Courseiva

Palo Alto Networks Certified Network Security Engineer PCNSE (PCNSE) — Questions 151–225

319 questions total · 5pages · All types, answers revealed

Page 2

Page 3 of 5

Page 4
151
MCQmedium

A company has an application signature for an internal ERP system that uses a proprietary protocol over TCP port 4444. The ERP traffic is sometimes misidentified as unknown-tcp. Which App-ID mechanism should be used to improve identification without affecting the default App-ID engine?

A.Configure a port-based application override for port 4444.
B.Enable SSL decryption for the ERP traffic.
C.Create a custom application with a data pattern (signature).
D.Create an application override to allow the traffic without App-ID.
AnswerC

A custom application with a data pattern matches the proprietary protocol's payload signature on port 4444, giving deterministic identification. This adds a signature without altering the predefined App-ID engine, satisfying the constraint of not affecting default identification.

Why this answer

Creating a custom application with a data pattern (signature) allows the firewall to identify the ERP traffic based on its unique payload characteristics, without overriding or disabling the default App-ID engine. This approach uses a custom App-ID signature that matches the proprietary protocol's data pattern, ensuring accurate identification while the default engine continues to process other traffic normally.

Exam trap

The trap here is that candidates confuse 'application override' (which bypasses App-ID) with 'custom application signature' (which enhances App-ID), leading them to choose options that disable inspection rather than improve it.

How to eliminate wrong answers

Option A is wrong because a port-based application override statically maps all traffic on TCP 4444 to a specific application, which bypasses the default App-ID engine entirely and prevents it from learning or updating signatures for that port. Option B is wrong because SSL decryption is irrelevant for a proprietary protocol over TCP that does not use SSL/TLS encryption; it would not help identify the application and could introduce unnecessary overhead. Option D is wrong because an application override allows traffic without any App-ID inspection, which defeats the purpose of improving identification and can permit unwanted or malicious traffic to pass unchecked.

152
MCQhard

An engineer is troubleshooting an HA pair where the passive firewall is not synchronizing sessions. The HA1 link is up and the HA state is 'passive'. The engineer notices that the HA2 link is up, but session synchronization is still not working. Which action should the engineer take next?

A.Verify that the 'Session Synchronization' option is enabled in the HA configuration.
B.Configure the HA2 link to use the management interface to simplify cabling.
C.Ensure that the HA1 link is encrypted with a pre-shared key.
D.Check that the HA2 link is configured with the same IP addresses on both firewalls.
AnswerA

Session synchronization must be explicitly enabled in the HA configuration for the passive firewall to receive session updates. If disabled, no sessions will sync regardless of HA2 link status. This setting is found under Device > High Availability > General > Session Synchronization. Enabling it allows the active firewall to replicate sessions to the passive peer. Without it, the passive firewall will not have current session information.

Why this answer

Session synchronization requires the 'Session Synchronization' option to be enabled. Even if the HA2 link is up, if this setting is disabled, no sessions will be synchronized. The engineer should verify this setting first.

This is a common oversight when configuring HA. Once enabled, the active firewall will begin replicating sessions to the passive peer.

Exam trap

The trap here is assuming that a functional HA2 link is sufficient for session sync, when the 'Session Synchronization' option must also be enabled.

153
MCQhard

A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?

A.The tunnel interface is not configured with an IP address.
B.The IKE Gateway is configured with the wrong local interface.
C.The IKE Gateway configuration does not have the pre-shared key configured.
D.The IPsec Crypto profile is missing an encryption algorithm.
AnswerC

In a site-to-site VPN using pre-shared key authentication, the IKE Gateway must have the pre-shared key defined under the IKE Gateway configuration. Without it, the firewall cannot authenticate the peer during IKE Phase 1, and the tunnel will fail to establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not provide authentication credentials.

Why this answer

For a site-to-site VPN using pre-shared key authentication, the IKE Gateway must include the pre-shared key. Without it, IKE Phase 1 cannot authenticate the peer, and the tunnel will not establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not handle authentication.

Therefore, the missing pre-shared key is the most likely cause of the failure.

Exam trap

The trap here is assuming that configuring the IKE Crypto profile alone is sufficient for Phase 1, forgetting that authentication credentials like the pre-shared key must be explicitly set in the IKE Gateway.

154
MCQmedium

Refer to the exhibit. Which SSL protocol version is blocked as per this decryption profile?

A.TLS 1.1
B.TLS 1.0
C.TLS 1.3
D.TLS 1.2
AnswerA

The profile explicitly blocks TLS 1.1.

Why this answer

The decryption profile in the exhibit shows 'TLS 1.1' explicitly selected under 'Block SSL/TLS Versions,' meaning any session attempting to negotiate TLS 1.1 will be blocked. This is a direct configuration setting in Palo Alto Networks firewalls where you can selectively block specific SSL/TLS protocol versions to enforce stronger cryptographic standards.

Exam trap

Palo Alto Networks often tests the ability to read the exhibit carefully—candidates may assume that because TLS 1.1 is a deprecated protocol, the question is about which version is allowed, or they might confuse the 'Block' list with the 'Allow' list, leading them to pick TLS 1.0 or TLS 1.2 as the blocked version.

How to eliminate wrong answers

Option B is wrong because TLS 1.0 is not selected in the exhibit; only TLS 1.1 is checked, so TLS 1.0 remains allowed unless explicitly blocked. Option C is wrong because TLS 1.3 is not listed in the block options (the exhibit only shows TLS 1.0, 1.1, and 1.2), and it is not selected. Option D is wrong because TLS 1.2 is not checked in the exhibit; it is allowed by default unless explicitly blocked.

155
MCQeasy

Refer to the exhibit. A network engineer sees multiple IKE SAs for the same peer. What does this indicate?

A.A configuration error causes duplicate SAs.
B.Multiple Phase 2 tunnels are established.
C.Multiple Phase 1 proposals are accepted.
D.The firewall is under DDoS attack.
AnswerA

Correct. Multiple IKE SAs for the same peer indicate a configuration error, such as duplicate IKE gateways. When two or more IKE gateways are configured with identical peer IP settings, each gateway establishes its own IKE SA, resulting in multiple SAs.

Why this answer

In Palo Alto firewalls, each IKE gateway configuration establishes a separate IKE SA. If multiple IKE gateways are configured with the same peer IP address (e.g., duplicated or misconfigured gateways), multiple IKE SAs will appear for that peer. This typically indicates a configuration error rather than an intentional design, as each peer should usually have a single IKE gateway.

Multiple Phase 2 tunnels under the same IKE gateway do not create additional IKE SAs; they only create additional Phase 2 SAs within the same IKE SA. Therefore, multiple IKE SAs for the same peer point to duplicate or erroneous IKE gateway configurations.

Exam trap

A common misconception is that multiple IKE SAs for the same peer always indicate multiple Phase 2 tunnels. In reality, Phase 2 tunnels do not create extra IKE SAs. Instead, multiple IKE SAs are caused by multiple IKE gateway configurations for the same peer, which is often a configuration error.

How to eliminate wrong answers

Option A is wrong because duplicate IKE SAs are not a configuration error; they are a normal result of multiple Phase 2 tunnels. Option C is wrong because multiple Phase 1 proposals are negotiated during a single IKE SA establishment, not resulting in separate IKE SAs; only one proposal is selected per IKE SA. Option D is wrong because a DDoS attack would typically cause a flood of half-open or invalid SAs, not multiple established IKE SAs for the same peer with valid Phase 2 tunnels.

156
MCQeasy

What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?

A.Mask the original source IP address for privacy.
B.Inspect encrypted traffic for malware, exploits, and data leakage.
C.Allow only inbound SSL traffic to be inspected.
D.Improve network performance by reducing encryption overhead.
AnswerB

SSL decryption terminates encrypted sessions so App-ID, Content-ID threat prevention, URL filtering and file blocking can examine the plaintext payload. Without it, malware, exploits and data exfiltration hidden inside TLS remain invisible to the security policy.

Why this answer

SSL decryption in a Palo Alto Networks firewall is primarily used to inspect encrypted traffic (HTTPS, SMTPS, etc.) for threats such as malware, exploits, and data leakage. Without decryption, the firewall cannot apply threat prevention, URL filtering, or data filtering policies to the encrypted payload, leaving a blind spot in security enforcement.

Exam trap

The trap here is that candidates often confuse SSL decryption with performance optimization or privacy features, but the PCNSE exam emphasizes that its core purpose is to enable visibility and inspection of encrypted traffic for threat detection.

How to eliminate wrong answers

Option A is wrong because masking the original source IP address is the function of source NAT (SNAT) or privacy features like Private IP masking, not SSL decryption. Option C is wrong because SSL decryption can inspect both inbound and outbound traffic; it is not limited to inbound SSL traffic only. Option D is wrong because SSL decryption actually adds processing overhead due to the decryption/re-encryption cycle, it does not improve network performance or reduce encryption overhead.

157
MCQeasy

A security engineer is configuring HA on a pair of Palo Alto Networks firewalls. The engineer wants to ensure that the HA1 control link is highly available. Which configuration should the engineer use for the HA1 link?

A.Use a dedicated physical interface connected to a switch with redundant paths.
B.Use an HA1 backup link in addition to the primary HA1 link.
C.Use an IP-bridged HA1 link over a dedicated physical interface.
D.Use a dedicated physical interface with a direct cable between the firewalls.
AnswerB

Configuring an HA1 backup link provides redundancy for the control link. If the primary HA1 link fails, the backup link takes over, ensuring continuous HA communication. This is the recommended best practice for high availability of the HA1 control link.

Why this answer

The HA1 control link is critical for HA communication. To ensure high availability, a backup HA1 link should be configured. This allows the firewalls to maintain HA state synchronization even if the primary HA1 link fails.

Other options may provide a working link but do not offer redundancy for the link itself.

Exam trap

The trap here is assuming that a direct cable or a switched connection is sufficient for high availability, when in fact a backup link is needed.

158
MCQeasy

A company needs to provide internet access to 500 internal users using a single public IP address. Which NAT method should be configured?

A.Dynamic NAT (1:1 pool)
B.Static NAT (1:1)
C.Destination NAT
D.Source NAT with IP and port translation (PAT)
AnswerD

Source NAT with port translation multiplexes 500 internal sessions onto one public address by rewriting source ports, so each flow is uniquely identified in the translation table. This satisfies the stem's single-public-IP constraint, which static or dynamic IP-only NAT cannot, since those require one public address per internal host.

Why this answer

Source NAT with IP and port translation (PAT) allows 500 internal users to share a single public IP address by translating each private source IP:port combination to the public IP with a unique source port. This conserves public IPv4 addresses and is the standard method for large-scale internet access from a private network.

Exam trap

The trap here is that candidates confuse Dynamic NAT (which still requires a pool of public IPs) with PAT, assuming any 'dynamic' method can share a single IP, but only PAT performs port-level multiplexing to achieve this.

How to eliminate wrong answers

Option A is wrong because Dynamic NAT (1:1 pool) maps each internal IP to a unique public IP from a pool, requiring at least 500 public IPs, not a single one. Option B is wrong because Static NAT (1:1) provides a fixed one-to-one mapping between a private IP and a public IP, which also requires a public IP per user and does not scale. Option C is wrong because Destination NAT translates the destination IP/port of inbound traffic, not the source address of outbound traffic, and thus cannot provide internet access for internal users.

159
MCQeasy

A network security administrator is configuring a new Palo Alto Networks firewall and wants to ensure that traffic between two internal subnets is inspected by the firewall. The subnets are on different interfaces. What must be configured to allow the firewall to inspect this traffic?

A.A Policy-Based Forwarding (PBF) rule to redirect the traffic to the firewall.
B.A NAT policy rule translating the source IP addresses.
C.A Security policy rule allowing traffic from the source zone to the destination zone.
D.A decryption policy rule to decrypt the traffic.
AnswerC

For the firewall to inspect and allow traffic between two interfaces, a Security policy rule must permit the traffic from the source zone to the destination zone. Without such a rule, the default interzone deny rule will block the traffic. The rule should also specify the correct applications and services to match the traffic, ensuring that the firewall performs the necessary inspection.

Why this answer

To allow and inspect traffic between two internal subnets on different interfaces, the administrator must create a Security policy rule that permits traffic from the source zone to the destination zone. This rule enables the firewall to perform security inspections such as application identification, threat prevention, and content filtering. Other policies like NAT, PBF, or decryption are not required for basic traffic flow and do not replace the need for a Security policy rule.

Exam trap

The trap here is confusing NAT or PBF with security policy; NAT translates addresses and PBF changes forwarding, but neither permits traffic.

160
MCQeasy

Which Panorama deployment mode allows centralized management of firewalls while storing logs locally on each firewall instead of sending them to the Panorama log collector?

A.Panorama with Dedicated Log Collectors
B.Panorama with Log Collectors
C.Panorama without Log Collectors
D.Panorama in High Availability mode
AnswerC

Panorama deployed without Log Collectors manages policies and device configuration centrally while each managed firewall retains its own logs in local storage. This satisfies the stem's requirement that logs stay on the firewall rather than being forwarded to Panorama.

Why this answer

Panorama without Log Collectors is the correct deployment mode because it allows centralized management of firewalls while keeping logs stored locally on each firewall. In this mode, Panorama handles only configuration and policy management, and log collection is disabled, so no logs are forwarded to Panorama. This is ideal for environments where log retention must remain on the firewall due to compliance or bandwidth constraints.

Exam trap

The trap here is that candidates often assume Panorama always requires log forwarding for centralized management, confusing the management plane (configuration/policy) with the data plane (logging), and thus overlook the 'without Log Collectors' mode as a valid deployment option.

