fact session-specific details are needed.

99
Multi-Selecteasy

Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?

Select 2 answers
A.Export to Microsoft Azure Sentinel directly without any intermediate.
B.Local storage on the firewall's management disk (MP) and export via the web interface.
C.SNMPv3 traps for all log types.
D.Email alerts for all threat logs.
E.Syslog to an external log collector.
AnswersB, E

The management plane disk stores logs locally, and the web interface exports them for reporting and forensics. This satisfies the log collection requirement without external infrastructure, though retention is bounded by the firewall's on-box storage capacity.

Why this answer

Option B is correct because the firewall's management plane (MP) can retain logs locally on its management disk, and administrators can retrieve them through the web interface (or CLI) for reporting and forensic review. Option E is correct because the firewall natively supports forwarding logs via syslog to external log collectors (e.g., a syslog server or Panorama in log-collector mode), which is a standard method for centralized reporting and forensics. Option A is not valid because Azure Sentinel does not ingest Palo Alto logs directly without an intermediate, such as a syslog forwarder, Log Analytics agent, or CEF connector.

Option C is incorrect because SNMPv3 traps are used for monitoring/alerting on MIB objects, not for transporting full log records of all log types. Option D is incorrect because email alerts are notification-only and do not provide a complete, structured log collection mechanism for reporting and forensics.

Exam trap

The trap here is that candidates confuse 'log collection' with 'alerting mechanisms' (SNMP traps and email alerts), assuming they can replace full log export, but Palo Alto firewalls require dedicated log forwarding methods (syslog, Panorama, or local export) for complete reporting and forensics.

100
Multi-Selectmedium

A company wants to enforce multi-factor authentication (MFA) for employees accessing a specific internal application through the firewall. Which two configurations are required on the Palo Alto Networks firewall? (Choose two.)

Select 2 answers
A.Define an authentication profile that includes an MFA method
B.Configure a SAML identity provider
C.Create an authentication policy rule that references the application
D.Install the GlobalProtect client on user endpoints
E.Enable SSL decryption on the firewall
AnswersA, C

An authentication profile defines the authentication service and MFA factors the firewall uses to verify users. Referencing it in an authentication policy enforces MFA for the internal application, satisfying the stem's requirement to enforce multi-factor authentication for that specific application.

Why this answer

Option A is correct because an authentication profile on the Palo Alto Networks firewall defines the authentication methods, including MFA (such as RADIUS with OTP, or a SAML/MFA provider), and is the object that the firewall uses to challenge users for credentials and a second factor. Option C is correct because an authentication policy rule is what actually enforces authentication for matching traffic; it references the authentication profile and can be scoped to the specific internal application (via destination/URL category or application), so without this rule no MFA challenge is triggered. Option B is not required because a SAML identity provider is only one possible MFA mechanism and is not mandatory for enforcing MFA; the firewall can use other methods such as RADIUS with OTP.

Option D is not required because GlobalProtect is a remote-access VPN/client solution, not a prerequisite for authenticating users to an internal application through the firewall. Option E is not required because SSL decryption is used for inspecting encrypted traffic, not for enforcing MFA authentication.

Exam trap

The trap here is that candidates often confuse authentication policy rules with security policy rules, or assume that MFA always requires GlobalProtect or SAML, when in fact the firewall can enforce MFA directly via captive portal using an authentication profile and policy rule.

101
MCQmedium

An administrator adds a new security rule to allow outbound 'web-browsing' and 'ssl' traffic. After committing, users report that some HTTPS sites are still blocked. Traffic logs show that the traffic matches the new rule but is denied. What is the most likely cause?

A.The service 'application-default' does not match the port used by the site.
B.A decryption policy is required for HTTPS traffic.
C.The application filter does not include 'ssl'.
D.The rule is placed too low in the rulebase.
AnswerA

The rule permits only ports 80 and 443 via the web-browsing and ssl applications, but application-default enforces those standard ports. HTTPS sites on non-standard ports therefore match the rule yet fail the service check, producing the deny. Defining a custom service, or using any, resolves the mismatch.

Why this answer

When a security rule uses the 'application-default' service, the firewall only allows traffic that matches the default port for the specified application. For 'web-browsing' (HTTP), the default port is TCP 80, and for 'ssl' (HTTPS), the default port is TCP 443. If an HTTPS site uses a non-standard port (e.g., TCP 8443), the traffic matches the rule based on the application but is denied because the service 'application-default' does not recognize that port as valid for the application.

Exam trap

The trap here is that candidates often assume 'application-default' allows any port for the application, when in reality it strictly enforces the default port, causing denial for HTTPS on non-standard ports.

How to eliminate wrong answers

Option B is wrong because a decryption policy is not required for HTTPS traffic to be allowed; decryption is optional and used for inspection, not for basic forwarding. Option C is wrong because the application filter does not need to include 'ssl' separately; the rule already specifies 'ssl' as an application, and the issue is with the service, not the application filter. Option D is wrong because the traffic logs show the traffic matches the new rule, indicating the rule is being evaluated and matched; placement lower in the rulebase would cause a different rule to match first, not a match with denial.

102
MCQeasy

A user complains that they cannot access internal resources via GlobalProtect. The firewall shows the user is connected with an IP address from the tunnel pool. Which log type should the administrator check first to determine if traffic is being allowed or denied?

A.System logs.
B.Traffic logs.
C.Threat logs.
D.User-ID logs.
AnswerB

Traffic logs record the security policy action, source, destination and application for each session, showing whether GlobalProtect tunnel traffic to internal resources was allowed or denied. This directly answers whether policy is blocking the user's access.

Why this answer

The administrator should check Traffic logs first because they record every session attempt, showing whether traffic was allowed or denied based on security policies. Since the user is connected with a tunnel IP, the issue is likely policy-based, and Traffic logs provide the source, destination, and action (allow/deny) for each session, directly revealing if the traffic is being blocked.

Exam trap

The trap here is that candidates may think User-ID logs (Option D) are relevant because the user is connected, but User-ID logs only show authentication mappings, not traffic policy decisions.

How to eliminate wrong answers

Option A is wrong because System logs record system-level events (e.g., process restarts, configuration changes) and do not show per-session allow/deny decisions for user traffic. Option C is wrong because Threat logs capture only traffic that matches intrusion prevention or antivirus signatures, not general allow/deny decisions. Option D is wrong because User-ID logs map usernames to IP addresses but do not indicate whether traffic is permitted or denied by security policies.

103
MCQmedium

A company has two Palo Alto Networks firewalls configured in an active/passive HA pair. Traffic fails over correctly, but after a failover, existing sessions from external users to internal servers are broken. The security team wants to prevent this disruption. Which feature must be enabled?

A.Link Monitoring
B.Virtual Router Redundancy
C.Session State Synchronization
D.Path Monitoring
AnswerC

Session State Synchronization replicates session tables between HA peers, so the passive firewall already holds established flows when failover occurs. This satisfies the scenario's requirement to prevent broken external-to-internal sessions, since traffic resumes without re-establishing TCP handshakes.

Why this answer

Session State Synchronization (option C) is required because it ensures that session table entries—including TCP state, sequence numbers, and application-layer metadata—are replicated from the active firewall to the passive firewall in real time. Without this, after a failover, the newly active firewall has no knowledge of existing sessions, causing it to drop packets and forcing clients to re-establish connections. This feature is specifically designed to maintain stateful session continuity during HA failovers.

Exam trap

The trap here is that candidates confuse high-availability failover mechanisms (like link monitoring or path monitoring) with stateful session replication, assuming that any HA feature will preserve sessions, but only Session State Synchronization specifically copies the session table to the standby device.

How to eliminate wrong answers

Option A is wrong because Link Monitoring only checks the physical link status of interfaces and triggers a failover if a link goes down; it does not replicate session state. Option B is wrong because Virtual Router Redundancy (e.g., VRRP) provides gateway redundancy at Layer 3 but does not synchronize firewall session state; it is unrelated to stateful session preservation. Option D is wrong because Path Monitoring monitors the reachability of specific destination IP addresses (e.g., next-hop gateways) to trigger failover, but it does not synchronize session tables between HA peers.

104
Multi-Selecthard

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Select 3 answers
A.Large number of dynamic IP address group lookups.
B.Inefficient security policy rules causing excessive session processing.
C.Insufficient disk space on the log partition.
D.Excessive logging due to very frequent session matches.
E.BGP prefix flapping causing route recalculations.
AnswersA, B, D

Dynamic group lookups can be CPU intensive.

Why this answer

A large number of dynamic IP address group lookups can cause high CPU utilization because each lookup requires the firewall to evaluate the dynamic group membership in real time, often involving LDAP or other directory queries. This process is computationally expensive, especially when policies trigger frequent lookups for every new session, leading to sustained CPU spikes.

Exam trap

The trap here is that candidates often confuse disk space issues (Option C) with CPU utilization, but disk space problems affect storage and logging, not CPU directly, while BGP flapping (Option E) is a control-plane issue that is less commonly cited as a top cause of high CPU in Palo Alto Networks documentation.

105
MCQeasy

When configuring High Availability on a Palo Alto Networks firewall, which of the following is a best practice for the HA1 control link?

A.Use the management interface (MGT) for HA1
B.Configure HA1 as a subinterface on the HA2 link
C.Configure HA1 over a VLAN on a data interface to save ports
D.Use a dedicated physical interface for HA1, not shared with data traffic
AnswerD

HA1 carries heartbeat and synchronisation control traffic between peers. Sharing it with data traffic lets a saturated data path delay or drop heartbeats, causing false failover; a dedicated physical interface isolates control-plane traffic and satisfies the HA1 best-practise requirement.