How to eliminate wrong answers

Option A is wrong because Panorama with Dedicated Log Collectors requires logs to be sent from firewalls to dedicated collector hardware, not stored locally. Option B is wrong because Panorama with Log Collectors (using the built-in collector on the Panorama appliance) also forwards logs from firewalls to Panorama, not local storage. Option D is wrong because Panorama in High Availability mode is a redundancy configuration that can be used with or without log collectors, and does not inherently change where logs are stored; logs are still sent to Panorama if collectors are configured.

161
MCQhard

An HA pair is deployed with Active/Active mode. During a traffic spike, session table utilization reaches 90% on both firewalls. The engineer notices asymmetric routing and drops. What should be configured to optimize session distribution?

A.Change the HA mode to Active/Passive
B.Adjust the session distribution algorithm to match traffic patterns
C.Increase the HA2 link bandwidth using link aggregation
D.Enable session synchronization for all sessions
AnswerB

Proper distribution reduces asymmetric routing.

Why this answer

In an Active/Active HA pair, session distribution is controlled by a hash-based algorithm that determines which firewall handles a given flow. When asymmetric routing and drops occur during high session utilization, the default algorithm may not distribute traffic evenly, causing one firewall to become overloaded. Adjusting the session distribution algorithm (e.g., from IP hash to round-robin or a weighted distribution) can better match the traffic patterns and balance the load, reducing asymmetry and drops.

Exam trap

The trap here is that candidates often assume increasing HA2 bandwidth or enabling session synchronization will fix load imbalance, but these address sync throughput, not the root cause of uneven session distribution.

How to eliminate wrong answers

Option A is wrong because changing to Active/Passive would eliminate the load-sharing benefit of Active/Active, leaving one firewall idle and potentially still causing drops on the active unit during a traffic spike. Option C is wrong because increasing HA2 link bandwidth (used for session synchronization and state propagation) does not affect how sessions are initially distributed; it only improves the throughput of sync traffic, not the load-balancing algorithm. Option D is wrong because session synchronization is already enabled by default in Active/Active mode to maintain state; enabling it for all sessions does not change the distribution algorithm and will not optimize how sessions are assigned to firewalls.

162
MCQeasy

A network engineer needs to verify that a specific security rule is being hit by traffic. Which firewall log should be examined?

A.Configuration log
B.Traffic log
C.Threat log
D.System log
AnswerB

The traffic log records every session matched against security policy, including the rule name that permitted or denied it. Examining it confirms whether the specific security rule is being hit, directly satisfying the requirement to verify rule utilisation. Other logs, such as threat or URL filtering, only capture events after a rule already matched.

Why this answer

The Traffic log records every session that matches a security rule, including the rule ID, source/destination IPs, ports, and action (allow/deny). To verify that a specific security rule is being hit, you must examine the Traffic log, as it shows which rule processed each session. Configuration, Threat, and System logs do not contain per-session rule match data.

Exam trap

The trap here is that candidates confuse the Traffic log with the Threat log, thinking that only malicious traffic generates logs, but the Traffic log records all allowed and denied sessions regardless of threat status.

How to eliminate wrong answers

Option A is wrong because the Configuration log records administrative changes to the firewall (e.g., rule modifications, commits), not traffic matching events. Option C is wrong because the Threat log captures intrusion prevention, antivirus, or vulnerability exploits, not standard rule hits. Option D is wrong because the System log contains system-level events (e.g., HA state changes, disk errors, license expiry), not per-session rule match information.

163
MCQmedium

An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?

A.Users are manually selecting the wrong gateway from the client.
B.The gateways are not configured with priority settings.
C.The gateway selection rules on the portal do not match the users' source IP ranges.
D.The DNS resolution for the portal returns multiple IPs in round-robin.
AnswerC

Gateway selection rules on the portal map source IP ranges to preferred gateways, so mismatched ranges send Asian users to the wrong region. The portal agent config evaluates these rules before the client connects, making the source-IP match the deciding factor here.

Why this answer

GlobalProtect gateway selection is primarily determined by the gateway selection rules configured on the portal. These rules evaluate the user's source IP address against defined IP ranges (or countries) to assign the appropriate gateway. If the rules do not match the users' source IP ranges in the Asia region, the portal will either fail to assign a gateway or assign a default gateway, causing users to connect to the wrong gateway.

Exam trap

The trap here is that candidates often confuse gateway priority (which controls load balancing within a region) with gateway selection rules (which control which region's gateway a user connects to), leading them to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because while manual selection is possible, the scenario describes users 'connecting to the wrong gateway,' which implies an automated selection failure, not user error; manual selection would require deliberate action and is not the 'most likely cause' in a multi-region deployment. Option B is wrong because priority settings on gateways control load balancing and failover order among gateways within the same region, not which region a user connects to; gateway selection is based on portal rules, not gateway priority. Option D is wrong because DNS round-robin for the portal would distribute users across multiple portal IPs, but the portal itself still enforces gateway selection rules; this would not cause users to connect to the wrong gateway unless the portal configuration is incorrect.

164
Multi-Selectmedium

Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?

Select 3 answers
A.Verify the routing table on both firewalls.
B.Check the firewall policies for the tunnel zone.
C.Increase the IPSec SA lifetime.
D.Verify the proxy IDs on both peers match.
E.Ensure the tunnel interface is placed in a virtual router.
AnswersA, B, D

A tunnel can be up while traffic fails because no route directs packets into the VPN. Verifying the routing table on both firewalls confirms that remote subnet routes point to the tunnel interface, satisfying the stem's requirement.

Why this answer

Option A is correct because when a site-to-site VPN tunnel is up but traffic does not pass, the most common cause is a missing or incorrect route on one or both firewalls; verifying the routing table ensures that traffic destined for the remote subnet is directed into the tunnel interface rather than out a default or wrong interface. Option B is correct because firewall policies (security rules) must explicitly permit traffic between the local and remote tunnel zones; even with a healthy IPSec SA, an implicit deny or missing allow rule for the tunnel zone will silently drop packets. Option D is correct because proxy IDs (traffic selectors) define which source/destination subnets are permitted through the tunnel, and if the local and remote peers have mismatched proxy IDs, Phase 2 may appear up while traffic for the actual subnets is dropped or not encrypted.

Option C is not correct because increasing the IPSec SA lifetime only affects how often keys are renegotiated and does not resolve a no-traffic condition when the tunnel is already established. Option E is not correct because placing the tunnel interface in a virtual router is a design/configuration choice, not a troubleshooting step, and a tunnel can pass traffic without being bound to a virtual router.

Exam trap

The trap here is that candidates assume a tunnel being 'up' guarantees traffic flow, but the PCNSE exam tests that you must separately verify routing, security policies, and proxy IDs—each of which can block traffic independently of the tunnel's control-plane state.

165
Matchingmedium

Match each security profile type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Detects and blocks malware in traffic

Prevents spyware and command-and-control traffic

Blocks exploits targeting known vulnerabilities

Controls access to websites based on category

Blocks specific file types from being transferred

Why these pairings

The correct matches are: Antivirus scans for malware, Anti-Spyware protects against spyware, Vulnerability Protection prevents exploitation. URL Filtering categorizes URLs, and File Blocking blocks file types. Options D and E swap these definitions.

166
MCQhard

A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?

A.Configure a security policy rule with application 'ssl' and attach the URL filtering profile.
B.Enable SSL decryption for the trust zone and apply a decryption policy for HTTPS traffic.
C.Enable 'HTTP Header Logging' in the URL filtering profile and commit.
D.Create a custom URL category with the malware sites and apply it to a security policy rule.
AnswerB

URL filtering for HTTPS requires visibility into the full URL, which is encrypted. SSL decryption (forward proxy or inbound inspection) is necessary to decrypt the traffic so the firewall can inspect the HTTP Host header and path. Without decryption, the firewall can only use the SNI or certificate CN, which may not provide the full URL. Therefore, enabling SSL decryption with a decryption policy is required.

Why this answer

To filter HTTPS based on the full URL, the firewall must decrypt the traffic to inspect the HTTP Host header and path. SSL decryption, configured via a decryption policy, allows the firewall to act as a forward proxy. Without decryption, URL filtering for HTTPS is limited to server name indication or certificate information, which may not cover the full URL.

Therefore, enabling SSL decryption is the necessary step.

Exam trap

The trap here is believing that attaching a URL filtering profile to a security rule that allows SSL traffic is sufficient for HTTPS URL filtering, when decryption is actually required.

167
MCQhard

Refer to the exhibit. What happens when a user with an unknown identity (source-user unknown) tries to access resources in 192.168.1.0/24?

A.The traffic is blocked because the source-user is 'unknown'.
B.The traffic is allowed without authentication because the source-user is 'unknown'.
C.The user is prompted to authenticate via the configured authentication profile.
D.The user is redirected to the captive portal.
AnswerC

Unknown source users trigger the configured authentication profile, forcing a Captive Portal or authentication challenge before access to 192.168.1.0/24 is granted. This satisfies the security policy's requirement to identify unrecognised traffic, since the rule matches unknown source-user and applies the profile rather than silently permitting or dropping the session.

Why this answer

When a user with an unknown identity (source-user unknown) attempts to access resources in 192.168.1.0/24 and the policy rule action is 'allow-authentication', the firewall prompts the user to authenticate via the configured authentication profile. Option A is incorrect because the action is not 'deny', so traffic is not blocked solely due to unknown source-user. Option B is incorrect because the traffic is not allowed without authentication; the 'allow-authentication' action requires successful authentication.

Option D is incorrect because the action is specifically 'allow-authentication' which triggers an authentication prompt using the configured method (which may be captive portal, but the term 'redirect to captive portal' is less precise than 'prompted to authenticate').

168
MCQmedium

An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?

A.Add an external disk to the firewall
B.Configure log export and auto-deletion in Log Settings
C.Disable logging for non-critical traffic
D.Manually delete logs from the CLI
AnswerB

Log Settings controls log storage behaviour, including export to external servers and automatic deletion of older logs once thresholds are reached. Enabling auto-deletion directly reduces disk consumption, satisfying the requirement to reclaim space without manual intervention.

Why this answer

The firewall's log settings allow administrators to configure automatic log export and auto-deletion policies. By enabling log export to an external server (e.g., syslog) and setting a retention period or disk usage threshold, the firewall will automatically purge older log files when disk usage reaches a specified limit, such as 85%. This directly addresses the need to reduce disk usage without manual intervention or disabling logging.

Exam trap

The trap here is that candidates may confuse 'adding external storage' (Option A) as a solution for disk usage, but the question specifically asks for automatic deletion of older logs, not just expanding capacity.

How to eliminate wrong answers

Option A is wrong because adding an external disk does not automatically delete older logs; it only provides additional storage, which may delay but not solve the underlying issue of log growth. Option C is wrong because disabling logging for non-critical traffic reduces visibility and is not a targeted method for managing disk usage; it also violates best practices for security monitoring. Option D is wrong because manually deleting logs from the CLI is a reactive, non-automated approach that requires ongoing administrative effort and does not provide a sustainable solution for automatic log rotation.

169
Multi-Selecthard

Which TWO troubleshooting steps are most effective when an HA pair is not synchronizing sessions between peers? (Assume HA1 and HA2 are up.)

Select 2 answers
A.Ensure session synchronization is enabled on both firewalls under Device > High Availability > Setup
B.Check HA1 link utilization
C.Increase the packet buffer protection threshold
D.Review the session synchronization configuration for mismatched parameters (e.g., encryption, timeout)
E.Restart the HA process on both firewalls
AnswersA, D

Session synchronisation is a per-firewall setting, so it must be enabled on both peers for sessions to replicate. With HA1 and HA2 confirmed up, checking this toggle under Device > High Availability > Setup rules out the simplest cause of missing synchronisation.

Why this answer

Option A is correct because session synchronization must be explicitly enabled in Device > High Availability > Setup on both peers; if the checkbox is cleared on either firewall, sessions will not replicate even though HA1/HA2 heartbeats are up. Option D is correct because the session synchronization settings (e.g., sync encryption, session timeout, and related parameters) must match on both peers; a mismatch such as encryption enabled on one side but not the other silently prevents session state from being exchanged. Options B, C, and E are not the most effective steps: HA1 utilization affects heartbeat/control traffic rather than session sync (which normally uses HA2), packet buffer protection is unrelated to session replication, and restarting the HA process is a disruptive action that does not address configuration causes of sync failure.

Exam trap

PCNSE often tests the assumption that HA link 'up' status means synchronization is working, when in fact session sync can be disabled or misconfigured independently of link state.

170
MCQeasy

An administrator needs to ensure that the firewall sends an alert to an external server whenever a critical threat is detected, and also wants to receive a daily summary of blocked traffic. Which two log forwarding destinations should be configured to satisfy both requirements?

A.Configure an SNMP trap server profile for the daily summary and an email profile for the critical threat alerts.
B.Configure a syslog server profile for the critical threat alerts and a scheduled report for the daily summary.
C.Configure a syslog server profile for the daily summary and an email profile for the critical threat alerts.
D.Configure an email profile for the critical threat alerts and a scheduled report for the daily summary.
AnswerD

Email profiles attached to a log forwarding profile can trigger notifications when matching threat logs are generated, satisfying the immediate alert requirement. Scheduled reports can be configured to run daily and include data such as blocked traffic, satisfying the summary requirement. Together they map directly to both needs.

Why this answer

Critical threat alerts are event-driven and are best delivered through an email profile referenced by a log forwarding profile, which fires when a matching log is generated. A recurring summary of blocked traffic is a scheduled reporting task, produced by a report configured to run daily. Syslog streams raw events and does not produce summaries, and SNMP traps target device-level events rather than log content.

Exam trap

The trap here is confusing raw log streaming over syslog with an alerting mechanism, when a targeted notification requires a log forwarding profile with an email action.

171
MCQhard

The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?

A.The 'interface-address' option requires a specific translated address.
B.The rule is missing a 'from' zone specification.
C.The rule should be under 'destination-nat' instead of 'source-nat'.
D.The 'to-interface' should be 'any'.
AnswerB

Source NAT rules must include the source zone to determine when to translate.

Why this answer

A source NAT rule in PAN-OS requires a 'from' zone specification to match traffic. Without it, the rule does not know which zone the traffic originates from, so it will not be applied. In this case, the traffic from 10.1.1.1 to the internet likely originates from a zone (e.g., 'trust') that is not specified in the rule, causing the translation to fail.

Exam trap

The trap here is that candidates often assume source NAT rules only need a source IP range and an egress interface, overlooking the mandatory 'from' zone specification that PAN-OS requires for rule matching.

How to eliminate wrong answers

Option A is wrong because the 'interface-address' option does not require a specific translated address; it dynamically uses the IP address of the egress interface (ethernet1/1) as the translated source address, which is valid. Option C is wrong because the scenario describes source NAT (translating source IP of outbound traffic), not destination NAT (which translates destination IP of inbound traffic), so placing it under 'destination-nat' would be incorrect. Option D is wrong because setting 'to-interface' to 'any' would not fix the missing 'from' zone; the 'to-interface' specifies the egress interface for the translated traffic, and ethernet1/1 is appropriate for internet-bound traffic.

172
Multi-Selecteasy

Which TWO settings must be configured in a security policy rule to ensure the rule only matches when a specific application is detected on its standard port?

Select 2 answers
A.Set the Source Zone and Destination Zone.
B.Enable Threat Prevention.
C.Set the Service to 'application-default'.
D.Configure Logging at session start.
E.Set the Application to the specific application.
AnswersC, E

Setting Service to 'application-default' restricts the rule to the application's standard ports as defined in its signature, rather than any port. Combined with an explicit application match, this satisfies the requirement that the rule only match when the application is detected on its standard port.

Why this answer

Option E is correct because a security policy rule in PAN-OS matches traffic based on the Application field, so setting it to the specific application ensures the rule only matches sessions where that application is positively identified by App-ID. Option C is correct because setting the Service to 'application-default' makes the rule honor the application's standard/default port(s) as defined by the App-ID signature, rather than a custom or any service, which is exactly what is needed to match the application on its standard port. Together, Application = specific app plus Service = application-default ensures the rule matches only when that application is detected on its default port.

Option A is not required for this specific matching condition, since zones define the source/destination context but do not restrict matching to a detected application on its standard port. Option B (Threat Prevention) is a security profile action applied after matching, not a matching criterion. Option D (Logging at session start) affects logging behavior, not whether the rule matches the application on its standard port.

Exam trap

PCNSE often tests the confusion between Service and Application fields, tempting candidates to think specifying the application alone is sufficient — but without application-default, the rule may match on any port or fail to match the standard port correctly.

173
MCQmedium

Refer to the exhibit. A user in the 10.0.0.0/8 network is unable to access a web server at 172.16.1.10 which is in the DMZ zone. The firewall's security policy is shown: source zone trust, destination zone untrust, application web-browsing, action allow. What is the most likely reason for the failure?

A.The source IP range 10.0.0.0/8 is misconfigured.
B.The policy specifies the 'untrust' zone instead of the 'dmz' zone.
C.The policy is missing a 'permit' action.
D.The application 'web-browsing' is not the correct application for the traffic.
AnswerB

The policy's destination zone is 'untrust', but the web server is in the 'dmz' zone, so the traffic does not match this policy, causing the failure.

Why this answer

The policy's destination zone is 'untrust', but the server is in the 'dmz' zone, so the traffic does not match this policy. Option A is incorrect because the source IP range 10.0.0.0/8 includes the user's IP, so it is not misconfigured. Option C is incorrect because the policy has an 'allow' action, so it is not missing a permit.

Option D is incorrect because 'web-browsing' is the correct application for HTTP traffic.

174
MCQeasy

A firewall administrator is troubleshooting a scenario where users cannot reach an internal web server. The security policy allows the traffic, and the server is reachable from other networks. What should the administrator check first?

A.The source and destination zones in the security policy
B.The firewall's DNS settings
C.The server's SSL certificate
D.The interface management profile
AnswerA

If zones in the security policy do not match the actual ingress and egress interfaces, the rule never matches and traffic is denied despite appearing to allow it. Confirming zone assignments is the first check.

Why this answer

The most common reason for traffic failing despite a security policy allowing it is a zone mismatch. In Palo Alto Networks firewalls, security policies are zone-based, meaning the source and destination zones in the policy must exactly match the ingress and egress zones of the traffic. If the administrator configured the policy with the wrong zones (e.g., using 'trust' for the source when the client is in 'dmz'), the traffic will be denied even if all other parameters (IP, port, application) are correct.

This is the first thing to verify because it directly controls whether the policy is evaluated for the session.

Exam trap

The trap here is that candidates often jump to checking DNS or certificates (common web server issues) instead of first verifying the fundamental zone-based policy matching, which is unique to Palo Alto Networks firewalls and a frequent cause of silent traffic drops.

How to eliminate wrong answers

Option B is wrong because DNS settings on the firewall affect only the firewall's own name resolution (e.g., for FQDN objects or external services), not the ability for users to reach an internal web server; client-side DNS resolution is independent of the firewall's DNS configuration. Option C is wrong because the server's SSL certificate is irrelevant to basic connectivity; certificate issues cause browser warnings or TLS handshake failures, not a complete inability to reach the server (which would be a network-layer problem). Option D is wrong because the interface management profile controls administrative access (e.g., HTTPS, SSH, ping) to the firewall interface itself, not the forwarding of user traffic through the firewall.

175
Multi-Selecthard

Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)

Select 3 answers
A.Check the decryption log for errors such as 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed'.
B.Update the URL filtering database to ensure the site is categorized correctly.
C.Verify that the firewall's decryption certificate is trusted by the client.
D.Disable decryption globally to see if the sites become accessible.
E.Use the packet capture tool to analyze the SSL handshake between client, firewall, and server.
AnswersA, C, E

The decryption log records the precise failure reason for each session, exposing whether the firewall rejected the server certificate chain or hit an unsupported cipher during the handshake. This directly satisfies the stem's need to identify why specific HTTPS sites fail, since the logged error code names the exact stage that broke.

Why this answer

Option A is correct because the decryption log is the primary place to identify the exact failure reason, and messages like 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed' directly point to cipher mismatch or certificate validation problems breaking the HTTPS session. Option C is correct because SSL decryption requires the firewall to present its own certificate to the client; if that forward-trust or decryption certificate is not trusted by the client, the TLS handshake fails and the site becomes inaccessible. Option E is correct because a packet capture of the SSL handshake across client, firewall, and server reveals where the handshake breaks, such as a failed ClientHello, certificate alert, or SNI mismatch, which is essential for isolating the fault.

Option B does not belong because URL filtering database categorization affects policy enforcement, not the cryptographic SSL decryption process. Option D does not belong because disabling decryption globally is a disruptive workaround, not a troubleshooting step, and it would not identify the root cause of the decryption failure.

Exam trap

The trap here is that candidates often confuse decryption failures with URL filtering or policy issues, leading them to select option B, when in fact decryption logs and certificate trust are the direct troubleshooting steps for SSL decryption problems.

176
MCQeasy

A company has configured multi-factor authentication (MFA) via an authentication sequence using LDAP and RADIUS. Users authenticate successfully with LDAP but the MFA prompt from RADIUS does not appear. What is the most likely cause?

A.The authentication sequence must be configured to 'require all' or 'continue on success' to enforce each factor.
B.The RADIUS server profile has the wrong shared secret.
C.The authentication policy only covers HTTP applications.
D.The authentication sequence is set to 'continue on failure' and the LDAP authentication succeeds.
AnswerA

To require all factors in the sequence, the sequence type must be set to 'require all' or 'continue on success' so each factor is attempted regardless of previous success.

Why this answer

When using an authentication sequence in Palo Alto Networks firewalls, the sequence must be configured with the 'require all' or 'continue on success' option to enforce each factor in order. With 'continue on success', after LDAP succeeds, the firewall proceeds to the next factor (RADIUS MFA). If the sequence is set to 'continue on failure' (the default), the firewall stops after the first successful authentication and never attempts the second factor, so the MFA prompt never appears.

Exam trap

In Palo Alto Networks, the default behavior for authentication sequences is 'continue on failure', which means the firewall only moves to the next authentication factor if the current one fails. If LDAP succeeds, it never attempts RADIUS. Candidates often assume that simply adding multiple methods enforces all factors, but the sequence must be set to 'continue on success' or 'require all' to enforce MFA properly.

How to eliminate wrong answers

Option B is wrong because a wrong shared secret on the RADIUS server profile would cause the RADIUS authentication to fail or timeout, but the MFA prompt might still appear (the firewall would attempt to contact the RADIUS server). Option C is wrong because authentication policies are not limited to HTTP applications; they can be configured for any application or service, and the question does not specify an HTTP-only scenario. Option D is wrong because if the authentication sequence is set to 'continue on failure', the firewall would stop after the first successful authentication (LDAP) and never proceed to RADIUS, which matches the symptom but is not the most likely cause—the sequence must be explicitly configured to continue on success or require all to enforce multiple factors.

177
Multi-Selecteasy

Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?

Select 2 answers
A.LDAP
B.Local Database
C.Kerberos
D.RADIUS
E.SAML
AnswersC, E

Kerberos uses ticket-granting tickets issued by a domain controller, so a user who has already authenticated to the domain presents a service ticket to the firewall transparently. This delivers SSO because the firewall trusts the KDC's tickets instead of prompting for credentials again.

Why this answer

Kerberos (option C) supports SSO because it uses ticket-based authentication where the client obtains a Ticket Granting Ticket (TGT) from the Key Distribution Center (KDC) and presents it to the firewall without re-entering credentials. SAML (option E) supports SSO by exchanging signed XML assertions between an identity provider (IdP) and the firewall, enabling browser-based federated single sign-on.

Exam trap

The trap here is that candidates often assume RADIUS or LDAP support SSO because they are common authentication protocols, but neither provides the ticket or assertion exchange required for true single sign-on; only Kerberos and SAML implement SSO mechanisms in Palo Alto firewalls.

178
MCQhard

The firewall is in passive state. The network team reports that during a recent maintenance window, the active firewall lost its upstream link but the passive firewall did not take over. Based on the exhibit, what is the most likely reason?

A.HA2 heartbeat link is down, preventing the passive from detecting the active's failure.
B.The fail-holdup timer is set to 0, causing immediate failover but not triggered.
C.Link monitoring is enabled but not configured to monitor the specific interface that failed.
D.Path monitoring is disabled so the passive does not monitor connectivity to the upstream router.
AnswerC

Passive firewalls only fail over when the monitored link path fails. If link monitoring watches a different interface than the one that actually went down, the passive device never detects the failure and stays passive, so no takeover occurs despite the active firewall losing its upstream link.

Why this answer

Link monitoring on a Palo Alto Networks firewall is configured to monitor specific interfaces. If the upstream link that failed is not included in the link monitoring group, the passive firewall will not detect the loss of that link and will not trigger a failover. The passive firewall only monitors the interfaces explicitly listed under Device > High Availability > Link Monitoring, so an unmonitored interface failure will be ignored for HA purposes.

Exam trap

The trap here is that candidates confuse link monitoring (local interface state) with path monitoring (remote reachability) or assume the HA2 heartbeat link is responsible for failure detection, when in fact HA1 keepalives handle that and link monitoring is the feature that must explicitly include the failed interface.

How to eliminate wrong answers

Option A is wrong because the HA2 heartbeat link is used for session synchronization and state propagation, not for detecting link failures; the passive detects active failure via HA1 keepalive packets, not HA2. Option B is wrong because the fail-holdup timer (default 0) controls how long the passive waits before taking over after detecting a failure, but it does not prevent detection of the failure itself; the issue here is that the failure was never detected. Option D is wrong because path monitoring is a separate feature that monitors connectivity to specific destination IP addresses (e.g., next-hop routers), not the state of local interfaces; disabling path monitoring would not prevent the passive from detecting a local interface failure, which is the domain of link monitoring.

179
MCQmedium

An organization has two sites connected via IPSec VPN. The tunnel is up, but ICMP traffic between sites fails. No other traffic works. The firewall policy allows any-any. What is the most likely issue?

A.The IKE phase 1 proposal is mismatched.
B.The proxy IDs (interesting traffic) are not configured correctly.
C.The IPSec crypto profile uses AES-256 and the peer uses 3DES.
D.The tunnel interface MTU is set too low.
AnswerB

With route-based or policy-based tunnels, mismatched proxy IDs mean phase 2 selectors never match, so the firewall drops traffic even though IKE is up. Correctly aligned local and remote proxy IDs restore ICMP and all other traffic.

Why this answer

When the IPSec tunnel is up but no traffic passes, the most common cause is misconfigured proxy IDs (also called interesting traffic selectors). Proxy IDs define which source/destination subnets are permitted through the tunnel; if they don't match on both peers, the tunnel may establish (IKE and IPsec SAs are created) but the firewall will not encrypt or forward traffic because it does not match the defined selectors. Since the firewall policy allows any-any, the issue is not a policy block, pointing directly to proxy ID mismatch.