Why this answer

The HA1 control link carries critical heartbeat and synchronization traffic between the two firewalls in an active/passive or active/active HA pair. Using a dedicated physical interface ensures that control traffic is isolated from data traffic, preventing congestion or interference that could cause false failovers or synchronization delays. The management interface (MGT) is not recommended for HA1 because it shares the control plane CPU and can be overwhelmed by management traffic, leading to HA instability.

Exam trap

The trap here is that candidates often assume the MGT interface is acceptable for HA1 because it is a separate interface, but Palo Alto Networks explicitly recommends against it due to control plane resource contention and the risk of HA failure during management spikes.

How to eliminate wrong answers

Option A is wrong because the MGT interface is designed for out-of-band management and should not be used for HA1; it shares the control plane CPU and can cause HA heartbeat failures under heavy management load. Option B is wrong because HA1 cannot be configured as a subinterface on the HA2 link; HA2 is a dedicated data link for session and state synchronization, and subinterfaces are not supported for HA control traffic. Option C is wrong because configuring HA1 over a VLAN on a data interface violates the best practice of isolating control traffic; data interface VLANs carry user traffic and can introduce latency or packet loss that disrupts HA heartbeat timing.

106
MCQmedium

An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?

A.Enable the 'Permitted IP Addresses' setting under Device > Setup > Management and enter 10.0.0.0/24.
B.Add a static route for 10.0.0.0/24 pointing to the MGT interface and enable strict routing.
C.Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.
D.Create a security policy rule from the management zone to the management zone allowing only the 10.0.0.0/24 subnet.
AnswerC

An Interface Management profile defines which management services (HTTPS, SSH, etc.) are enabled and from which source networks they are reachable. Assigning it to the MGT interface with permitted IP addresses 10.0.0.0/24 restricts management access to that subnet. This is the correct method to limit management access on a Palo Alto Networks firewall.

Why this answer

Management access on Palo Alto Networks firewalls is controlled by Interface Management profiles, which specify allowed services and permitted source IP addresses. Assigning such a profile to the MGT interface ensures only hosts in 10.0.0.0/24 can reach the web interface and SSH. Security policies and static routes do not govern management plane traffic, and the global permitted IP list is less granular.

Exam trap

The trap here is assuming that security policy rules or static routes control management interface access, when in fact an Interface Management profile is the correct mechanism.

107
MCQhard

A firewall is configured with multiple virtual systems (vsys). The administrator notices that one vsys is consuming excessive dataplane resources, affecting others. Which feature should be used to guarantee each vsys a minimum share of CPU and session capacity?

A.Packet filtering rules
B.Session limit rules
C.QoS profiles
D.Resource profiles
AnswerD

Resource profiles assign each virtual system guaranteed minimum CPU and session capacity, preventing one vsys from monopolising dataplane resources. This directly satisfies the requirement to guarantee every vsys its minimum share when a single vsys consumes excessive resources.

Why this answer

Resource profiles are the correct feature because they allow an administrator to guarantee each virtual system (vsys) a minimum share of dataplane CPU and session capacity. This ensures that resource contention from one vsys does not starve others, providing predictable performance isolation in a multi-tenant firewall environment.

Exam trap

The trap here is confusing session limits (which cap usage) with resource profiles (which guarantee minimums), leading candidates to choose session limit rules as a way to protect other vsys, when in fact they only prevent a single vsys from exceeding a threshold, not ensuring fair share under contention.

How to eliminate wrong answers

Option A is wrong because packet filtering rules control which traffic is allowed or denied based on headers and state, not CPU or session resource allocation. Option B is wrong because session limit rules cap the maximum number of concurrent sessions for a vsys but do not guarantee a minimum share of CPU or session capacity. Option C is wrong because QoS profiles manage bandwidth and priority for network traffic, not dataplane CPU cycles or session table resources.

108
MCQeasy

A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?

A.User not assigned a license
B.Incorrect gateway IP address in portal configuration
C.Gateway interface not in the same zone as portal
D.Gateway MTU mismatch
AnswerB

The portal hands the client the gateway address to connect to; if that configured address is wrong, authentication succeeds but the tunnel to the internal gateway fails. This matches the stem's symptom of portal success with gateway failure on the same firewall.

Why this answer

When the portal and gateway are on the same firewall, the portal configuration must specify the correct IP address or FQDN for the gateway. If the gateway IP address in the portal configuration is incorrect, the client will successfully authenticate to the portal but then fail to establish a tunnel to the gateway because it cannot reach the gateway at the specified address. This is the most common cause of this symptom.

Exam trap

The trap here is that candidates often assume the issue is a zone mismatch or license problem, but the portal and gateway can be in different zones and licenses are not required for basic gateway connectivity, so the incorrect gateway IP address in the portal configuration is the precise cause.

How to eliminate wrong answers

Option A is wrong because license assignment is not required for GlobalProtect gateway connectivity; licenses are only needed for features like GlobalProtect subscription services or specific user counts, not for basic gateway authentication and tunnel setup. Option C is wrong because the portal and gateway can be in different zones; in fact, they are often placed in separate zones (e.g., portal in an untrust zone, gateway in a trust zone) and this does not prevent connectivity as long as inter-zone rules allow the traffic. Option D is wrong because an MTU mismatch would cause packet fragmentation issues or connectivity drops after the tunnel is established, not a failure to connect to the gateway after portal authentication.

109
Multi-Selecthard

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

Select 2 answers
A.Log forwarding must use TLS encryption
B.Log forwarding requires an external syslog server
C.Log forwarding supports sending logs to multiple destinations
D.Log forwarding can be configured per security policy rule
E.Log forwarding can only send logs to a single Panorama collector
AnswersC, D

Panorama log forwarding profiles let you define multiple server entries within a single profile, so each log type can be dispatched to several collectors or syslog receivers simultaneously. This satisfies the requirement for redundancy or parallel retention without duplicating profiles.

Why this answer

Option C is correct because Panorama log forwarding profiles allow you to define multiple server entries (up to four syslog servers, plus SNMP, email, or HTTP destinations) within a single log forwarding profile, so logs can be sent to several destinations simultaneously. Option D is correct because log forwarding profiles are attached directly to security policy rules (via the Actions tab's Log Forwarding setting), enabling per-rule control over where that rule's traffic and threat logs are sent. Option A is incorrect because TLS encryption is not mandatory for log forwarding; syslog forwarding can use UDP or plain TCP, and TLS is only one optional transport choice.

Option B is incorrect because an external syslog server is not required — logs can be forwarded to Panorama itself, to another managed firewall, or to email/SNMP/HTTP destinations. Option E is incorrect because log forwarding is not limited to a single Panorama collector; multiple destinations, including multiple Panorama or syslog targets, can be configured in one profile.

Exam trap

The trap here is that candidates assume Log Forwarding is limited to a single destination or requires a syslog server, but Panorama actually supports multiple destinations and various log types without mandating syslog or TLS.

110
MCQmedium

A security administrator is deploying a PA-5220 firewall with a single external zone and several internal zones. The requirement is to allow DNS queries to any external DNS server while ensuring that responses are permitted only when they match an existing session. Which security policy configuration meets this requirement?

A.Create a security rule from the internal zones to the external zone with application 'dns' and service 'application-default'. No other rules are needed because the firewall automatically allows return traffic.
B.Create two security rules: one from internal zones to external zone allowing application 'dns', and another from external zone to internal zones allowing application 'dns' to permit responses.
C.Create a security rule from internal zones to external zone with service 'dns' (UDP 53) and application 'any'. This ensures DNS queries are allowed and responses are permitted by the stateful engine.
D.Create a security rule from internal zones to external zone with application 'dns' and service 'any'. The firewall will automatically restrict the service to DNS ports based on the application.
AnswerA

This rule permits DNS queries from internal zones to any external DNS server. Using application 'dns' with service 'application-default' ensures the correct ports (UDP/TCP 53) are allowed. The firewall's stateful inspection automatically allows return traffic for established sessions, so no separate inbound rule is required. This is the standard best practice for outbound DNS.

Why this answer

The correct configuration allows DNS queries from internal to external zones using the application 'dns' and service 'application-default'. The firewall's stateful nature automatically permits return traffic for established sessions, so no inbound rule is required. Specifying the application ensures only DNS traffic is allowed, and application-default service restricts to standard DNS ports, maintaining security.

Exam trap

The trap here is assuming that return traffic needs an explicit inbound security rule, which would unnecessarily expose the internal network and violate stateful firewall principles.

111
MCQmedium

A network administrator is troubleshooting an IPsec site-to-site VPN that fails to establish. IKE phase 1 completes successfully, but phase 2 fails with a 'no proposal chosen' message. Both sides have identical IKE and IPsec crypto profiles, and the pre-shared key is correct. What is the most likely cause of the failure?

A.The proxy IDs (local/remote subnets) do not match between peers
B.The tunnel is configured as route-based instead of policy-based
C.The IKE gateway's local interface is down
D.Dead peer detection is not enabled on the IKE gateway
AnswerA

IKE phase 1 succeeding confirms peer authentication and proposal agreement. Phase 2 'no proposal chosen' with identical crypto profiles points to proxy ID mismatch, since the firewall selects the IPsec SA based on matching local and remote subnet selectors.

Why this answer

In IPsec site-to-site VPNs, IKE phase 1 establishes the secure management channel using parameters like encryption, authentication, and Diffie-Hellman groups. Phase 2 negotiates the IPsec security associations (SAs) for actual data traffic, and the 'no proposal chosen' error indicates a mismatch in the phase 2 parameters. Since both sides have identical crypto profiles and the pre-shared key is correct, the most likely cause is that the proxy IDs (local and remote subnets) do not match between peers.

Proxy IDs define the traffic selectors that each peer expects to protect; if they are misaligned, the IPsec SA negotiation fails even if all other settings are identical.

Exam trap

The trap here is that candidates often assume identical crypto profiles guarantee phase 2 success, overlooking that proxy IDs (traffic selectors) are a separate, critical parameter that must be mirrored exactly on both peers.

How to eliminate wrong answers

Option B is wrong because a route-based tunnel (using a tunnel interface) still requires matching proxy IDs or traffic selectors in the IPsec profile; the failure mode for proxy ID mismatch is the same regardless of tunnel type. Option C is wrong because if the IKE gateway's local interface were down, IKE phase 1 would not complete successfully, but the question states phase 1 completes. Option D is wrong because dead peer detection (DPD) is a keepalive mechanism for detecting peer availability and does not affect the negotiation of IPsec SAs or cause a 'no proposal chosen' error.

112
MCQeasy

A network administrator needs to monitor the firewall's interface status and receive alerts when an interface goes down. Which built-in feature should they configure?

A.Syslog forwarding with severity level 'critical'
B.NetFlow export for interface statistics
C.SNMP traps for linkDown
D.Email alerts for system logs
AnswerC

SNMP traps can be configured to send alerts for linkDown events. The firewall supports SNMP traps for interface status changes, including linkDown and linkUp. By configuring an SNMP trap destination and enabling linkDown traps, the administrator can receive immediate notifications when an interface goes down, meeting the monitoring requirement.

Why this answer

SNMP traps are the standard method for receiving real-time alerts on interface status changes. Configuring SNMP traps for linkDown events allows the administrator to be notified immediately when an interface goes down. Other options like syslog, email alerts, or NetFlow do not provide the same immediate and specific alerting for interface status.

Exam trap

The trap here is assuming that any log forwarding method can provide real-time interface status alerts.

113
MCQmedium

An administrator manages a PA-5220 pair running PAN-OS 11.1. During a change window, the active firewall's management plane becomes unreachable and the device fails over to the passive peer. The administrator wants to review the events that occurred on the failed device before the failover. Which action should the administrator take to obtain this information?

A.Connect to the failed device console and review the HA and system logs stored locally in the management plane log files.
B.On the passive peer, run the show high-availability state command and export the output to a file for review.
C.Use the Panorama-managed Config Audit feature to compare the running configuration against the last committed version on the failed device.
D.On the active peer, run the show session all filter source command to identify sessions that terminated during the failover.
AnswerA

The management plane stores HA, system, and configuration logs locally on the device. Even when the management interface is unreachable over the network, console access allows the administrator to read these logs and reconstruct the events leading up to the failover, which is the intended way to investigate this scenario.

Why this answer

Management plane logs are retained locally on each firewall and record system, HA, and configuration events. When the management interface is unreachable but the device still powers on, console access lets the administrator read those logs directly. Panorama config audit, HA state output, and session tables all describe current or configuration state rather than the historical event sequence needed here.

Exam trap

The trap here is assuming that an unreachable management interface means the logs are lost, when local management plane logs remain accessible through the console.

114
MCQhard

An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?

A.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and configure a separate NAT rule for inbound traffic from untrust to trust with destination address '203.0.113.5' and translated destination '10.1.1.0/24'.
B.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5'. No destination translation.
C.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and set the destination translation to the original destination. This ensures return traffic is routed correctly.
D.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and enable 'Bi-directional' option to allow return traffic.
AnswerB

This rule translates the source IP of outbound packets from 10.1.1.0/24 to the external interface IP 203.0.113.5. The original packet zones identify traffic from trust to untrust. The firewall automatically handles return traffic by reversing the translation for established sessions. This is the standard source NAT configuration for hide NAT.

Why this answer

For source NAT, the correct configuration is a NAT rule that translates the source IP of outbound packets from the internal subnet to the external interface IP. The firewall automatically handles return traffic by reversing the translation for established sessions, so no additional rules are needed. This provides hide NAT, allowing multiple internal hosts to share a single public IP.

Exam trap

The trap here is thinking that a separate inbound NAT rule or bi-directional option is needed for return traffic, when the stateful firewall automatically manages it for source NAT.

115
MCQeasy

An HA pair is configured with Active/Passive mode. The passive firewall fails to become active after the active firewall's management interface goes down. What is the most likely cause?

A.HA1 keepalive failure is not detected
B.Management interface failure is not a monitored condition by default
C.HA2 link monitoring is not enabled
D.Session synchronization is not complete
AnswerB

Management interface down does not trigger HA failover unless explicitly configured under device HA.

Why this answer

In an Active/Passive HA pair, the passive firewall monitors the active firewall's liveness via the HA1 control link. By default, only the HA1 link failure triggers a failover; the management interface is not monitored for HA state transitions. Therefore, if the management interface goes down but the HA1 link remains up, the passive firewall does not detect a failure and will not become active.

Exam trap

The trap here is that candidates assume any interface failure triggers HA failover, but Palo Alto Networks HA only monitors interfaces explicitly configured as monitored interfaces; the management interface is not monitored by default.

How to eliminate wrong answers

Option A is wrong because HA1 keepalive failure is detected via the HA1 control link; if the management interface goes down but HA1 remains up, keepalives continue, so no failure is detected. Option C is wrong because HA2 link monitoring is used for data link path monitoring and session synchronization, not for triggering failover in Active/Passive mode; failover is based on HA1 keepalive failure or monitored interface failure, not HA2. Option D is wrong because session synchronization completeness does not affect failover triggering; the passive firewall will not become active unless it detects a failure condition, regardless of sync state.

116
MCQeasy

An organization has a pair of PA-5250 firewalls in active/passive HA. During a maintenance window, the active firewall is rebooted. After the reboot, the firewall that was passive becomes active and passes traffic. However, the other firewall remains in a non-functional state and shows 'unknown' as HA state. The administrator checks the HA configuration and finds both firewalls have the same HA settings. What is the most likely issue?

A.The backup firewall has a different software version.
B.The floating IP addresses are not configured.
C.The HA keepalive timer is too short.
D.The HA control link is down or misconfigured.
AnswerD

HA state synchronisation and election traffic traverse the dedicated HA control link. If that link is down or misconfigured, the rebooted peer cannot exchange hello and state messages, so it remains 'unknown' even though data-plane failover succeeded.

Why this answer

After a reboot, the previously active firewall fails to join the HA pair and shows 'unknown' state, which indicates it cannot communicate with its peer. Since both firewalls have identical HA settings, the most likely cause is that the HA control link (the dedicated link used for heartbeat and state synchronization) is down or misconfigured, preventing the rebooted firewall from establishing a valid HA session.

Exam trap

The trap here is that candidates often assume a software version mismatch or keepalive timer issue is the cause, but the 'unknown' state specifically points to a loss of control-plane connectivity, not a version or timer problem.

How to eliminate wrong answers

Option A is wrong because if the backup firewall had a different software version, the HA pair would typically show a version mismatch or fail to form, but the backup became active and passed traffic successfully, indicating compatible versions. Option B is wrong because floating IP addresses are used for service access and do not affect the HA state or the ability of a firewall to join the pair; the 'unknown' state is a control-plane issue, not a data-plane addressing issue. Option C is wrong because a keepalive timer that is too short would cause flapping or frequent state transitions, not a persistent 'unknown' state; the rebooted firewall would still attempt to re-establish the control link and report its state.

117
MCQhard

After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?

A.The IdP does not support IdP-initiated SAML flow
B.The user mapping agent is not configured
C.The firewall and IdP system clocks are out of sync
D.The SAML identity provider certificate is expired
AnswerC

Clock skew between the firewall and IdP invalidates the assertion's NotBefore/NotOnOrAfter conditions, so signature validation fails despite successful IdP authentication. The portal rejects the assertion as invalid because its timestamp falls outside the permitted window, satisfying the stem's 'invalid saml assertion' constraint. Synchronising both systems via NTP resolves the repeated credential prompts.

Why this answer

The firewall logs show 'saml-auth-success' (meaning the IdP successfully authenticated the user and issued a SAML assertion), but the portal log shows 'user-login-failure: invalid saml assertion'. This indicates the firewall received the assertion but rejected it as invalid. The most common cause for a validly signed assertion to be rejected is clock skew between the firewall and the IdP, because SAML assertions contain timestamps (NotBefore and NotOnOrAfter conditions) that are checked against the local system clock.

If the clocks differ by more than the allowed skew (typically 5 minutes), the assertion is considered invalid even though it was correctly signed.

Exam trap

The trap here is that candidates see 'saml-auth-success' and assume the authentication succeeded end-to-end, but they miss that the firewall's portal log rejection indicates a validation failure on the assertion itself, not a failure at the IdP.

How to eliminate wrong answers

Option A is wrong because IdP-initiated SAML flow is not required for GlobalProtect; GlobalProtect uses SP-initiated SAML flow, where the firewall (service provider) redirects the user to the IdP. The error here is about assertion validation, not about which party initiated the flow. Option B is wrong because the user mapping agent is used for mapping IP addresses to usernames for policy enforcement, not for SAML authentication validation; the error occurs during the SAML assertion validation phase, before any user mapping would occur.

Option D is wrong because if the IdP certificate were expired, the firewall would fail to validate the signature on the SAML assertion and would log a signature validation error, not an 'invalid saml assertion' error; the logs show 'saml-auth-success' from the IdP side, meaning the certificate was valid at the time of signing.

118
MCQmedium

An engineer is deploying a new Palo Alto Networks firewall running PAN-OS 10.1 as a standalone device. The security team requires that the firewall forward syslog messages to an external server. After configuring the Syslog server profile and applying it to a Log Forwarding profile, the engineer notices that no logs are being received on the syslog server. The firewall's management interface can reach the syslog server on UDP port 514. Which action should the engineer take to resolve this issue?