Exam trap

The trap here is that candidates assume a tunnel being 'up' means all traffic should work, but in Palo Alto Networks, the tunnel state only reflects IKE and IPsec SA establishment, not the correctness of proxy IDs which control traffic selection.

How to eliminate wrong answers

Option A is wrong because an IKE phase 1 proposal mismatch would prevent the tunnel from coming up at all—the tunnel being up indicates phase 1 completed successfully. Option C is wrong because an IPSec crypto profile mismatch (e.g., AES-256 vs 3DES) would cause the tunnel to fail during phase 2 negotiation, not allow the tunnel to be up with no traffic. Option D is wrong because a low tunnel interface MTU would cause fragmentation or packet drops for large packets, but ICMP traffic (typically small packets) would still pass; it would not cause a complete failure of all traffic.

180
Multi-Selectmedium

An administrator is preparing to upgrade a PA-5220 firewall from PAN-OS 10.2 to a later maintenance release. Before the upgrade, the administrator wants to minimize the chance of a failed upgrade and ensure a rollback path exists. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Verify that the current configuration passes validation and resolve any commit warnings before starting.
B.Change the management interface to a different IP address so the upgrade does not conflict with the old configuration.
C.Delete the previous PAN-OS image from the firewall to free space for the new version.
D.Export a named configuration snapshot and a device state backup to an external server before upgrading.
E.Disable all Security policy rules temporarily so that traffic is not inspected during the upgrade.
AnswersA, D

Configuration errors or unresolved commit warnings can cause the post-upgrade commit to fail, leaving the firewall in an inconsistent state. Validating the configuration and clearing warnings beforehand ensures the new PAN-OS version can commit the existing configuration cleanly, which directly reduces the risk of a failed upgrade and preserves a predictable rollback point.

Why this answer

Validating the configuration and clearing commit warnings ensures the new PAN-OS version can commit the existing configuration, and exporting both a configuration snapshot and a device state backup creates an external restore point. Together these steps reduce upgrade risk and guarantee a usable rollback path if the new version misbehaves.

Exam trap

The trap here is treating free-space cleanup as more important than preserving the previous image, when the previous image is the primary rollback mechanism.

181
MCQmedium

A security administrator configures a new network template in Panorama and assigns it to a template stack. The template stack is associated with a device group containing several firewalls. After committing the Panorama configuration and pushing to devices, some firewalls in the device group do not have the new template settings. What is the most likely cause?

A.The firewalls that are not receiving the template are not included in the same template stack.
B.The device group has not been committed.
C.The firewalls are not licensed for Panorama management.
D.The template is in 'preview' mode.
AnswerA

Template settings only reach firewalls that are members of the template stack. Firewalls in the device group but absent from that stack receive no template configuration, explaining why only some devices show the new settings.

Why this answer

In Panorama, templates are assigned to template stacks, and template stacks are then assigned to specific firewalls. If a firewall does not belong to the template stack that contains the new template, it will not receive those settings, regardless of its membership in the device group. Device groups manage policy objects and rules, not network configuration templates.

Exam trap

The trap here is that candidates often confuse device groups (which manage policy) with template stacks (which manage network configuration), assuming that membership in a device group automatically applies all associated templates.

How to eliminate wrong answers

Option B is wrong because the device group commit is separate from template commit; templates are committed as part of the Panorama configuration push, and a missing device group commit would affect policy, not template settings. Option C is wrong because Panorama management does not require a separate license for firewalls; it is a built-in capability of the firewall platform. Option D is wrong because Panorama does not have a 'preview' mode for templates; templates are either committed or not, and preview is a concept for policy rules, not network templates.

182
MCQmedium

What does the session state 'SYN_SENT' indicate about this traffic flow?

A.The session has been torn down by the server.
B.The firewall has sent a SYN packet and is waiting for a response.
C.The traffic is being dropped due to asymmetric routing.
D.The application has been identified as incomplete.
AnswerB

SYN_SENT means the firewall initiated the connection by transmitting a SYN packet and now awaits the returning SYN-ACK from the responder. This half-open state confirms the firewall is the active sender, not the receiver, of the initial handshake packet.

Why this answer

The SYN_SENT session state in a Palo Alto Networks firewall indicates that the firewall has sent a SYN packet to initiate a TCP three-way handshake and is awaiting a SYN-ACK response from the remote host. This state is part of the firewall's session setup process, where it tracks the TCP connection state machine to ensure proper traffic flow. It does not imply a teardown, asymmetric routing drop, or incomplete application identification.

Exam trap

The trap here is that candidates confuse SYN_SENT with a session teardown state or assume it indicates a problem like asymmetric routing, when in fact it is a normal transient state during TCP connection setup that only becomes problematic if it persists beyond the timeout.

How to eliminate wrong answers

Option A is wrong because a session torn down by the server would show states like FIN_WAIT, CLOSE_WAIT, or TIME_WAIT, not SYN_SENT, which is an initial handshake state. Option C is wrong because asymmetric routing typically causes sessions to be in a 'half-open' state or show as 'drop' due to security policy mismatch, not SYN_SENT; SYN_SENT is a normal transient state during connection establishment. Option D is wrong because application identification occurs after the TCP handshake completes and data is exchanged; SYN_SENT is too early in the flow for app-ID to be determined, and an 'incomplete' application would be flagged later, not at this stage.

183
MCQhard

A network security engineer is troubleshooting why a Palo Alto Networks firewall is not enforcing a security policy that should block traffic from the untrust zone to the trust zone. The policy is configured correctly, and the firewall is receiving traffic. The engineer suspects that the traffic is being allowed by a different policy due to policy evaluation order. Which factor determines the order in which security policies are evaluated?

A.The rule with the most specific match is evaluated first, regardless of position.
B.Rules are evaluated based on the zone pair, with intra-zone rules first.
C.The order of rules in the security policy rulebase, from top to bottom.
D.Rules with a deny action are always evaluated before allow rules.
AnswerC

Security policies are evaluated from top to bottom in the rulebase. The first rule that matches the traffic is applied. If a rule above the intended block rule allows the traffic, the block rule will not be evaluated. Therefore, the engineer must ensure that more specific rules are placed above general allow rules to enforce the desired blocking.

Why this answer

Security policies are evaluated sequentially from the top of the rulebase to the bottom. The first matching rule is enforced, so rule order is critical. Placing a block rule below an allow rule that matches the same traffic will result in the traffic being allowed.

Therefore, the engineer must reorder rules to ensure the block rule is evaluated first.

Exam trap

The trap here is assuming that PAN-OS prioritizes rules by specificity or action, when it strictly follows rule order.

184
MCQmedium

A company has configured User-ID with Active Directory polling. Some users cannot access resources even though their security policy rules appear correct. The administrator verifies that the User-ID agent is connected and polling. What additional step should the administrator take?

A.Restart the User-ID agent service.
B.Check the firewall's management plane CPU usage.
C.Ensure the firewall has a license for User-ID.
D.Verify that the user group mapping is correct.
AnswerD

Group mapping determines which users inherit policy based on their directory groups. With Active Directory polling, the agent retrieves group membership alongside user-to-IP mappings, so stale or incorrect group data leaves users unmatched by rules. Verifying mapping confirms the identity data feeding policy evaluation is accurate, resolving access failures despite correct rules.

Why this answer

Even if the User-ID agent is connected and polling, the firewall may not have the correct group-to-user mappings. Without accurate group mapping, security policies that reference user groups will fail to match, causing access issues for users who are members of those groups. The administrator should verify the group mapping configuration in the User-ID agent or on the firewall to ensure users are properly associated with their groups.

Exam trap

The trap here is that candidates assume a connected and polling User-ID agent guarantees correct policy enforcement, overlooking the critical step of verifying group mapping accuracy, which is a common misconfiguration in Active Directory environments.

How to eliminate wrong answers

Option A is wrong because restarting the User-ID agent service is a generic troubleshooting step that does not address the root cause of incorrect group mapping; the agent is already connected and polling, so a restart would not fix mapping errors. Option B is wrong because checking the firewall's management plane CPU usage is relevant for performance issues, not for user authentication or group mapping problems; high CPU would not prevent users from accessing resources if policies are correct. Option C is wrong because User-ID functionality does not require a separate license; it is included with the firewall's base subscription (e.g., Threat Prevention or URL Filtering), so a missing license is not the issue here.

185
MCQhard

A security administrator is troubleshooting why a user cannot access an internal server at 192.168.1.50 from the trust zone. The firewall is a PA-5220 running PAN-OS 10.2. The administrator checks the traffic log and sees that the session is allowed by a security policy rule. However, the user still cannot connect. The administrator runs 'show session all filter source 10.1.1.10 destination 192.168.1.50' and sees the session state as 'ACTIVE' but with 'tcp-rst-from-server' flag. What is the most likely cause?

A.The firewall is performing SSL decryption and the certificate is invalid.
B.The server is sending a TCP reset because it is not listening on the requested port.
C.The firewall is dropping the packets due to a security profile.
D.The session is being aged out due to timeout.
AnswerB

The 'tcp-rst-from-server' flag indicates that the server sent a TCP reset packet. This typically happens when the server receives a SYN for a port it is not listening on, or the service is not running. The firewall allowed the session, but the server rejected the connection. This is a common cause when the application on the server is down or the port is incorrect. The user cannot connect because the server actively refused the connection.

Why this answer

The 'tcp-rst-from-server' flag in the session details indicates that the server sent a TCP reset packet. This usually means the server is not listening on the requested port or the service is unavailable. The firewall allowed the session, but the server refused the connection.

The user cannot connect because the server actively rejected the SYN. Troubleshooting should focus on the server's service status and port configuration.

Exam trap

The trap here is assuming the firewall is blocking traffic because the user cannot connect, but the session flag clearly shows the server sent a reset, indicating a server-side issue.

186
MCQmedium

A company uses User-ID to map users to IPs. Some users report that their traffic is being blocked even though they are in the correct user group for access. The security policy uses user-based conditions. What is a likely cause?

A.The security policy order is incorrect
B.The firewall is not configured to use the User-ID agent
C.The User-ID agent is not running
D.The user's IP is not in the User-ID mapping table
AnswerD

User-ID policy enforcement depends on a valid IP-to-user mapping. If the source IP is absent from the mapping table, the firewall cannot resolve the user, so user-based rules fail to match and traffic is blocked.

Why this answer

When a security policy uses user-based conditions, the firewall must have a valid User-ID mapping for the user's IP address to enforce the rule. If the user's IP is not in the User-ID mapping table, the firewall cannot associate the traffic with a user group, and it will either match a default deny rule or fail to match the intended allow rule, resulting in blocked traffic. This is the most direct cause given that the user group assignment is correct but the mapping is missing.

Exam trap

The trap here is that candidates often assume the issue is with the User-ID agent's configuration or status, but the question specifies that some users are affected, pointing to a per-user mapping gap rather than a global agent failure.

How to eliminate wrong answers

Option A is wrong because security policy order affects which rule matches first, but if the correct user-based rule exists and the user's IP is unmapped, the rule will not match regardless of order. Option B is wrong because if the firewall were not configured to use the User-ID agent, no user mappings would exist at all, but the issue is specific to some users, implying the agent is configured. Option C is wrong because if the User-ID agent were not running, no mappings would be populated for any user, but the problem is isolated to certain users, indicating the agent is operational.

187
MCQeasy

A network engineer notices that traffic from a specific subnet is being dropped by the firewall. The traffic log shows 'drop' with reason 'policy deny'. The engineer checks the security policy and confirms there is an allow rule for that subnet. What should be checked next?

A.Check the application override.
B.Check the QoS policy.
C.Check the rule order and ensure the allow rule is above any deny rules.
D.Check the NAT policy for the traffic.
AnswerC

PAN-OS evaluates security rules top-down and stops at the first match. A deny rule positioned above the allow rule for that subnet matches first, producing the 'policy deny' drop despite the allow rule existing lower in the policy.

Why this answer

When a traffic log shows 'policy deny' despite an existing allow rule, the most common cause is rule order: Palo Alto firewalls evaluate security rules from top to bottom, and the first matching rule is applied. If a deny rule appears above the allow rule for the same subnet, the deny rule will match first and drop the traffic, making it essential to verify the rule sequence.

Exam trap

The common mistake is assuming that if an allow rule exists for the subnet, it will always be applied, ignoring that Palo Alto firewalls evaluate rules top-down and a higher-priority deny rule can preempt the allow rule.

How to eliminate wrong answers

Option A is wrong because application override is used to bypass App-ID for specific traffic, not to resolve policy deny issues caused by rule order; it would not change the matching behavior of security rules. Option B is wrong because QoS policy controls bandwidth allocation and prioritization, not access control; a QoS misconfiguration would not cause a 'policy deny' log entry. Option D is wrong because NAT policy is processed after security policy matching; if traffic is denied by security policy, it never reaches the NAT stage, so checking NAT would not address the deny reason.

188
MCQmedium

A firewall in an HA pair is being upgraded. The administrator wants to minimize traffic loss. What is the recommended procedure for upgrading the passive firewall in an active/passive pair?

A.Upgrade the active firewall first, then failover to the passive
B.Upgrade the passive firewall, failover to it, then upgrade the original active
C.Suspend HA, upgrade both, then re-enable HA
D.Upgrade both firewalls simultaneously after disconnecting HA links
AnswerB

Upgrading the passive node first keeps the active firewall forwarding traffic, then a failover promotes the upgraded unit so it carries sessions while the original active is upgraded. This staged approach satisfies the minimise-traffic-loss constraint without taking both nodes offline simultaneously.