A.Add the syslog server's IP address to the firewall's management interface permitted IP list.
B.Enable logging on the security policy rules that should generate the logs.
C.Configure a security policy rule that allows the management interface to send traffic to the syslog server.
D.Configure a NAT policy to translate the firewall's management IP to an external IP address.
AnswerB

For logs to be forwarded, the originating security policy rules must have logging enabled at session end or at session start. Without logging enabled, no traffic logs are generated, so nothing is sent to the syslog server. Even if the Syslog server profile and Log Forwarding profile are correctly configured, the absence of logs means no forwarding occurs. Enabling logging on the relevant security rules is the necessary step.

Why this answer

Log forwarding requires that the relevant security policy rules have logging enabled. Without logging, no traffic logs are generated, so nothing is sent to the syslog server even if the Syslog server profile and Log Forwarding profile are properly configured. Enabling logging on the security rules that handle the traffic of interest ensures that logs are created and then forwarded according to the Log Forwarding profile.

Exam trap

The trap here is assuming that configuring the Syslog server profile and Log Forwarding profile alone is sufficient, while overlooking that the security policy rules must have logging enabled to generate the logs.

119
MCQmedium

An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?

A.Disable decryption globally and create a custom URL category for the financial domains to enable decryption only for those.
B.Create two Decryption Policy rules: one with 'ssl-decrypt' action for the general category and a second rule with 'no-decrypt' action for the financial domains.
C.Upload the server certificates for the financial domains to the firewall and enable 'no-decrypt' on the Decryption Profile.
D.Configure a single Decryption Policy rule with a 'decrypt' action and add the financial domains to the 'Exclude Certificate' list.
AnswerB

Ordering matters: the no-decrypt rule must sit above the ssl-decrypt rule, because PAN-OS evaluates decryption policy top-down and stops at the first match. This satisfies the stem's constraint that financial services domains retain end-to-end encryption while all other external HTTPS traffic is decrypted.

Why this answer

It follows the best practice of using a 'no-decrypt' rule with higher priority than the 'ssl-decrypt' rule to exclude specific traffic from decryption. This ensures that traffic to financial services domains is not decrypted, while all other external HTTPS traffic is decrypted as required.

Exam trap

The trap here is that candidates may confuse the 'Exclude Certificate' list in the Decryption Profile with a method to prevent decryption, when in fact it only affects certificate re-signing, not the decryption action itself.

How to eliminate wrong answers

Option A is wrong because disabling decryption globally and then enabling it only for specific domains would require decryption of financial traffic, which contradicts the requirement for end-to-end encryption. Option C is wrong because uploading server certificates for financial domains and enabling 'no-decrypt' on the Decryption Profile does not prevent decryption; the 'no-decrypt' action must be set in the Decryption Policy rule, not the profile. Option D is wrong because adding financial domains to the 'Exclude Certificate' list in a Decryption Profile only excludes those certificates from being re-signed, but the traffic is still decrypted, which violates the end-to-end encryption requirement.

120
MCQhard

A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?

A.The custom application signature is not associated with the security rule.
B.The firewall is running in L2 mode.
C.The traffic is not matching the app's protocol or port in the signature.
D.The application timeout is too short.
AnswerC

Custom application signatures match on protocol and port criteria; if the session's UDP port or protocol differs from the signature definition, App-ID cannot identify it, so the session is logged as unknown rather than matching the custom app.

Why this answer

The custom application definition specifies UDP port 12345, but if the actual traffic uses a different port or does not match the protocol (UDP) defined in the signature, the firewall will classify it as 'unknown'. The security rule allows the application, but the traffic must first be identified by the App-ID engine based on the signature's protocol and port criteria; a mismatch here prevents proper classification.

Exam trap

The trap here is that candidates assume a security rule referencing a custom application will automatically classify all traffic on that rule as the application, but App-ID requires the traffic to match the signature's protocol and port criteria first.

How to eliminate wrong answers

Option A is wrong because custom application signatures are automatically associated with the security rule when the rule references the application; no separate association step is needed. Option B is wrong because L2 mode does not affect App-ID classification; the firewall still performs application identification regardless of the deployment mode. Option D is wrong because the application timeout controls how long a session remains active after traffic stops, not whether the traffic is initially identified as the custom application.

121
MCQhard

A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?

A.The firewall's decryption profile is blocking the session because the website's certificate is expired.
B.The firewall's SSL decryption license has expired, causing it to block decrypted sessions.
C.The website requires TLS 1.3, which is not supported by the firewall's decryption profile.
D.The website uses certificate pinning, causing the client to reject the firewall's forged certificate.
AnswerD

Certificate pinning in applications or browsers causes them to expect a specific certificate or public key. When the firewall performs SSL Forward Proxy decryption, it presents a forged certificate, which the client rejects if pinning is enforced. This leads to access failures. Exempting such sites from decryption is a common workaround.

Why this answer

Certificate pinning causes clients to expect a specific certificate or public key for a website. When SSL Forward Proxy decryption is enabled, the firewall presents a forged certificate, which the client rejects due to pinning. This results in access failures.

Exempting such sites from decryption is a typical solution. Other causes like expired certificates or licensing are not applicable here.

Exam trap

The trap here is assuming that a trusted public CA certificate guarantees successful decryption, overlooking client-side pinning.

122
MCQeasy

An administrator has configured an authentication profile with LDAP and sets the authentication sequence to 'continue on failure'. A user enters an incorrect password first, then correct. Will the user be authenticated?

A.Yes, because the sequence continues on failure and the second attempt succeeds.
B.Yes, but only if the LDAP server is configured for multiple attempts.
C.No, because the first failure blocks authentication.
D.No, because the sequence stops on success, but the first attempt failed.
AnswerD

Correct. The authentication sequence 'continue on failure' only moves to the next method if the current method fails due to a server error (timeout, unreachable). An incorrect password is a successful authentication attempt that returns a negative result; therefore, the sequence stops, and the user is not authenticated. The second correct password is never tried.

Why this answer

The authentication sequence 'continue on failure' only proceeds to the next authentication method if the current method fails (e.g., server timeout or unreachable). It does NOT retry the same LDAP server with a different password. Since the first attempt failed due to an incorrect password, the sequence stops, and the user is not authenticated.

The second correct password is never attempted because the failure is treated as a final rejection, not a retry opportunity.

Exam trap

The trap here is that candidates confuse 'continue on failure' (which moves to the next authentication method after a server error) with a retry mechanism for incorrect passwords, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because 'continue on failure' does not mean the user can retry with a different password on the same LDAP server; it only moves to the next authentication method (e.g., another LDAP server or local database) if the first method fails due to a connectivity or server error, not due to invalid credentials. Option B is wrong because the LDAP server configuration for multiple attempts is irrelevant; the Palo Alto Networks firewall's authentication sequence controls retries, and the sequence does not retry the same server with a corrected password. Option C is wrong because the first failure does not block authentication in all cases; it blocks authentication only because the failure is due to invalid credentials, not because the sequence stops unconditionally.

123
MCQhard

Two Palo Alto Networks firewalls are configured in an active/passive HA pair. During a scheduled maintenance, the network team reboots both firewalls simultaneously. After reboot, both firewalls appear as 'active' in the HA state. What is the most likely cause and the correct troubleshooting step?

A.Both firewalls have the same priority; the tie is broken by serial number, but due to simultaneous reboot, both came up as active. The solution is to reboot one firewall.
B.The HA configuration is set to active/active mode instead of active/passive.
C.The heartbeat link between the firewalls is missing or fails, causing each to believe the other is down. The correct step is to restore the heartbeat link and then set the appropriate firewall as passive.
D.The heartbeat interfaces are not configured on each firewall.
AnswerC

A missing heartbeat link prevents each firewall from receiving HA hello messages, so both transition to active after reboot. Restoring the heartbeat connection re-establishes state synchronisation and election, after which the secondary can be forced passive to clear the split-brain condition.

Why this answer

In an active/passive HA pair, each firewall monitors the peer's health via the heartbeat link. If the heartbeat link fails, each firewall assumes the peer is down and transitions to active state to ensure traffic continuity. Simultaneous reboot does not cause both to become active unless the heartbeat link is absent or broken; restoring the heartbeat link and forcing one firewall to passive resolves the split-brain scenario.

Exam trap

The trap here is that candidates assume simultaneous reboot causes a priority tie, but the real issue is the missing heartbeat link, which prevents the firewalls from detecting each other's state after reboot.

How to eliminate wrong answers

Option A is wrong because priority and serial number tie-breaking only apply when both firewalls attempt to become active at the same time with a functional heartbeat; simultaneous reboot does not override the need for heartbeat communication. Option B is wrong because active/active mode would require explicit configuration and would not cause both to appear active after reboot if the heartbeat link were functional; the symptom described matches a heartbeat failure, not a mode misconfiguration. Option D is wrong because the heartbeat interfaces must be configured for HA to function; if they were not configured, the firewalls would not form an HA pair at all, but the question states they are in an HA pair, implying heartbeat interfaces are configured.

124
MCQeasy

A network security administrator is deploying a new PA-3220 firewall in a data center. The security team requires that all traffic traversing the firewall be inspected for threats, but they want to minimize latency for trusted internal traffic that is already known to be benign. The administrator decides to create a security policy rule that allows traffic from the 'Trust' zone to the 'DMZ' zone without any security profiles attached. Which statement accurately describes the behavior of this rule?

A.The traffic will be allowed, but the firewall will still perform application identification and threat inspection if a profile is later added to the rule.
B.The traffic will be allowed, and because no security profiles are attached, the firewall will not perform any threat inspection on this traffic.
C.The traffic will be blocked by default because security profiles are mandatory for all allow rules.
D.The traffic will be allowed, but the firewall will automatically apply the default security profiles from the 'default' security profile group.
AnswerB

Security profiles are the mechanism that enables threat inspection. When a security policy rule allows traffic and no security profiles are attached, the firewall does not apply antivirus, anti-spyware, vulnerability protection, or other threat scanning for that session. This matches the administrator's intent to minimize latency for trusted internal traffic.

Why this answer

Security profiles are the components that enable threat inspection on allowed traffic. When a security policy rule permits traffic but has no security profiles attached, the firewall performs application identification and other basic functions but does not scan for threats such as viruses, spyware, or vulnerabilities. This behavior allows administrators to tailor inspection based on trust levels and performance requirements.

In this scenario, the administrator intentionally omits profiles to reduce latency for trusted internal traffic, and the firewall will honor that configuration.

Exam trap

The trap here is assuming that the firewall always performs threat inspection on allowed traffic, but threat inspection requires explicit attachment of security profiles to the security policy rule.

125
Drag & Dropmedium

Order the steps to upgrade the PAN-OS software on a standalone firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for upgrading PAN-OS on a standalone firewall is: Download the new image from the support portal, Upload it to the firewall, Install the image, Reboot the firewall to load the new version, and Verify the upgrade was successful. Common mistakes include swapping the order of upload and download, installing before upload, or reboot before install.

126
MCQmedium

A network security engineer is configuring an authentication profile on a Palo Alto Networks firewall to allow administrators to log in using their Active Directory credentials. The engineer wants to ensure that only members of the 'NetOps' group can access the firewall. Which setting in the authentication profile should be configured to enforce this?

A.Allow List
B.User Domain
C.Kerberos Keytab
D.Authentication Sequence
AnswerA

The Allow List in an authentication profile specifies which users or groups are permitted to authenticate. By adding the 'NetOps' group to the Allow List, only members of that group can successfully authenticate. This directly enforces the group-based access restriction described in the scenario.

Why this answer

The Allow List in an authentication profile explicitly permits only specified users or groups to authenticate. By adding the 'NetOps' group, the firewall will check group membership during authentication and allow only those users. Other settings like authentication sequence, user domain, or Kerberos keytab do not provide this group-based restriction.

Exam trap

The trap here is confusing the authentication sequence with the Allow List, assuming that the sequence itself can enforce group membership.

127
MCQmedium

A company implements SSL Forward Proxy decryption. Users complain that accessing certain websites, such as video streaming and software updates, is slow. Which action should the administrator take to improve performance?

A.Increase the SSL session cache to 1024.
B.Upgrade the firewall to a higher model.
C.Exclude known high-traffic sites from decryption.
D.Enable SSL session re-use.
AnswerC

SSL Forward Proxy decryption adds significant CPU load, and streaming or update traffic consumes disproportionate bandwidth for little inspection value. Excluding those destinations from decryption bypasses the proxy processing entirely, restoring throughput and reducing firewall resource consumption.

Why this answer

Excluding known high-traffic sites (e.g., video streaming and software update servers) from SSL Forward Proxy decryption reduces the processing overhead on the firewall. Decrypting and re-encrypting high-volume traffic consumes significant CPU and memory resources, causing latency. By bypassing decryption for these sites, the firewall can forward traffic directly, improving performance without sacrificing security for other traffic.

Exam trap

The trap here is that candidates often focus on optimizing TLS handshake performance (session cache or reuse) rather than recognizing that the primary bottleneck is the decryption of large data payloads, which is unaffected by handshake optimizations.

How to eliminate wrong answers

Option A is wrong because increasing the SSL session cache to 1024 (the maximum supported value) only helps with session reuse for previously decrypted connections, but it does not address the fundamental bottleneck of decrypting high-traffic streams; the cache reduces handshake overhead, not bulk data processing. Option B is wrong because upgrading to a higher model firewall is a costly, long-term solution that does not solve the immediate performance issue; the problem is likely due to decryption of high-volume traffic, not insufficient hardware capacity for normal operations. Option D is wrong because enabling SSL session reuse (via session IDs or session tickets) reduces the number of full TLS handshakes but does not reduce the decryption workload for the actual data transfer; the slowdown is from decrypting large payloads, not from repeated handshakes.

128
MCQhard

An organization has two different applications (AppA and AppB) that both use TCP port 8080. The firewall must apply different security policies to each application. What is the recommended approach?

A.Use source/destination IP addresses in security policies instead of App-ID.
B.Add the applications on separate virtual wire interfaces.
C.Change the port of one application to a different value.
D.Create an application override policy to identify each application by IP address.
AnswerD

Application override lets the firewall classify AppA and AppB by source or destination IP rather than signature, since both share TCP port 8080 and App-ID cannot distinguish them. This satisfies the requirement to apply different security policies to each application.

Why this answer

When two applications share the same TCP port (8080), App-ID cannot differentiate them based on port alone. An application override policy allows you to explicitly identify each application by its source/destination IP address, overriding the default App-ID classification and enabling separate security policies for AppA and AppB.

Exam trap

The trap here is that candidates often assume App-ID can always distinguish applications on the same port, but in reality, when applications share the same port and protocol, an application override is required to enforce different policies based on IP addresses.

How to eliminate wrong answers

Option A is wrong because using source/destination IP addresses in security policies without App-ID bypasses the application visibility and control that App-ID provides, and it does not leverage the firewall's ability to identify applications by their behavior. Option B is wrong because virtual wire interfaces are used for transparent mode deployments and do not solve the problem of distinguishing two applications on the same port; they would still see the same TCP port 8080 traffic. Option C is wrong because changing the port of one application is a workaround that may not be feasible in production and does not utilize the firewall's App-ID capabilities; it also introduces unnecessary complexity and potential compatibility issues.

129
MCQeasy

An administrator wants to enforce authentication for SSL decrypted traffic so that only authenticated users can access decrypted content. Which firewall feature should be configured?

A.SSL Inbound Inspection
B.Authentication Policy
C.User-ID agent
D.SSL Forward Proxy
AnswerB

Authentication Policy enforces user-based access control after SSL decryption, matching traffic against Microsoft Entra ID, LDAP or local user groups. It satisfies the stem's constraint that only authenticated users reach decrypted content, unlike decryption profiles or URL filtering, which act on traffic regardless of identity.

Why this answer

Authentication Policy is the correct feature because it allows the firewall to enforce user authentication specifically for SSL decrypted traffic. By configuring an Authentication Policy, the firewall can require users to authenticate before accessing decrypted content, ensuring that only authenticated users can proceed. This is distinct from SSL decryption profiles, which handle the decryption itself but not user access control.

Exam trap

The trap here is that candidates often confuse SSL Forward Proxy (which handles decryption) with Authentication Policy (which handles user access control), leading them to select the decryption feature instead of the authentication enforcement feature.

How to eliminate wrong answers

Option A is wrong because SSL Inbound Inspection is used to decrypt inbound traffic destined for protected servers, not to enforce authentication for decrypted content. Option C is wrong because the User-ID agent is responsible for mapping users to IP addresses for visibility and policy enforcement, but it does not enforce authentication for decrypted traffic. Option D is wrong because SSL Forward Proxy decrypts outbound SSL traffic for inspection, but it does not enforce user authentication; it only enables decryption.

130
MCQhard

A security administrator is troubleshooting App-ID on a firewall that is deployed in a Layer 2 transparent mode. The administrator notices that some applications are not being identified correctly, even though the traffic is not encrypted. What is the most likely reason for this issue?

A.App-ID requires the firewall to be in Layer 3 mode to perform protocol decoding.
B.Layer 2 transparent mode does not support App-ID inspection.
C.The firewall is not in the path of the traffic, so it cannot inspect it.
D.The firewall may be configured to bypass App-ID inspection for certain zones or interfaces.
AnswerD

In Layer 2 transparent mode, the firewall can be configured with zones and interfaces that have App-ID inspection disabled or bypassed, such as when using a 'tap' mode or when certain traffic is excluded. This can prevent App-ID from identifying applications. The administrator should check the zone and interface configurations to ensure App-ID is enabled.

Why this answer

In Layer 2 transparent mode, the firewall can inspect traffic, but App-ID may be bypassed if certain zones or interfaces are configured to disable inspection. This can happen if the administrator has set the zone to not perform App-ID or if the traffic is excluded from inspection. Checking these configurations is the most likely solution.

Exam trap

The trap here is assuming that Layer 2 mode inherently prevents App-ID inspection, when in fact it is supported, but configuration can disable it.

131
MCQmedium

An administrator is troubleshooting high CPU usage on a PA-5250 firewall. The CPU usage spikes every 5 minutes. Which CLI command should be used to identify the process causing the spike?

A.show session all
B.show dataplane
C.show running resource-monitor
D.show system resources
AnswerC

The resource-monitor command samples per-process CPU and memory usage at intervals, so it captures the five-minute spike and names the offending process. Plain 'show system resources' gives only a point-in-time snapshot, which would likely miss the periodic spike.

Why this answer

The 'show running resource-monitor' command displays real-time CPU and memory usage per process on Palo Alto Networks firewalls. Since the CPU spikes every 5 minutes, this command can identify which specific process (e.g., management-plane daemon, dataplane task) is consuming the most CPU during those intervals, enabling targeted troubleshooting.

Exam trap

The trap here is that candidates often confuse 'show system resources' (overall utilization) with 'show running resource-monitor' (per-process breakdown), assuming the former is sufficient for process-level diagnosis when it only shows aggregate CPU and memory percentages.

How to eliminate wrong answers

Option A is wrong because 'show session all' lists active sessions but does not provide per-process CPU usage data. Option B is wrong because 'show dataplane' shows dataplane statistics and packet processing info, not management-plane process CPU consumption. Option D is wrong because 'show system resources' gives overall system CPU and memory usage but lacks the granular per-process breakdown needed to pinpoint the specific process causing the spike.

132
Multi-Selecthard

Which THREE of the following are mandatory components for GlobalProtect client connectivity?