Why this answer

In an active/passive HA pair, the passive firewall is upgraded first while the active firewall continues to handle traffic. After the passive firewall is upgraded and rebooted, an administrative failover is performed to make it the new active firewall, minimizing traffic loss. The original active firewall is then upgraded, ensuring there is always a firewall processing traffic during the upgrade process.

Exam trap

The trap here is that candidates often assume upgrading the active firewall first is safer because it is the primary device, but this ignores the fact that the passive firewall must be upgraded and ready to take over before the active firewall is touched to avoid traffic loss.

How to eliminate wrong answers

Option A is wrong because upgrading the active firewall first would cause traffic disruption during its reboot, as the passive firewall is not yet upgraded and may not be able to take over seamlessly. Option C is wrong because suspending HA breaks the synchronization and state sharing, leaving the network unprotected during the upgrade and requiring manual reconfiguration, which increases the risk of traffic loss. Option D is wrong because upgrading both firewalls simultaneously after disconnecting HA links leaves no firewall protecting the network, causing complete traffic loss until at least one firewall is back online.

189
Multi-Selecthard

Which THREE components should be verified when troubleshooting a site-to-site IPSec VPN that is not coming up?

Select 3 answers
A.Zone protection profile on the untrust zone
B.Interface management profile on the external interface
C.Pre-shared key configuration on both ends
D.Peer IP address in the tunnel interface configuration
E.IKE version (v1 vs v2) compatibility
AnswersC, D, E

A mismatched pre-shared key causes IKE phase 1 authentication to fail, so the tunnel never negotiates. Verifying identical keys on both peers satisfies the stem's requirement to check components preventing the IPSec VPN from coming up, since the pre-shared key must match exactly on each end.

Why this answer

When a site-to-site IPSec VPN fails to establish, the IKE Phase 1 negotiation is the first thing to verify, and option C (pre-shared key configuration on both ends) is critical because a mismatched PSK causes IKE authentication to fail immediately. Option D (peer IP address in the tunnel interface configuration) is correct because the local device must reference the correct remote peer's public IP as the IKE gateway; a wrong or unreachable peer IP prevents any IKE exchange from starting. Option E (IKE version v1 vs v2 compatibility) is correct because both peers must agree on IKEv1 or IKEv2; a version mismatch means the devices cannot negotiate Phase 1 at all.

Options A and B are not part of the core IPSec VPN bring-up path: a zone protection profile (A) affects flood/scan protection on the untrust zone and does not govern tunnel negotiation, and an interface management profile (B) controls which management services (ping, SSH, HTTPS, etc.) are permitted on the interface, which is unrelated to IPSec tunnel establishment.

Exam trap

The trap here is that candidates often confuse zone protection profiles or interface management profiles with VPN-related security settings, but these profiles only affect data-plane or management-plane traffic, not the control-plane IKE negotiation required for tunnel establishment.

190
Multi-Selectmedium

Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?

Select 2 answers
A.Two physical or subinterfaces assigned to the vwire.
B.A management profile must be applied to the vwire.
C.A zone must be assigned to the vwire.
D.The interfaces must be of type 'aggregate'.
E.No IP addresses configured on the interfaces used in the vwire.
AnswersA, E

A vwire requires exactly two interfaces.

Why this answer

A virtual wire (vwire) requires exactly two interfaces to function as a transparent bridge between two network segments. These interfaces can be physical or subinterfaces, and they must be assigned to the vwire to pass traffic without Layer 3 processing. Without two interfaces, the vwire cannot forward frames between the connected devices.

Exam trap

The trap here is that candidates often assume a vwire needs a zone or management profile because they confuse it with a Layer 3 interface, but Palo Alto vwires are purely Layer 2 constructs that require only two interfaces and no IP addresses.

191
MCQmedium

An administrator is troubleshooting why a Security policy rule that allows traffic from the 'trust' zone to the 'untrust' zone is not matching for certain sessions. The administrator notices that the sessions are being denied by an interzone rule. What is the most likely cause?

A.The allow rule is configured with the application 'any' instead of a specific application.
B.The allow rule is configured with a source user instead of a source IP address.
C.The allow rule is configured with a destination zone of 'untrust' but the traffic is destined to the firewall itself.
D.The interzone rule is placed above the allow rule in the rulebase.
AnswerD

Security policy rules are evaluated top-down, and the first rule that matches the traffic is applied. If an interzone deny rule is positioned above the allow rule, it will match and block the traffic before the allow rule is evaluated. This is a common cause of unexpected denials when rule order is not carefully managed, especially when interzone rules are added for default protection.

Why this answer

The most likely cause is that the interzone deny rule is positioned above the allow rule in the Security policy rulebase. Because PAN-OS evaluates rules from top to bottom and stops at the first match, a deny rule higher in the list will take precedence over a later allow rule. To resolve the issue, the administrator should move the allow rule above the interzone deny rule or adjust the interzone rule to be more specific so it does not match the intended traffic.

Exam trap

The trap here is focusing on application or user settings when the symptom clearly indicates a rule order problem, as interzone rules are often placed at the top for default protection.

192
MCQhard

Refer to the exhibit. Based on the log, what triggered the failover?

A.Loss of HA1 heartbeat from the peer
B.A link failure on ethernet1/1
C.An administrator manually triggered a failover
D.A path monitoring group determined that the upstream ISP is unreachable
AnswerD

Path monitoring groups probe specified destination IPs; when probes fail, the firewall treats the monitored path as down and triggers failover. The log records an unreachable upstream ISP, satisfying the path-monitoring failure condition that initiates the failover.

Why this answer

The log entry indicates that the failover was triggered by a path monitoring group, which detected that the upstream ISP became unreachable. Path monitoring actively probes the next-hop gateway or a target IP address; when the probe fails, the firewall considers the path down and initiates a failover to the passive peer. This is distinct from HA1 heartbeat loss or link failure, as the log explicitly references the path monitoring group.

Exam trap

The trap here is that candidates often confuse path monitoring with simple link monitoring or HA1 heartbeat loss, but the log entry's explicit reference to a 'path monitoring group' is the key differentiator that points to upstream unreachability rather than local interface or HA communication issues.

How to eliminate wrong answers

Option A is wrong because loss of HA1 heartbeat would generate a log entry referencing 'HA1 heartbeat timeout' or 'HA1 link down', not a path monitoring group event. Option B is wrong because a link failure on ethernet1/1 would produce a log entry for 'link down' or 'interface down', not a path monitoring group action. Option C is wrong because an administrator manually triggering a failover would show a log entry like 'admin requested failover' or 'manual failover', not a path monitoring group event.

193
MCQeasy

Which component of the PAN-OS architecture is responsible for processing security policies and performing packet inspection?

A.Panorama plane
B.Management plane
C.Data plane
D.Control plane
AnswerC

The data plane handles all packet-level processing, including security policy enforcement, application identification, and threat inspection, after the management plane pushes committed configuration and the control plane builds routing and session tables. This satisfies the stem's requirement for the component performing packet inspection and policy enforcement.

Why this answer

The data plane is the correct answer because it is the hardware-accelerated component in PAN-OS that handles all packet forwarding, security policy enforcement, and deep packet inspection (including App-ID, Content-ID, and SSL decryption). It operates on a separate processor from the management and control planes to ensure that security processing does not impact management access or routing stability.

Exam trap

The trap here is that candidates confuse the control plane's role in session setup with packet inspection, but the control plane only handles control traffic (e.g., ARP, routing updates) and session table management, not the actual security policy enforcement or deep packet inspection that occurs in the data plane.

How to eliminate wrong answers

Option A is wrong because Panorama is a centralized management platform for multiple firewalls, not a plane within a single PAN-OS firewall; it does not perform packet inspection or enforce security policies directly. Option B is wrong because the management plane handles administrative tasks (CLI, GUI, logging, configuration commits) and does not process live traffic or perform packet inspection. Option D is wrong because the control plane manages routing protocols (e.g., OSPF, BGP), session setup, and high-availability state synchronization, but it does not inspect packet payloads or enforce security rules.

194
MCQmedium

A network engineer wants to reduce the number of applications in security policies by combining several applications that are always used together. What is the best practice?

A.Use a wildcard application for the protocol.
B.Create a custom application that covers all the applications.
C.Configure an application group and add all related applications.
D.Remove the individual applications and just use port-based rules.
AnswerC

An application group bundles related applications into one object referenced by policy, reducing rule count while preserving App-ID granularity. This satisfies the requirement to combine applications always used together without listing each separately in every rule.

Why this answer

An application group in Palo Alto Networks PAN-OS allows multiple applications to be referenced as a single object in security policies, reducing policy count while maintaining application-level visibility and control. This is the recommended best practice because it preserves the granular security benefits of App-ID without creating redundant rules. Unlike custom applications, application groups do not require reverse-engineering or signature creation, and they remain dynamically updated with the application content database.

Exam trap

PCNSE often tests the difference between application groups and custom applications, and candidates may incorrectly think a custom application is needed to combine multiple applications. The trap is confusing 'grouping' with 'creating'—application groups are the correct object for aggregation, not custom signatures.

How to eliminate wrong answers

Option A is wrong because a wildcard application (e.g., 'any') for a protocol would match all applications using that protocol, drastically expanding the attack surface and defeating the purpose of application-based policies. Option B is wrong because creating a custom application to cover multiple existing applications is unnecessary and error-prone; custom applications are intended for proprietary or unknown traffic, not for grouping known applications. Option D is wrong because port-based rules abandon application identification entirely, reverting to legacy firewall behavior and losing the security and visibility benefits of App-ID.

195
Multi-Selectmedium

An administrator is configuring a Palo Alto Networks firewall to enforce security policies based on user identity. The environment uses Active Directory, and the administrator plans to deploy User-ID. Which TWO actions are required to enable User-ID to map IP addresses to usernames? (Choose two.)

Select 2 answers
A.Ensure the firewall can communicate with the domain controllers over the required ports for User-ID (e.g., RPC, WMI).
B.Configure the firewall to use LDAP to query the domain controller for user group memberships.
C.Create a security policy that includes user or group objects in the Source User field.
D.Configure a User-ID Agent or enable the firewall's integrated User-ID agent to connect to the domain controllers.
E.Enable User-ID on the zone(s) where users reside by applying a User-ID enabled zone configuration.
AnswersA, D

The User-ID agent (integrated or external) must communicate with domain controllers to read security logs and query sessions. This requires network connectivity and appropriate firewall rules to allow protocols such as RPC and WMI. Without this communication, the agent cannot retrieve user mapping information, making it a prerequisite for User-ID to operate.

Why this answer

To enable User-ID mapping, the firewall must have a User-ID agent (integrated or external) configured to connect to domain controllers and the necessary network access to those controllers. These two actions allow the firewall to learn user-to-IP mappings from Active Directory security logs. Other steps like zone configuration or LDAP are for enforcement or group mapping, not for enabling the basic mapping function.

Exam trap

The trap here is assuming that enabling User-ID on a zone or creating user-based policies is required to start mapping users, when the core prerequisites are the agent and connectivity to domain controllers.

196
Multi-Selectmedium

A security engineer is configuring a Palo Alto Networks firewall to send alerts to an external SNMP manager. The engineer wants to ensure that the firewall sends SNMP traps for specific events, such as a link state change and a configuration change. Which two actions must the engineer perform to achieve this? (Choose two.)

Select 2 answers
A.Configure an SNMP server profile with the manager's IP address and community string.
B.Configure a log forwarding profile to send SNMP traps.
C.Create a security policy rule to allow SNMP traffic from the firewall to the manager.
D.Enable SNMP traps for link state and configuration changes in the SNMP setup.
E.Enable SNMP on the dataplane interfaces to allow trap generation.
AnswersA, D

An SNMP server profile defines the SNMP manager's IP address, port, and community string (for SNMPv2c) or user credentials (for SNMPv3). Without this profile, the firewall does not know where to send traps. This is a mandatory step to enable SNMP trap forwarding. The engineer must create and apply this profile to the firewall's management interface or a specific interface.

Why this answer

To send SNMP traps for specific events, the engineer must first configure an SNMP server profile with the manager's details, and then enable the desired traps in the SNMP setup. These two steps ensure the firewall knows where to send traps and which events to report. Security policy rules and log forwarding profiles are not involved in system-level SNMP trap generation, and SNMP operates on the management plane, not the dataplane.

Exam trap

The trap here is assuming that security policy rules or log forwarding profiles are needed for SNMP traps, when in fact SNMP trap configuration is separate and managed entirely within the SNMP setup.

197
Multi-Selecteasy

Which THREE of the following are core components of the GlobalProtect solution? (Choose exactly three.)

Select 3 answers
A.GlobalProtect License Server
B.GlobalProtect Gateway
C.GlobalProtect Client
D.GlobalProtect Mobile App
E.GlobalProtect Portal
AnswersB, C, E

The GlobalProtect Gateway is a core component, terminating client tunnels and enforcing security policy for remote users. It works alongside the portal and the agent to deliver the solution, making it one of the three required components.

Why this answer

The three core components of the GlobalProtect solution are the GlobalProtect Portal (E), the GlobalProtect Gateway (B), and the GlobalProtect Client (C). The GlobalProtect Portal (E) is the web-based interface that authenticates end users, distributes the GlobalProtect agent/app and its configuration, and provides the list of available gateways. The GlobalProtect Gateway (B) is the security appliance (firewall or Prisma Access) that terminates the tunnels and enforces security policy, providing access to internal resources.

The GlobalProtect Client (C) is the agent software installed on endpoints (Windows, macOS, Linux, iOS, Android) that connects to the portal and gateway to establish the VPN connection. The GlobalProtect License Server (A) is not a core component; licensing is managed through the firewall or Panorama, not a separate license server. The GlobalProtect Mobile App (D) is not a distinct core component — mobile support is delivered via the GlobalProtect Client (the app is simply the client for mobile platforms), so it is not counted separately.

Exam trap

The trap here is that candidates often mistake the GlobalProtect Mobile App as a core component, but it is simply a variant of the GlobalProtect Client and not one of the three fundamental architectural elements.

198
MCQmedium

During a failover test, the active firewall in an active/passive HA pair goes down, but the passive firewall remains in passive state and does not take over. The passive firewall shows HA state 'passive' and the HA1 link status is 'down'. What is the most likely cause?

A.The HA2 link is not configured for session synchronization.
B.The HA1 link is not configured with the same subnet on both firewalls.
C.The passive firewall is configured with a lower HA priority.
D.The HA1 link is down, preventing heartbeat communication.
AnswerD

The HA1 link is the control link used for heartbeats and synchronization between HA peers. If it is down, the passive firewall does not receive heartbeats from the active firewall and may not detect a failure, thus remaining passive. The stem explicitly states HA1 link status is 'down', making this the most likely cause for the passive firewall not taking over.

Why this answer

The HA1 link is critical for heartbeats and control communication. When it is down, the passive firewall cannot determine the active firewall's status and will not initiate failover. The stem indicates HA1 link status is 'down', which directly explains why the passive firewall remains passive despite the active firewall going down.

Exam trap

The trap here is assuming that HA2 link issues prevent failover, but HA2 is for session synchronization and not for failover detection.

199
MCQmedium

A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?

A.Configure the SSL/TLS Service Profile to bypass decryption for the domain.
B.Configure a Decryption Profile to exclude the domain.
C.Create a Decryption Policy rule matching the traffic and set the action to 'No Decrypt'.
D.Enable certificate revocation checking for the decryption zone.
AnswerC

A Decryption Policy rule with the action set to 'No Decrypt' bypasses SSL Forward Proxy decryption for traffic matching *.bank.com, satisfying the compliance constraint that financial sites remain encrypted. The firewall still permits the session, forwarding the encrypted traffic untouched, so no certificate is presented to the client and no inspection occurs.

Why this answer

In Palo Alto Networks firewalls, SSL Forward Proxy decryption is controlled by Decryption Policy rules. To exclude specific traffic from decryption, you create a Decryption Policy rule that matches the traffic (e.g., destination domain *.bank.com) and set the action to 'No Decrypt'. This ensures the firewall forwards the traffic without intercepting or decrypting it, meeting compliance requirements.

Exam trap

The trap here is confusing the purpose of Decryption Profiles (which control decryption behavior) with Decryption Policy rules (which control which traffic is decrypted), leading candidates to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because the SSL/TLS Service Profile is used to define the certificate and protocol settings for decryption, not to bypass decryption for specific domains. Option B is wrong because a Decryption Profile controls advanced decryption settings like certificate revocation checking and protocol versions, not the decision to decrypt or not. Option D is wrong because enabling certificate revocation checking for the decryption zone affects validation of certificates during decryption, not the exclusion of traffic from decryption.

200
MCQmedium

An administrator needs every administrator login, configuration commit, and firewall restart to be recorded in a central location for an upcoming audit. The auditor requires that the records be queryable by username and timestamp, and that they be retained independently of the firewall's own log storage. Which action should the administrator take to meet these requirements?

A.Enable the Audit Log on the management plane and forward it to an external syslog server.
B.Configure a Log Forwarding profile on the management interface to send system logs to an external server.
C.Configure a Syslog server profile under Device > Server Profiles > Syslog and attach it to the Management interface's log settings.
D.Create a custom report under Monitor > Manage Custom Reports that includes the configuration log and schedule it to be emailed daily.
AnswerA

The audit log records administrative actions, including administrator logins, configuration commits, and system restarts, and each entry includes the username and a timestamp. Forwarding it to an external syslog server keeps the records independent of the firewall's local log storage, so the audit trail survives log rotation or device replacement and remains queryable for the auditor.

Why this answer

Administrative activity such as administrator logins, configuration commits, and reboots is recorded in the management-plane audit log, which includes the username and timestamp for each entry. To retain those records independently of the firewall's local storage, the audit log must be forwarded to an external syslog server, satisfying both the query and retention requirements.

Exam trap

The trap here is assuming that any syslog forwarding configuration captures administrator activity, when only the audit log records management-plane actions.

201
MCQeasy

A security administrator is configuring a Palo Alto Networks firewall and needs to ensure that traffic from the trust zone to the untrust zone is inspected for threats. The administrator wants to enable threat prevention profiles on the security policy. Which Palo Alto Networks feature is responsible for detecting and preventing threats such as viruses, spyware, and command-and-control traffic?

A.SSL Decryption
B.App-ID
C.User-ID
D.Content-ID
AnswerD

Content-ID is the Palo Alto Networks integrated threat prevention engine that includes antivirus, anti-spyware, vulnerability protection, URL filtering, and file blocking. It inspects allowed traffic for threats and can block or alert based on security profiles. In this scenario, enabling threat prevention profiles on the security policy activates Content-ID to detect and prevent viruses, spyware, and command-and-control traffic. Content-ID works in conjunction with App-ID to provide comprehensive security.

Why this answer

Content-ID is the Palo Alto Networks integrated threat prevention engine that provides antivirus, anti-spyware, vulnerability protection, and other threat detection capabilities. It inspects allowed traffic based on security profiles attached to security policies. In this scenario, enabling threat prevention profiles activates Content-ID to detect and prevent threats such as viruses, spyware, and command-and-control traffic.

App-ID identifies applications, User-ID maps users, and SSL Decryption enables inspection of encrypted traffic, but none of these detect threats directly.

Exam trap

The trap here is assuming that App-ID or SSL Decryption provides threat detection, but only Content-ID does.

202
MCQmedium

During a troubleshooting session, a user reports that they cannot access an internal web server through the firewall's public IP. The firewall is configured with destination NAT. The engineer checks the NAT policy and sees the rule is active. What should be the next step to verify the NAT is functioning correctly?

A.Check the session table to see if the NAT translation is occurring.
B.Check the application dependency.
C.Check the security policy for the post-NAT zone.
D.Check the routing table for the destination.
AnswerA

Destination NAT rewrites the packet header, so the session table is the authoritative record of whether translation actually occurred. Inspecting it confirms the public IP maps to the internal server and that traffic is matching the active rule, isolating NAT from policy or routing faults.

Why this answer

Checking the session table (e.g., using 'show session all' or 'show session id <id>') directly confirms whether the destination NAT (DNAT) translation is being applied to the traffic. If the session shows the original destination IP being translated to the internal server's IP, the NAT rule is functioning; if not, the issue lies elsewhere (e.g., policy order, matching conditions). This is the most immediate and definitive verification step in a Palo Alto Networks firewall.

Exam trap

The trap here is that candidates often jump to checking security policies or routing first, forgetting that the session table provides the most direct evidence of whether the NAT translation is actually being applied to the traffic.

How to eliminate wrong answers

Option B is wrong because application dependency checks are relevant for App-ID or SSL decryption issues, not for verifying whether a NAT translation is occurring. Option C is wrong because checking the security policy for the post-NAT zone is a subsequent step after confirming NAT is working; the security policy uses the post-NAT zone, but verifying NAT itself requires looking at the session table first. Option D is wrong because checking the routing table for the destination is relevant for routing issues (e.g., next-hop reachability), but does not confirm whether the NAT translation is actually being performed on the traffic.

203
MCQhard

A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?

A.Add the websites to the SSL Decryption Exclusion list.
B.Configure the firewall to use the forward untrust certificate for these websites.
C.Disable SSL decryption globally.
D.Enable 'Block sessions with untrusted issuers' in the decryption profile.
AnswerA

Certificate pinning causes applications to reject certificates that are not signed by the expected CA. When the firewall re-signs the certificate, the pinned certificate does not match, and the connection fails. Adding these websites to the SSL Decryption Exclusion list bypasses decryption for them, allowing the original certificate to be presented to the client and satisfying pinning. This resolves access issues while still decrypting other traffic.

Why this answer

Certificate pinning causes applications to reject certificates not signed by the expected CA. When the firewall decrypts and re-signs, the pinned certificate is replaced, causing failures. Adding the affected websites to the SSL Decryption Exclusion list bypasses decryption for them, allowing the original certificate to be presented and satisfying pinning.

This maintains decryption for other traffic.

Exam trap

The trap here is thinking that the forward untrust certificate or global decryption disable is the solution, when the correct approach is to exclude the specific pinned websites from decryption.

204
MCQeasy

An administrator needs to allow FTP traffic from the internal network to an external server. The firewall is configured with a security policy that has the application 'ftp' and service 'service-http'. What is the most likely cause of the traffic being denied?

A.The source address is wrong.
B.The application is incorrectly set to ftp.
C.The rule is not enabled.
D.The service object in the rule is set to service-http, which does not match FTP traffic.
AnswerD

FTP uses TCP ports 20 and 21, whereas service-http matches TCP 80. Because the security policy's service object is service-http, the firewall drops the FTP session on port 21 before the ftp application can be identified, so the traffic is denied.

Why this answer

The security policy's service object is set to 'service-http' (TCP port 80), but FTP traffic uses TCP port 21 for control and TCP port 20 for data. In Palo Alto Networks firewalls, the service object defines the destination port for the traffic; if it does not match the actual port used by the application, the firewall will deny the session even if the application is correctly identified. The mismatch between the service and the application's expected port causes the traffic to be blocked.

Exam trap

The trap here is that candidates may think the application field alone is sufficient to allow traffic, but the service object must also match the destination port; Palo Alto Networks often tests this by pairing a correct application with an incorrect service to see if you understand the dual-layer check.

How to eliminate wrong answers

Option A is wrong because the source address being incorrect would cause traffic to not match the policy at all, but the question states the policy is configured with the application 'ftp' and service 'service-http', implying the source address is not the primary issue. Option B is wrong because the application 'ftp' is correctly set to allow FTP traffic; the problem is not the application but the service mismatch. Option C is wrong because the rule not being enabled would prevent any traffic matching, but the question asks for the most likely cause given the specific configuration details; the service mismatch is a more precise and common issue than a disabled rule.

205
MCQeasy

A network administrator is deploying a new Palo Alto Networks firewall and needs to configure the data-plane interfaces. The firewall will be placed between the internal network and the internet. The internal network uses private IP addresses and must be translated to a public IP address for outbound traffic. Which type of NAT should the administrator configure on the firewall?

A.Destination NAT (DNAT)
B.U-Turn NAT
C.No NAT; use a security policy to allow outbound traffic
D.Source NAT (SNAT)
AnswerD

Source NAT translates the source IP address of outbound packets, allowing internal private addresses to be represented by a public IP address on the internet. This is exactly what is needed to enable internal hosts to access external resources while hiding their private addresses. SNAT is the standard method for outbound internet access from a private network.

Why this answer

Source NAT (SNAT) translates the source IP address of outbound packets to a public IP address, enabling internal hosts with private addresses to communicate with external networks. This is the correct choice because the scenario requires outbound traffic from a private network to be translated to a public address. SNAT is the standard NAT type for internet access from private networks.

Exam trap

The trap here is confusing source NAT with destination NAT; outbound traffic requires source address translation, not destination translation.

206
MCQhard

Refer to the exhibit. An administrator has configured this decryption policy but users in the 10.1.1.0/24 subnet receive certificate warnings when accessing HTTPS sites. What is the most likely cause?

A.The rule should be at the top of the rulebase
B.The destination address should be specific
C.The application should be web-browsing
D.The decryption certificate is not trusted by clients
AnswerD

An untrusted forward-trust certificate causes browsers to reject the firewall's re-signed certificates, triggering warnings. Since the policy decrypts traffic from 10.1.1.0/24, clients must trust the CA issuing the decryption certificate; without that trust chain installed, every HTTPS site presents an untrusted certificate.

Why this answer

Certificate warnings occur when the decryption certificate used by the firewall is not trusted by the client machines. In a forward proxy decryption scenario, the firewall generates a new certificate on-the-fly for each HTTPS session, and if that certificate is not installed in the client's trusted root store, the browser will display a security warning. This is the most common cause of certificate warnings in decryption deployments.

Exam trap

Palo Alto Networks often tests the distinction between rule configuration issues (like order or application matching) and certificate trust issues, leading candidates to focus on policy settings rather than the fundamental requirement that clients must trust the decryption CA.

How to eliminate wrong answers

Option A is wrong because rule order affects which rule matches traffic, but moving the rule to the top would not resolve certificate trust issues; the warning is caused by the certificate itself, not by rule precedence. Option B is wrong because making the destination address more specific would only narrow the scope of decryption, but the certificate warning would still occur for any traffic that matches the rule if the certificate is not trusted. Option C is wrong because the application 'web-browsing' is typically used for HTTP/HTTPS traffic, but the decryption policy already uses 'ssl' as the service, which correctly identifies HTTPS traffic; changing the application would not address the certificate trust problem.

207
MCQhard

An administrator notices that the firewall's dataplane CPU is consistently high and wants to determine which application is generating the most traffic without waiting for scheduled reports. Which action provides the most immediate visibility into top applications by session and byte count?