Select 3 answers
A.Authentication profile.
B.Client certificate.
C.DNS suffix.
D.Gateway configuration.
E.Portal configuration.
AnswersA, D, E

An authentication profile is mandatory because GlobalProtect must verify user identity before granting tunnel access. It binds the portal or gateway to a specific authentication method, such as LDAP, SAML or Kerberos, satisfying the requirement that every client connection is authenticated. Without it, no user credential validation occurs and connectivity cannot be established.

Why this answer

Option A (Authentication profile) is correct because the GlobalProtect portal and/or gateway must reference an authentication profile to authenticate users before granting access, making it a mandatory component for client connectivity. Option D (Gateway configuration) is correct because the GlobalProtect gateway is the actual security enforcement point that terminates the client tunnel and provides access to protected resources; without it, clients cannot establish connectivity. Option E (Portal configuration) is correct because the portal is the initial connection point that delivers client configuration and gateway information to the GlobalProtect agent, and it is required for the client to discover and connect to gateways.

Option B (Client certificate) is not mandatory because certificate-based authentication is only one possible method; username/password or other authentication methods can be used instead. Option C (DNS suffix) is not mandatory because it is an optional configuration setting used for split-DNS or internal name resolution, not a requirement for establishing GlobalProtect connectivity.

Exam trap

The trap here is that candidates often confuse optional features like client certificates or DNS suffixes with mandatory components, but the exam specifically tests that only the portal, gateway, and authentication profile are required for the client to establish connectivity.

133
MCQmedium

Refer to the exhibit. A firewall administrator is troubleshooting why some applications are not being correctly identified. The firewall is running App-ID version 8000-7120. What does the 'appid packet buffer: 1024 KB' indicate?

A.App-ID can only handle 1024 KB of packet data per session.
B.The firewall can buffer up to 1024 KB of packet data for App-ID analysis.
C.The firewall logs the first 1024 KB of every session for App-ID.
D.The firewall offloads App-ID processing to a dedicated buffer of 1024 KB.
AnswerB

The packet buffer figure defines how much packet payload the App-ID engine can hold in memory while matching signatures across multiple packets. Exceeding this 1024 KB limit truncates analysis, causing applications needing deeper inspection to be misidentified.

Why this answer

The 'appid packet buffer: 1024 KB' indicates the maximum amount of packet payload data the firewall can buffer per session for App-ID analysis. This buffer stores the initial packets of a session so that App-ID can inspect the payload for application signatures, even if the data arrives in multiple packets. Option B correctly states this buffering capability.

Exam trap

The trap here is confusing the buffer size with a per-session data limit or a logging threshold, when in fact it is a temporary storage mechanism for App-ID analysis.

How to eliminate wrong answers

Option A is wrong because App-ID does not have a hard limit of 1024 KB of packet data per session; the buffer size is a configurable limit for buffering, not a processing limit. Option C is wrong because the firewall does not log the first 1024 KB of every session; it buffers the data for analysis, not for logging purposes. Option D is wrong because App-ID processing is not offloaded to a dedicated buffer; the buffer is part of the firewall's normal packet processing pipeline and is used for temporary storage during signature matching.

134
MCQeasy

An administrator configures the management interface with IP 192.168.1.1/24 and can ping it from a host on the same subnet, but cannot access the web interface. What is the likely cause?

A.The web server is not running.
B.The host is not in the allowed IP list.
C.The firewall is in FIPS mode.
D.HTTP/HTTPS is not enabled in the interface management profile.
AnswerD

Ping succeeds because ICMP is permitted by default on the management interface, but the web interface requires HTTP or HTTPS explicitly enabled within the interface management profile; without that service permitted, management access is refused.

Why this answer

The management interface on a Palo Alto Networks firewall requires an explicit management profile that enables HTTP/HTTPS access. Even if the interface has a valid IP and is reachable via ping (ICMP), the web server will not respond to HTTP/HTTPS requests unless the corresponding services are enabled in the interface management profile. By default, the management interface may have a profile that allows only ping, not web access.

Exam trap

The trap here is that candidates assume a reachable IP (via ping) implies all management services are accessible, but Palo Alto separates ICMP from HTTP/HTTPS in the management profile, so ping success does not guarantee web access.

How to eliminate wrong answers

Option A is wrong because the web server (management web interface) is a built-in service that is always running on the firewall; the issue is not that the server is down, but that access is blocked by the management profile. Option B is wrong because the allowed IP list is a separate access control mechanism that restricts which source IPs can reach the management interface, but the question states the host can ping the interface, so the host is reachable; the problem is that HTTP/HTTPS services are not permitted in the profile, not that the host is excluded from an allow list. Option C is wrong because FIPS mode affects cryptographic algorithms and disables weaker protocols, but it does not prevent HTTP/HTTPS access entirely; if FIPS mode were enabled, HTTPS would still work with FIPS-compliant ciphers, so this would not cause a complete inability to access the web interface.

135
MCQhard

Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?

A.The traffic matched a security rule that explicitly denies it
B.A threat prevention profile detected and blocked the session
C.The traffic was blocked because the application is not allowed
D.The destination URL is categorized as prohibited
AnswerA

The log names 'deny-rule' as the matched rule, so the drop results from explicit policy denial rather than an implicit default or threat inspection. Traffic matching that rule is discarded, satisfying the stem's requirement to explain the drop event from 203.0.113.10 to 10.1.1.200 on port 443.

Why this answer

The traffic log explicitly states that the rule matched is 'deny-rule'. In Palo Alto Networks firewalls, when a security rule is configured with an action of 'Deny', any traffic matching that rule is dropped and logged with a 'deny' action. Since the log shows a drop event and the matched rule is 'deny-rule', the most direct and likely reason is that the traffic was explicitly denied by this security rule, not by any additional security profiles or external factors.

Exam trap

The trap here is that candidates may confuse a security rule's 'deny' action with a block caused by a security profile (like Threat Prevention or URL Filtering), but the log explicitly shows the rule matched is 'deny-rule', indicating the drop is from the rule itself, not from any profile-based inspection.

How to eliminate wrong answers

Option B is wrong because a threat prevention profile blocking a session would be logged with a different action (e.g., 'reset-both' or 'drop') and would reference a specific threat ID or vulnerability signature, not simply show a rule match of 'deny-rule'. Option C is wrong because if the application were not allowed, the firewall would typically log an 'application not allowed' or 'deny' action with a different rule match, but the log explicitly shows the rule 'deny-rule' as the matched rule, indicating the deny is due to the rule itself, not an application-based policy. Option D is wrong because URL filtering blocks would be logged with a URL filtering profile action (e.g., 'block' or 'override') and would reference a URL category, not simply show a rule match of 'deny-rule'; the log does not indicate any URL filtering profile involvement.

136
MCQmedium

A team uses the Panorama API to generate custom reports. They need to retrieve a list of all rules that have logging at session end enabled. Which API endpoint should be used?

A.GET /api/?type=config&action=get&xpath=/config/devices/entry/vsys/entry/rulebase/security/rules
B.GET /api/?type=op&cmd=<show><log></log></show>
C.GET /api/?type=config&action=get&xpath=/config/shared/log-settings
D.GET /api/?type=report&reporttype=predefined
AnswerA

Retrieving the security rulebase via a config get returns each rule's definition, including its log-end setting, so the team can filter for rules with session-end logging enabled. This satisfies the requirement to enumerate all such rules, since logging configuration lives in the rulebase itself rather than operational logs.

Why this answer

Security rules and their log settings live in the rulebase under /config/devices/entry/vsys/entry/rulebase/security/rules, so a config-type GET against that XPath returns every security rule including the log-end attribute. Filtering the returned XML for log-end='yes' yields the list of rules with session-end logging enabled. This is the correct API path for reading rule configuration, not logs or reports.

Exam trap

The trap is confusing configuration retrieval with log retrieval — candidates see 'logging' in the question and pick the show log or report endpoint, but the question asks for rule configuration, which lives in the config tree.

How to eliminate wrong answers

Option B is wrong because type=op with a show log command retrieves actual log entries from the log database, not the rule configuration that defines which rules log at session end. Option C is wrong because /config/shared/log-settings holds global log forwarding and profile settings, not individual security rule definitions. Option D is wrong because type=report with a predefined reporttype returns generated report data, not raw rule configuration, and cannot be filtered by the log-end attribute.

137
MCQmedium

A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?

A.Multiple virtual routers
B.ECMP with route metrics
C.Policy-based forwarding (PBF) with source criteria
D.Subinterfaces per ISP
AnswerC

Policy-based forwarding evaluates source addresses before the routing table, so matching traffic is forced out ISP-1 regardless of load-balancing or route metrics. This directly satisfies the requirement that specific sources always egress via one ISP, which ECMP or failover alone cannot guarantee.

Why this answer

Policy-based forwarding (PBF) allows you to override the routing table for specific traffic based on criteria such as source IP, destination IP, or application. By configuring a PBF rule with source criteria, you can force traffic from certain sources to always egress via ISP-1, regardless of the load-balancing configuration. This is the correct method for source-based path selection in a multi-ISP setup.

Exam trap

The trap here is that candidates often confuse ECMP load balancing with source-based path selection, assuming that route metrics or multiple virtual routers can achieve deterministic egress control, when in fact only PBF provides the necessary policy override for specific source traffic.

How to eliminate wrong answers

Option A is wrong because multiple virtual routers are used to maintain separate routing tables for different network segments or administrative domains, not to selectively forward traffic from specific sources to a particular ISP. Option B is wrong because ECMP with route metrics distributes traffic across multiple equal-cost paths based on a hash algorithm (e.g., source-destination IP), but it cannot guarantee that traffic from specific sources always uses ISP-1; it is designed for load balancing, not deterministic source-based routing. Option D is wrong because subinterfaces per ISP are used to segment traffic at Layer 2 or for VLAN tagging, not to enforce egress path selection based on source criteria; they do not influence the routing decision.

138
Multi-Selecthard

Which THREE are required for a successful firewall-to-firewall IPSec VPN tunnel? (Choose three.)

Select 3 answers
A.Matching IKE version and encryption algorithms
B.Same firewall model
C.Same certificate authority
D.Matching proxy IDs (local/remote subnets)
E.Matching pre-shared keys or certificates
AnswersA, D, E

Matching IKE version and encryption algorithms is mandatory because both peers must negotiate identical Phase 1 and Phase 2 proposals; any mismatch in IKEv1 versus IKEv2, encryption, hashing, authentication or Diffie-Hellman group causes the security association negotiation to fail, preventing the tunnel from establishing.

Why this answer

Option A is correct because both peers must negotiate a compatible IKE version (IKEv1 or IKEv2) and agree on matching Phase 1/Phase 2 encryption, hash, authentication, and DH group algorithms, otherwise the ISAKMP/IPSec SA negotiation fails. Option D is correct because the proxy IDs (local and remote subnet selectors) must mirror each other on both firewalls; if the local subnet on one side does not match the remote subnet on the other, the tunnel will not establish or will fail to pass traffic. Option E is correct because authentication requires matching pre-shared keys or mutually trusted certificates, and a mismatch in PSK or certificate trust causes Phase 1 authentication to fail.

Option B is not required because IPSec is a standards-based protocol and interoperates between different firewall vendors and models. Option C is not required because a shared certificate authority is only needed when using certificate-based authentication; PSK authentication works without any CA, and even with certificates the requirement is mutual trust, not necessarily the same CA.

Exam trap

The trap here is that candidates often assume hardware or CA compatibility is required, but the PCNSE exam tests that only IKE parameters, authentication credentials, and proxy IDs must match—not the firewall model or a shared CA.

139
MCQhard

In an Active/Passive HA pair, the passive firewall reports 'non-functional' state. The 'show high-availability state' output on the passive shows 'state: non-functional' and 'reason: configuration mismatch'. The active firewall shows 'state: active' and 'reason: no reason'. Which action should be taken to resolve the issue without disrupting traffic?

A.Run 'request high-availability sync-to-remote' from the active firewall
B.Restart the HA process on the passive firewall with 'debug software restart high-availability'
C.Failover the active firewall to force re-sync
D.Upgrade both firewalls to the same PAN-OS version
AnswerA

Running `request high-availability sync-to-remote` from the active firewall pushes the running configuration to the passive peer, resolving the configuration mismatch that forces the passive into non-functional state. Because the passive is already not passing traffic, synchronising it cannot disrupt existing sessions, satisfying the no-disruption constraint.

Why this answer

The 'configuration mismatch' error indicates that the configuration databases on the active and passive firewalls are out of sync. Running 'request high-availability sync-to-remote' from the active firewall pushes the active configuration to the passive firewall without disrupting traffic, as it only updates the passive unit's configuration and does not trigger a failover or restart.

Exam trap

The trap here is that candidates often assume a 'non-functional' state requires a restart or failover, but the specific 'configuration mismatch' reason points to a sync issue that can be resolved non-disruptively with a configuration push from the active firewall.

How to eliminate wrong answers

Option B is wrong because restarting the HA process on the passive firewall does not resolve a configuration mismatch; it only restarts the HA state machine and may temporarily disrupt HA communication without syncing the configuration. Option C is wrong because failing over the active firewall would force a traffic disruption by switching the active role to the passive unit, which is in a non-functional state, potentially causing a full outage. Option D is wrong because the issue is a configuration mismatch, not a PAN-OS version mismatch; upgrading both firewalls would not fix the configuration discrepancy and could introduce unnecessary downtime.

140
MCQhard

A security administrator is configuring a security policy to allow the 'web-browsing' application but block the 'facebook' application. The administrator creates a rule that allows 'web-browsing' and a subsequent rule that denies 'facebook'. However, users report that they can still access Facebook. The administrator checks the traffic logs and sees that Facebook traffic is being identified as 'web-browsing'. Which action should the administrator take to correctly block Facebook?

A.Create a custom App-ID signature for Facebook based on its SSL certificate.
B.Add a URL filtering profile to block facebook.com.
C.Enable SSL decryption for Facebook traffic to allow App-ID to identify it correctly.
D.Modify the security policy to deny 'ssl' instead of 'facebook'.
AnswerC

Facebook uses SSL/TLS encryption, and without decryption, the firewall may only see 'web-browsing' or 'ssl' rather than the specific application. Enabling SSL decryption allows the firewall to inspect the encrypted traffic and identify it as 'facebook'. This is necessary because App-ID cannot always distinguish between encrypted applications without decryption. Once decrypted, the firewall can enforce the deny rule for 'facebook'.

Why this answer

The correct action is to enable SSL decryption for Facebook traffic. Without decryption, the firewall cannot inspect the encrypted payload and may only see generic 'web-browsing' or 'ssl'. By decrypting, the firewall can identify the application as 'facebook' and enforce the deny rule.

The other options are either too broad, unreliable, or address a different feature.

Exam trap

The trap here is assuming that App-ID can always identify applications even when encrypted, when in fact SSL decryption is often required for accurate identification of encrypted applications.

141
MCQmedium

A firewall is dropping traffic that should be allowed. The security policy appears correct. An administrator checks the session table and notices the session state is 'CLOSE'. What is the most likely cause of the traffic being dropped?

A.The server is sending a FIN/RST prematurely due to application layer issues.
B.A deny all security policy is blocking the traffic.
C.Asymmetric routing is causing the session to be torn down.
D.Packet buffer exhaustion on the firewall is causing drops.
AnswerA

A session in CLOSE state means a FIN or RST was already exchanged, so the firewall treats the flow as terminating and drops subsequent packets. A premature FIN/RST from the server, caused by application-layer issues, produces this state despite a correct security policy.

Why this answer

When a firewall sees a session state of 'CLOSE', it indicates that the session has been terminated via a proper TCP FIN or RST exchange. If the server is sending a FIN or RST prematurely due to application-layer issues (e.g., a misconfigured application, a bug causing early connection closure, or a load balancer sending a reset), the firewall will close the session and drop subsequent packets that belong to that flow, even if the security policy allows the traffic. This is because the firewall's session table no longer has an active session for the traffic, so the packets are treated as unsolicited and dropped.

Exam trap

The trap here is that candidates often assume a 'CLOSE' state means the firewall is actively dropping traffic due to a policy or resource issue, but the correct interpretation is that the session was properly terminated and the firewall is simply enforcing that closure by dropping subsequent packets.

How to eliminate wrong answers

Option B is wrong because a 'deny all' security policy would cause the firewall to drop traffic at the policy lookup stage, not after a session is established and then closed; the session state would not show 'CLOSE' but rather the traffic would never create a session. Option C is wrong because asymmetric routing typically causes the firewall to see only one direction of traffic, leading to session setup failures or 'half-open' states, not a clean 'CLOSE' state; the firewall would drop packets due to no matching session, but the session state would not be 'CLOSE' unless a proper teardown occurred. Option D is wrong because packet buffer exhaustion causes random drops or session setup failures, not a specific 'CLOSE' state; the firewall would likely show session states like 'INIT' or 'ACTIVE' with drops, not a clean teardown.

142
Multi-Selectmedium

An administrator is preparing a PA-3220 running PAN-OS 11.0 for a maintenance window and wants to capture the current operational state so it can be compared after the window. Which two actions should the administrator take to preserve this state for later comparison? (Choose two.)

Select 2 answers
A.Delete the oldest log segments to free space so new logs are not lost during the window.
B.Generate a Tech Support File from the device to capture logs, configuration, and system state in one archive.
C.Export a named configuration snapshot so the current committed configuration can be restored or diffed later.
D.Change the management interface IP address so the device is reachable from a different subnet after the window.
E.Run the request system reboot command to flush volatile state so the snapshot is clean.
AnswersB, C

The Tech Support File bundles the running configuration, logs, and diagnostic output into a single archive. It is designed exactly for capturing a device's state at a point in time so it can be reviewed or compared later, which fits the goal of preserving the pre-maintenance state for post-window comparison.

Why this answer

Preserving state before maintenance involves capturing both configuration and diagnostics. A named configuration snapshot saves the committed configuration for later diff or rollback, while a Tech Support File archives configuration, logs, and system diagnostics in one artifact. Rebooting, deleting logs, and changing the management address all alter the device rather than preserve its state.

Exam trap

The trap here is treating a reboot or log cleanup as preparation, when both destroy the very state the administrator intends to preserve for comparison.

143
MCQmedium

A security administrator needs to ensure that the firewall sends an email notification to the security team whenever a critical threat is detected. The email server is reachable at 10.10.10.5, and the firewall's management interface is in the 10.10.10.0/24 subnet. Which configuration step is required to enable email notifications for critical threats?

A.Configure a Syslog server profile under Device > Server Profiles > Syslog and set the severity level to critical.
B.Configure an Email server profile under Device > Server Profiles > Email and then attach it to a Log Forwarding profile used in the security policy.
C.Configure a Log Forwarding profile under Objects > Log Forwarding and enable email notifications directly in the profile.
D.Configure an SNMP trap destination under Device > Server Profiles > SNMP and enable traps for critical threats.
AnswerB

To send email notifications for threats, you must create an Email server profile with the SMTP server details and then reference it in a Log Forwarding profile. The Log Forwarding profile is then applied to the security policy that matches the traffic. This is the standard method for email alerting on critical threats.

Why this answer

The correct approach is to create an Email server profile that defines the SMTP server, and then reference that profile within a Log Forwarding profile. The Log Forwarding profile is then attached to the security policy that logs the critical threats. This ensures that when a threat is detected, an email is sent.

Other options involve different server types that do not provide email functionality.

Exam trap

The trap here is assuming that Log Forwarding profiles can directly send email without an Email server profile.