A.Enable packet capture on the untrust zone and inspect the captured packets to identify the dominant application.
B.Use the Application Command Center (ACC) on the dashboard, which aggregates traffic by application, source, and destination.
C.Configure a new scheduled report for application usage and wait for the next daily run to review the results.
D.Run the show session all command and manually sort the output by byte count to identify the busiest applications.
AnswerB

The ACC aggregates recent traffic and presents top applications, sources, destinations, and threats in a dashboard view without waiting for a scheduled report. It is designed for immediate operational visibility and updates as new logs arrive, making it the fastest way to see which application is driving traffic and load.

Why this answer

The Application Command Center aggregates log data into dashboard widgets that show top applications, users, and threats, updating as logs are generated. It provides immediate operational visibility without waiting for a scheduled report and summarizes far more usefully than raw session or packet data. Scheduled reports and packet captures are slower or more manual and do not deliver the ranked application view required.

Exam trap

The trap here is reaching for raw session or packet data when a purpose-built aggregated dashboard already answers the question faster.

208
MCQeasy

A firewall is experiencing performance issues. The administrator wants to collect diagnostic data for TAC analysis. Which command generates a comprehensive support file?

A.debug system dump
B.show system resources
C.show log system
D.generate tech-support file
AnswerD

The `generate tech-support file` command bundles comprehensive diagnostics — configuration, logs, and system state — into a single archive for TAC analysis. It satisfies the stem's requirement for a comprehensive support file, unlike narrower commands that capture only specific subsystems or packet-level data.

Why this answer

The 'generate tech-support file' command collects a comprehensive archive of system logs, configuration, resource utilization, and diagnostic data into a single file, which is the standard method for providing TAC with the necessary information to analyze performance issues. This command is specifically designed for troubleshooting and support scenarios, unlike other commands that only capture partial or real-time data.

Exam trap

Palo Alto Networks often tests the distinction between commands that provide real-time snapshots (like 'show system resources') versus commands that generate a comprehensive diagnostic archive (like 'generate tech-support file'), leading candidates to mistakenly choose a command that only shows current state rather than the full dataset needed for TAC analysis.

How to eliminate wrong answers

Option A is wrong because 'debug system dump' is not a valid command on Palo Alto Networks firewalls; the correct command for generating a core dump or debug data is 'debug system core-dump', and it does not produce a comprehensive support file. Option B is wrong because 'show system resources' only displays current CPU, memory, and disk usage in real-time, which is insufficient for TAC analysis as it lacks historical logs, configuration, and other diagnostic data. Option C is wrong because 'show log system' only displays system logs from the log buffer or disk, but it does not include configuration, resource snapshots, or other critical diagnostic information needed for a full TAC investigation.

209
MCQhard

A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?

A.Add the partner site to the SSL Decryption Exclusion list.
B.Install the forward untrust certificate on the firewall and present it to the partner site.
C.Configure the firewall to use the forward trust certificate as the forward untrust certificate.
D.Import the internal certificate authority's root certificate into the users' browsers' trusted root store.
AnswerD

For SSL Forward Proxy decryption, the firewall presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, it will show a warning. Importing the internal CA root into the users' trusted root store allows the browser to validate the re-signed certificate, resolving the warning while keeping decryption active.

Why this answer

The browser warning occurs because the firewall re-signs the partner site's certificate with its forward trust certificate, which is issued by the company's internal CA. If the client does not trust that CA, validation fails. Importing the internal CA root into the users' browsers' trusted root store establishes trust, allowing decryption to continue without warnings.

The other options either bypass decryption or misuse certificate types, failing to resolve the trust issue.

Exam trap

The trap here is assuming that the forward untrust certificate should be used to resolve client trust warnings, when actually the forward trust certificate's issuing CA must be trusted by the client.

210
MCQmedium

In an Active/Passive HA pair, which statement is true regarding configuration synchronization?

A.Configuration is not synced automatically; the administrator must export and import.
B.Only committed changes on the active are synced to the passive.
C.All configuration changes on the active peer are automatically synced to the passive.
D.The passive peer initiates the sync.
AnswerB

Committed configuration on the active firewall synchronises automatically to the passive peer, ensuring both devices hold identical running configurations for seamless failover. Uncommitted candidate changes remain local and are never propagated, satisfying the requirement that the passive stays ready to assume traffic without manual intervention.

Why this answer

In an Active/Passive HA pair, configuration synchronization occurs only after changes are committed on the active firewall. The passive peer then receives the committed configuration via the HA control link (using TCP port 2928 by default). This ensures that only validated, committed changes are propagated, preventing the passive from receiving uncommitted or partial configurations that could cause instability.

Exam trap

The trap here is that candidates often assume all configuration changes (including uncommitted candidate changes) are synced in real time, but Palo Alto Networks only syncs committed configurations to maintain consistency and prevent partial or broken configurations from being applied to the passive peer.

How to eliminate wrong answers

Option A is wrong because configuration synchronization in Active/Passive HA is automatic after a commit on the active peer, not requiring manual export/import. Option C is wrong because not all changes are synced automatically; only committed changes are synced—uncommitted changes (e.g., pending candidate config) are not propagated to the passive. Option D is wrong because the active peer initiates the sync after a commit, not the passive; the passive passively receives the configuration updates.

211
MCQmedium

An engineer notices that the HA pair is not synchronizing configuration changes. The 'show high-availability sync-status' output shows 'sync-failure'. What is the first step to troubleshoot?

A.Verify HA1 link status and IP connectivity between peers
B.Disable preemption on the active firewall
C.Check the HA2 link session synchronization status
D.Reboot both firewalls to clear the failure
AnswerA

A sync-failure indicates the peers cannot exchange configuration data, and that exchange travels over the HA1 link. Verifying HA1 interface status and IP connectivity between peers confirms whether the dedicated synchronisation path is down before investigating deeper causes such as version mismatches or commit failures.

Why this answer

The 'sync-failure' status on the 'show high-availability sync-status' output indicates that configuration synchronization between the HA peers has failed. The first step in troubleshooting is to verify the HA1 link status and IP connectivity between peers because HA1 is the dedicated control link used for heartbeats and configuration sync. Without a functional HA1 link, the firewalls cannot exchange configuration data, making this the most fundamental check before investigating other potential causes.

Exam trap

The trap here is that candidates often jump to checking the HA2 link (session synchronization) because they confuse configuration sync with stateful session sync, but HA1 is the correct link for configuration changes.

How to eliminate wrong answers

Option B is wrong because disabling preemption does not address the underlying connectivity or sync mechanism; preemption controls which firewall becomes active after a failure, not the synchronization of configurations. Option C is wrong because the HA2 link is used for session synchronization (stateful failover), not for configuration synchronization; checking HA2 would be relevant for session sync issues, not config sync failures. Option D is wrong because rebooting both firewalls is a drastic and unnecessary step that could cause service disruption; it should only be considered after verifying basic connectivity and link status, as a reboot will not fix a fundamental HA1 link problem.

212
MCQeasy

To reduce the number of authentication prompts for users accessing multiple applications through the firewall, which configuration is recommended?

A.Increase the authentication timeout value
B.Enable session cookies in the authentication policy
C.Use certificate-based authentication
D.Disable authentication for commonly used applications
AnswerB

Session cookies let the firewall cache a user's authentication result, so subsequent application access reuses that session instead of re-prompting. This directly satisfies the stem's constraint of reducing authentication prompts across multiple applications, provided cookie lifetime and timeout settings are tuned appropriately.

Why this answer

Enabling session cookies in the authentication policy allows the firewall to store a session cookie on the user's browser after the first successful authentication. This cookie is then presented for subsequent requests to different applications, eliminating repeated authentication prompts. The firewall validates the cookie against the existing user session, providing a seamless single sign-on (SSO) experience without requiring re-authentication for each application.

Exam trap

The trap here is that candidates often confuse increasing the authentication timeout (Option A) with reducing prompts, but timeout only extends the session lifespan, not the number of prompts per application; the key is the session cookie mechanism that ties all application requests to a single authenticated session.

How to eliminate wrong answers

Option A is wrong because increasing the authentication timeout value only extends the duration a user remains authenticated, but it does not prevent repeated prompts when accessing multiple applications; each new application request still triggers authentication unless a session cookie is used. Option C is wrong because certificate-based authentication eliminates passwords but does not inherently reduce the number of authentication prompts across multiple applications; each application still requires a separate certificate exchange unless combined with session cookies. Option D is wrong because disabling authentication for commonly used applications bypasses security controls entirely, leaving those applications unprotected and violating the principle of least privilege.

213
MCQeasy

A network administrator wants to generate a report that shows the top applications used over the past week. The firewall is managed by Panorama. Which Panorama feature should the administrator use to create and schedule this report?

A.Use the Manage Custom Reports feature under Monitor > Manage Custom Reports to create a report and schedule it.
B.Use the PDF Report feature under Monitor > PDF Reports to create a report.
C.Use the Log Forwarding profile to send logs to an external syslog server and then generate reports on that server.
D.Use the Application Command Center (ACC) to view top applications and export the data.
AnswerA

Panorama's Manage Custom Reports feature allows you to create reports based on various data sources, including traffic logs, and schedule them for generation and distribution. This is the correct tool to create a scheduled report of top applications.

Why this answer

Panorama's Manage Custom Reports feature is designed for creating, scheduling, and distributing reports. It allows selecting data sources such as traffic logs and defining the report content, including top applications. The report can be scheduled to run at intervals and emailed to recipients.

Other options involve real-time monitoring or external systems, which do not provide the scheduled reporting capability within Panorama.

Exam trap

The trap here is confusing Panorama's reporting feature with the firewall's PDF Reports or real-time monitoring tools.

214
MCQeasy

A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?

A.A Layer 2 interface with a VLAN interface configured for DNS.
B.A virtual wire interface pair with a management profile allowing DNS.
C.A loopback interface with a management profile allowing DNS.
D.A Layer 3 interface with an IP address and a default route pointing to the next-hop gateway.
AnswerD

For the firewall to send DNS queries to external DNS servers, it needs a routable interface with an IP address and a default route to reach the internet. In Layer 3 mode, the firewall uses the interface's IP as the source for DNS queries. The default route ensures that traffic to unknown destinations, including DNS servers, is forwarded to the next-hop gateway. This is the standard configuration for outbound management traffic.

Why this answer

The firewall requires a Layer 3 interface with an IP address and a default route to send DNS queries to external servers. The interface provides the source IP, and the default route directs traffic to the next-hop gateway. Other interface types like loopback, virtual wire, or Layer 2 do not provide the necessary routable connectivity for outbound DNS resolution.

Exam trap

The trap here is confusing management access with outbound connectivity; a loopback or management interface alone does not provide a path for DNS queries.

215
MCQmedium

Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?

A.The firewall's SSL/TLS service profile does not include the cipher suites used by the clients or servers.
B.The firewall is overloaded and cannot handle more decryption sessions.
C.The decryption certificate is not trusted by clients.
D.There is a network connectivity issue between firewall and servers.
AnswerA

Bypassed sessions occur when the firewall cannot negotiate the client's or server's cipher suite, so it falls back to no decryption. If the SSL/TLS service profile lacks the required cipher suites, the handshake fails and sessions are bypassed, matching the exhibit's majority-bypass symptom.

Why this answer

The majority of bypassed sessions are most likely caused by a cipher mismatch between the firewall's SSL/TLS service profile and the clients or servers. When the firewall decrypts traffic, it must negotiate a cipher suite that both the client and server support; if the service profile does not include the cipher suites used by the endpoints, the firewall cannot complete the SSL/TLS handshake and bypasses the session. This is a common misconfiguration in Palo Alto Networks firewalls where the SSL/TLS service profile's cipher list is too restrictive.

Exam trap

The trap here is that candidates often confuse 'bypassed sessions' with 'decryption failures' due to certificate issues or network problems, but bypassed sessions specifically indicate the firewall intentionally skipped decryption due to configuration mismatches like cipher or protocol version incompatibility.

How to eliminate wrong answers

Option B is wrong because firewall overload typically results in session drops or resource exhaustion errors, not a high percentage of bypassed sessions; bypassed sessions indicate the firewall intentionally skipped decryption due to policy or configuration issues, not capacity limits. Option C is wrong because an untrusted decryption certificate causes client-side certificate warnings or connection failures, not bypassed sessions; bypassed sessions occur when the firewall cannot decrypt, not when the client rejects the certificate. Option D is wrong because a network connectivity issue between the firewall and servers would cause session timeouts or connection resets, not bypassed sessions; bypassed sessions are logged when the firewall decides not to decrypt, not when it cannot reach the server.

216
MCQeasy

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that management traffic is separated from data traffic. Which interface type should be used for out-of-band management?

A.A dedicated management interface (MGT) with its own IP address and default gateway.
B.A VLAN interface on a data port configured with a management profile.
C.A tunnel interface configured for management access.
D.A loopback interface configured in the management zone.
AnswerA

The dedicated management interface (MGT) is designed for out-of-band management. It has its own IP address, default gateway, and separate routing table, ensuring that management traffic is isolated from data plane traffic. This separation enhances security and prevents data traffic from interfering with management access, which is critical for firewall administration.

Why this answer

The dedicated management interface (MGT) is specifically designed for out-of-band management, providing a separate routing table and isolation from data traffic. This ensures that management access is not affected by data plane issues and enhances security by keeping management traffic separate. Other interface types are part of the data plane and do not offer the same level of separation.

Exam trap

The trap here is assuming any interface with a management profile provides out-of-band management, but only the dedicated MGT interface ensures true separation.

217
MCQmedium

A company has a Palo Alto Networks firewall with two virtual systems (vsys) configured. The administrator wants to ensure that traffic between vsys1 and vsys2 is inspected by the firewall. What must be configured to allow this inter-vsys traffic?