144
Multi-Selectmedium

A security administrator is designing a zero trust architecture using Palo Alto Networks Next-Generation Firewalls. They need to ensure that all traffic between the internal network and the internet is inspected, and that users are identified regardless of location. Which two components are required to achieve user identification for both on-premises and remote users? (Choose two.)

Select 2 answers
A.Captive Portal to authenticate users who are not covered by other User-ID methods.
B.User-ID Agent to monitor directory servers and map IP addresses to usernames for on-premises users.
C.Syslog forwarding to send user mapping logs to an external server.
D.XML API to query the firewall for user mapping information.
E.GlobalProtect to authenticate remote users and map their IP addresses to usernames.
AnswersB, E

The User-ID Agent connects to directory servers such as Active Directory to retrieve user-to-IP mappings for on-premises users. This is essential for identifying users on the internal network, as it provides the mapping that the firewall uses in security policies to enforce user-based rules.

Why this answer

To identify users both on-premises and remotely, the administrator needs GlobalProtect for remote users and a User-ID Agent for on-premises users. GlobalProtect authenticates remote users and provides IP-to-username mapping, while the User-ID Agent monitors directory servers to map IP addresses to usernames for internal users. Together, they enable consistent user-based policy enforcement across locations.

Exam trap

The trap here is thinking that a single component can handle all user identification, when in fact different methods are needed for on-premises and remote users.

145
MCQhard

During a security audit, it is discovered that some HTTP traffic is being incorrectly identified as 'web-browsing' instead of 'ssl' even though the traffic uses HTTPS. The firewall is positioned as a transparent bridge and no SSL decryption is configured. What is the most likely cause?

A.SSL decryption must be enabled for the firewall to correctly identify SSL traffic.
B.The firewall is not seeing the full SSL handshake due to asymmetric routing.
C.The default interzone rule is blocking the SSL identification packets.
D.The security policy allows 'web-browsing' before 'ssl' in the rule order.
AnswerB

A transparent bridge without decryption must infer the application from the TLS handshake. With asymmetric routing, return traffic bypasses the firewall, so it never observes the full handshake and falls back to classifying the flow as web-browsing on port 443 instead of ssl.

Why this answer

When a firewall operates as a transparent bridge without SSL decryption, it relies on the Server Name Indication (SNI) field or the certificate exchange during the TLS handshake to identify HTTPS traffic as 'ssl'. Asymmetric routing causes the firewall to see only one direction of the TCP handshake (e.g., only the SYN or only the SYN-ACK), preventing it from observing the full TLS handshake. Without the complete handshake, App-ID cannot extract the necessary signatures (e.g., TLS version, cipher suites, certificate details) and falls back to classifying the traffic as 'web-browsing' based on port 443.

Exam trap

The trap here is that candidates assume SSL decryption is mandatory for SSL identification, but the firewall can identify HTTPS without decryption by inspecting the TLS handshake; the real issue is that asymmetric routing prevents the firewall from seeing the complete handshake, causing App-ID to fall back to port-based classification.

How to eliminate wrong answers

Option A is wrong because SSL decryption is not required for App-ID to identify SSL traffic; the firewall can identify HTTPS by inspecting the TLS handshake metadata (e.g., SNI, certificate) without decrypting the payload. Option C is wrong because interzone rules control traffic flow between zones, not the identification process; App-ID operates before policy enforcement, so a default interzone rule would not prevent the firewall from seeing the SSL handshake packets. Option D is wrong because security policy rule order affects which action is taken on traffic, not how App-ID classifies it; App-ID identifies the application first, then matches it against the policy, so rule order does not cause misidentification.

146
MCQhard

A network security engineer is troubleshooting why a user's session to a SaaS application is being decrypted by SSL Forward Proxy but then immediately reset. The engineer checks the session details and sees the session end reason as 'tcp-rst-from-server'. Packet capture on the firewall shows that the server is sending a TCP RST after the client sends a TLS Client Hello. The firewall's decryption profile is configured to block sessions with untrusted issuers. What is the most likely cause of the reset?

A.The server is rejecting the connection because the SNI in the Client Hello does not match the server's expected hostname, or the server requires mutual TLS authentication.
B.The firewall's forward trust certificate is not trusted by the client, causing the client to reset the connection.
C.The server is using a self-signed certificate that is not trusted by the firewall's forward trust certificate.
D.The server is configured to require TLS 1.3, but the firewall's decryption profile is set to only allow TLS 1.2, causing the server to reset the connection.
AnswerA

When SSL Forward Proxy decrypts traffic, it generates a new Client Hello to the server. If the server expects a specific SNI that matches its certificate, or if it requires client certificate authentication (mutual TLS), the server may reject the connection with a TCP RST. This is a common issue when decryption interferes with server-side validation. The session end reason 'tcp-rst-from-server' confirms the server initiated the reset.

Why this answer

The correct answer is that the server is rejecting the connection due to SNI mismatch or mutual TLS requirements. When SSL Forward Proxy decrypts, it acts as a man-in-the-middle, and the server may see a different SNI or lack a client certificate, causing it to reset the connection. This is consistent with the observed 'tcp-rst-from-server' and the server sending a RST after receiving the Client Hello.

Exam trap

The trap here is assuming that any reset during SSL decryption is caused by certificate trust issues on the client or firewall side, when in fact the server may be rejecting the connection due to decryption-induced changes in the TLS handshake.

147
MCQeasy

A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?

A.Block sessions with expired certificates under SSL Forward Proxy settings.
B.Block sessions with unknown certificate status under SSL Forward Proxy settings.
C.Block sessions with untrusted issuers under SSL Forward Proxy settings.
D.Block sessions with client authentication failures under SSL Forward Proxy settings.
AnswerA

The decryption profile includes an option to block sessions when the server certificate is expired. Enabling this setting causes the firewall to drop the connection if the server's certificate has expired, preventing users from accessing potentially insecure sites. This directly addresses the requirement to block expired certificates.

Why this answer

Within a decryption profile, the SSL Forward Proxy settings include an option to block sessions when the server certificate is expired. Enabling this ensures that the firewall checks the validity period of the server's certificate and drops the connection if it has expired. This is the correct setting to meet the requirement.

Exam trap

The trap here is confusing certificate expiration with other certificate validation checks like untrusted issuer or unknown status; each has a separate setting in the decryption profile.

148
Drag & Dropmedium

Arrange the steps to enable and configure GlobalProtect on a Palo Alto Networks firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for enabling and configuring GlobalProtect on a Palo Alto Networks firewall starts with configuring the portal, which handles authentication and client settings. Next, the gateway is configured to manage VPN connections. Then, the GlobalProtect agent (client configuration) is set up to push settings to endpoints.

Finally, security policies are applied to allow GlobalProtect traffic. Following this order ensures dependencies are satisfied and reduces configuration errors.

149
MCQmedium

An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?

A.show counter global | match ipsec
B.show log system
C.debug ike global on
D.debug flow basic
AnswerC

With no IPsec SAs present, the failure lies in Phase 1, so IKE negotiation must be examined. The 'debug ike global on' command enables global IKE daemon debugging, exposing payload exchanges, proposal mismatches and authentication failures that explain why the tunnel never reaches quick mode. This targets the negotiation stage the stem identifies as failing.

Why this answer

'debug ike global on' enables detailed IKE (Internet Key Exchange) debugging on Palo Alto firewalls, capturing Phase 1 and Phase 2 negotiation messages, including proposal mismatches, authentication failures, and timeout errors. Since no IPsec SAs exist, the issue lies in IKE negotiation, and this command provides the most granular, real-time output to diagnose why the tunnel fails to establish.

Exam trap

The trap here is that candidates often confuse 'debug flow basic' (data-plane) with IKE debugging (control-plane), or assume 'show counter global' will reveal negotiation failures, when in fact counters only track post-establishment statistics and not the IKE handshake itself.

How to eliminate wrong answers

Option A is wrong because 'show counter global | match ipsec' displays aggregate IPsec packet counters (e.g., encaps/decaps, drops) but does not provide IKE negotiation details; it is useful for post-establishment traffic issues, not for debugging why SAs are missing. Option B is wrong because 'show log system' shows system-level events (e.g., admin logins, config changes) but does not capture IKE-specific debug messages; it lacks the granularity needed for protocol-level negotiation failures. Option D is wrong because 'debug flow basic' is used for debugging data-plane packet flow (e.g., session setup, NAT, routing) and does not cover IKE control-plane negotiation; it would not reveal why IKE Phase 1 or Phase 2 fails.

150
MCQmedium

A network security engineer is configuring a route-based IPsec VPN between two Palo Alto Networks firewalls. The engineer needs to ensure that the tunnel interface is used for dynamic routing updates and that the VPN can fail over to a backup path if the primary path goes down. Which configuration is required to achieve this?

A.Use policy-based VPN with proxy IDs and configure multiple proxy IDs for redundancy.
B.Enable IKEv2 and configure a separate tunnel interface for each path, then use OSPF with equal-cost multipath.
C.Configure a tunnel interface, assign it to a zone, and enable tunnel monitoring with a destination IP address.
D.Enable IKEv1 with aggressive mode and configure multiple pre-shared keys for each path.
AnswerC

A tunnel interface is required for route-based VPN, and assigning it to a zone allows policy enforcement. Tunnel monitoring sends ICMP probes to a specified IP address; if probes fail, the tunnel is considered down, triggering failover via routing changes. This directly addresses the need for dynamic routing and failover.

Why this answer

A route-based VPN requires a tunnel interface to participate in dynamic routing. Tunnel monitoring detects when the primary path fails, allowing routing protocols to withdraw routes and use a backup path. This combination ensures both dynamic routing and failover, which are essential for the described requirements.

Exam trap

The trap here is assuming that dynamic routing protocols alone provide failover without tunnel monitoring, but they need a trigger to detect path failure.

Page 1

Page 2 of 5

Page 3

All pages