A.A NAT policy rule translating the source IP addresses between vsys.
B.A Security policy rule in each vsys allowing traffic to the other vsys.
C.A shared Security policy rule in the shared policy or a rule in each vsys, plus routing between the vsys.
D.A Policy-Based Forwarding (PBF) rule to redirect traffic between vsys.
AnswerC

Inter-vsys traffic requires that each vsys have a Security policy rule permitting the traffic, and that routing is configured to send traffic from one vsys to the other. This can be achieved with a shared policy rule that applies to both vsys or with individual rules in each vsys. Additionally, the virtual routers in each vsys must have routes to the other vsys, often via a shared interface or inter-vsys link.

Why this answer

To allow inter-vsys traffic, the administrator must configure Security policy rules that permit the traffic, either as a shared rule or individual rules in each vsys, and ensure that routing is in place to direct traffic between the vsys. Each vsys has its own virtual router, so routes must exist to forward traffic from one vsys to the other, often through a shared interface or an inter-vsys link. Without both policy and routing, the traffic will be blocked or dropped.

Exam trap

The trap here is assuming that a Security policy rule alone is enough for inter-vsys traffic, but routing between the isolated vsys instances is also required.

218
MCQhard

An engineer is troubleshooting an HA pair where the passive firewall is not receiving session updates. The HA1 link is up and the firewalls are in active/passive mode. The engineer runs 'show high-availability state' and sees 'State: passive' and 'Peer State: active'. Which additional command should the engineer run to verify that session synchronization is enabled and functioning?

A.show high-availability interface ha2
B.show high-availability state-synchronization
C.show session all
D.show high-availability state
AnswerB

This command displays the session synchronization state and statistics, including whether synchronization is enabled and if there are any errors. It directly addresses the engineer's need to verify that session updates are being sent and received. If synchronization is not working, this command will show details such as packet counts and errors, helping to pinpoint the issue.

Why this answer

To verify session synchronization, the engineer should use the command that specifically reports on synchronization state and statistics. 'show high-availability state-synchronization' provides details such as whether synchronization is enabled, the number of synchronized sessions, and any errors. This is the most direct way to confirm if session updates are being sent and received correctly.

Exam trap

The trap here is assuming that HA1 and HA2 link status are sufficient, but session synchronization also depends on configuration and can be disabled or failing even with healthy links.

219
MCQmedium

A security team is implementing SSL Decryption. They want to ensure that traffic to health-related websites is not decrypted due to privacy concerns. Which method should they use to exclude this traffic?

A.Use a source IP address exclusion list in the decryption policy.
B.Disable decryption for all sites that use certificate pinning.
C.Add the domain names to a custom URL category and create a no-decryption rule matching that category.
D.Configure a decryption profile to exclude traffic based on App-ID.
AnswerC

Adding health-related domains to a custom URL category lets a no-decryption rule match them by category rather than by individual address, satisfying the requirement to exclude that traffic from SSL Decryption. The firewall then bypasses decryption for those sessions while still applying other security policy, preserving privacy without disabling inspection globally.

Why this answer

Palo Alto Networks firewalls allow you to create custom URL categories containing specific domain names (e.g., health-related sites) and then reference that category in a decryption policy rule set to 'no-decrypt'. This ensures traffic matching those domains is excluded from SSL decryption, addressing privacy concerns without affecting other traffic.

Exam trap

The trap here is that candidates often confuse App-ID with URL filtering, thinking App-ID can selectively exclude traffic based on domain names, but App-ID operates at the application layer and cannot parse individual URLs within encrypted sessions without decryption.

How to eliminate wrong answers

Option A is wrong because source IP address exclusion lists in decryption policy only exclude traffic based on IP addresses, not domain names; health-related websites often use CDNs or load balancers with dynamic IPs, making IP-based exclusion impractical and incomplete. Option B is wrong because disabling decryption for all sites that use certificate pinning is a broad, security-weakening approach that would exclude many non-health sites and is not a precise method for excluding specific health-related domains. Option D is wrong because App-ID identifies applications (e.g., web-browsing, SSL) but cannot distinguish between specific domain names within an encrypted session; it cannot selectively exclude traffic to health-related websites based on URL or domain.

220
MCQhard

In an HA active/passive setup, the engineer wants to ensure that during a failover, existing FTP data sessions are not interrupted. What additional configuration is required beyond default session synchronization?

A.Use HA3 link for session synchronization
B.Enable asymmetric routing support
C.Enable UDP session synchronization
D.Configure an application layer gateway (ALG) for FTP
AnswerD

FTP data sessions use a separate dynamic data channel, so default session synchronisation alone cannot preserve them across failover. Configuring an application layer gateway makes the firewall inspect and synchronise the FTP control and data channels, keeping existing transfers alive when the passive node takes over.

Why this answer

FTP uses separate control and data channels, and the data channel port is dynamically negotiated via the PORT or PASV command. Without an application layer gateway (ALG) for FTP, the firewall cannot track these dynamic ports, so session synchronization would only replicate the control session, causing data sessions to drop after a failover. Enabling the FTP ALG ensures the firewall inspects FTP commands and creates the necessary pinholes for data sessions, which are then synchronized to the passive peer.

Exam trap

The trap here is that candidates assume session synchronization alone is sufficient for all TCP sessions, overlooking that FTP's dynamic port negotiation requires application-layer inspection to create and sync the data channel sessions.

How to eliminate wrong answers

Option A is wrong because the HA3 link is used for state synchronization and session table updates, but it does not address the protocol-specific issue of FTP's dynamic data ports; session synchronization alone cannot preserve FTP data sessions without ALG support. Option B is wrong because asymmetric routing support handles scenarios where traffic takes different paths inbound and outbound, but it does not solve the problem of FTP data sessions being dynamically negotiated and not tracked by default session sync. Option C is wrong because UDP session synchronization is irrelevant to FTP, which uses TCP for both control and data channels; enabling UDP sync would not help preserve FTP data sessions.

221
Multi-Selectmedium

Which TWO of the following are true regarding Panorama's templates and device groups?

Select 2 answers
A.Device groups can only contain firewalls of the same model.
B.Templates are used to push network configurations such as interfaces, virtual routers, and zones.
C.Templates override device group settings when both are applied.
D.Panorama cannot manage firewalls in different geographic locations.
E.Shared policies are defined in the 'Shared' device group and are inherited by all other device groups.
AnswersB, E

Templates push network-level configuration — interfaces, virtual routers, zones — to managed firewalls, satisfying the stem's requirement for network settings rather than policy. Device groups handle policy objects and rules instead, so this option correctly identifies the configuration layer templates manage within Panorama's hierarchy.

Why this answer

Option B is correct because Panorama templates are specifically designed to push network-level configuration to managed firewalls, including interfaces, virtual routers, zones, and other network settings, which is their primary purpose. Option E is correct because Panorama includes a predefined 'Shared' device group at the top of the device group hierarchy, and policies defined there are inherited by all other device groups below it. Option A is incorrect because device groups can contain firewalls of different models, as long as they run compatible PAN-OS versions; model homogeneity is not required.

Option C is incorrect because templates and device groups operate on different configuration scopes (network vs. policy/objects) and do not override each other in that manner. Option D is incorrect because Panorama can manage firewalls across different geographic locations, which is one of its key centralized-management benefits.

Exam trap

The trap here is confusing the roles of templates and device groups, leading candidates to think templates override device group settings or that device groups are model-specific, when in fact they are independent configuration layers with different purposes.

222
MCQeasy

A network administrator wants to verify if a specific internal IP address (10.1.1.100) is being translated to a public IP when accessing the internet. Which CLI command should be used?

A.show running nat-policy
B.show session all filter source 10.1.1.100
C.show nat rule
D.show address 10.1.1.100
AnswerB

`show session all filter source 10.1.1.100` queries the session table for entries matching that source address, revealing the NAT translation applied to each flow. Because Palo Alto Networks firewalls perform NAT through session-based policy evaluation, the session table holds the source and destination translation details, directly confirming whether 10.1.1.100 is translated to a public IP.

Why this answer

The 'show session all filter source 10.1.1.100' command displays active sessions in the firewall's session table, including the source IP, destination IP, and the translated (NAT) IP addresses. This allows the administrator to verify whether the internal IP 10.1.1.100 is being NATed to a public IP when accessing the internet, as the session table shows both the pre-NAT and post-NAT source addresses.

Exam trap

The trap here is that candidates confuse viewing NAT policy configuration (which shows rules) with viewing active NAT translations (which requires session table inspection), leading them to pick 'show running nat-policy' instead of the session-based command.

How to eliminate wrong answers

Option A is wrong because 'show running nat-policy' displays the configured NAT policy rules, not the active translations or sessions; it shows what should happen, not what is currently happening. Option C is wrong because 'show nat rule' is not a valid CLI command on Palo Alto Networks firewalls; the correct command for viewing NAT rules is 'show running nat-policy' or 'show nat-policy'. Option D is wrong because 'show address 10.1.1.100' is not a valid command; the correct command to view address objects is 'show address' or 'show address-group', and it does not show translation or session information.

223
MCQhard

An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?

A.The firewall's App-ID identified the traffic as a different application than the one specified in the rule
B.The application is not recognized by the firewall and is treated as unknown
C.The security rule is not configured to allow any application
D.The firewall's SSL decryption is misconfigured
AnswerA

App-ID inspects the session and identifies the actual application, which may differ from the one the rule specifies. An 'application mismatch' denial means the detected application does not match the rule's application, so the session is dropped. This satisfies the stem's constraint that the policy allows the expected application.

Why this answer

The 'application mismatch' log reason indicates that the firewall's App-ID engine identified the traffic as a different application than the one specified in the security rule. Even though the rule allows the application you intended, the actual traffic does not match that App-ID signature, so the session is denied. This is a common scenario when the application classification does not align with the rule's application object.

Exam trap

The trap here is that candidates often assume 'application mismatch' means the application is unknown or unsupported, but it specifically means the traffic was identified as a different application than what the rule expects, highlighting the importance of verifying App-ID results versus rule configuration.

How to eliminate wrong answers

Option B is wrong because 'application mismatch' is a specific denial reason that occurs when the traffic is recognized but as a different application, not when it is unknown (unknown traffic would show 'unknown-tcp' or 'incomplete' App-ID). Option C is wrong because the scenario explicitly states the security policy allows the application, so the rule is configured to allow an application; the issue is a mismatch, not a missing 'any' application. Option D is wrong because SSL decryption misconfiguration would cause decryption errors or 'ssl-decrypt' related drops, not an 'application mismatch' denial; App-ID can still match encrypted traffic based on metadata or SNI.

224
MCQeasy

A firewall administrator is troubleshooting why a user is unable to access a website. The administrator checks the traffic logs and sees that the session was allowed by the security policy, but the application is identified as 'ssl' instead of 'web-browsing'. The website uses HTTPS on port 443. What is the most likely reason for the application being identified as 'ssl'?

A.The security policy rule is set to allow 'ssl' but not 'web-browsing', so the application is identified as 'ssl'.
B.The website uses a non-standard port for HTTPS, so the firewall cannot identify it as 'web-browsing'.
C.The firewall's application database is outdated and does not recognize 'web-browsing' over SSL.
D.The firewall is not configured to decrypt SSL traffic, so it cannot identify the application as 'web-browsing'.
AnswerD

Without SSL decryption, the firewall can only see the SSL handshake and cannot inspect the HTTP headers to identify the application as 'web-browsing'. The application will be identified as 'ssl' because it is encrypted. This is expected behavior when decryption is not enabled, and it does not necessarily mean the user cannot access the website.

Why this answer

The application is identified as 'ssl' because the traffic is encrypted and the firewall cannot inspect the HTTP headers without SSL decryption. To identify 'web-browsing', the firewall must decrypt the traffic. This is expected behavior when decryption is not configured.

The other options are less likely because the port is standard, the policy does not dictate application identification, and the database is not indicated as outdated.

Exam trap

The trap here is assuming that the firewall can always identify 'web-browsing' even without decryption, when in fact encrypted traffic is identified as 'ssl'.

225
MCQmedium

The security policy rule shown in the exhibit has log-start and log-end both set to 'no', but a log-forwarding profile is configured. Which statement best describes the logging behavior for sessions matching this rule?

A.Sessions are logged only if the session duration exceeds a threshold.
B.Sessions are logged to Panorama immediately when the session starts.
C.Sessions are not logged because logging is disabled.
D.Sessions are logged to Panorama only when the session ends.
AnswerC

Log forwarding only sends traffic, threat and URL logs generated by the session; it cannot create logs that the security policy rule itself does not produce. With log-start and log-end both disabled, no session logs are generated for forwarding.

Why this answer

When both log-start and log-end are set to 'no' in a security policy rule, session logging is disabled regardless of any log-forwarding profile attached. The log-forwarding profile only specifies where logs are sent if logging is enabled; it does not override the explicit logging disable. Therefore, no session logs are generated for this rule.

Exam trap

The trap here is that candidates assume a log-forwarding profile overrides the log-start/log-end settings, but in PAN-OS, the profile only forwards logs that are already enabled by those flags.

How to eliminate wrong answers

Option A is wrong because there is no threshold-based logging behavior in PAN-OS; logging is either enabled or disabled per rule. Option B is wrong because log-start being set to 'no' means no logs are generated at session start, and the log-forwarding profile cannot enable logging on its own. Option D is wrong because log-end being set to 'no' prevents end-of-session logging, and the log-forwarding profile does not activate logging when logging is disabled.

Page 2

Page 3 of 5

Page 4

All pages