Courseiva

Palo Alto Networks Certified Network Security Engineer PCNSE (PCNSE) — Questions 226–300

319 questions total · 5pages · All types, answers revealed

Page 3

Page 4 of 5

Page 5
226
MCQhard

A network security engineer is investigating why a firewall's dataplane CPU is consistently at 95%. After reviewing the session table, they notice a large number of sessions in a 'discard' state. Which action should the engineer take first to resolve the high CPU utilization?

A.Reduce the TCP handshake timeout value.
B.Check the security policy for a rule that denies traffic without sending a response.
C.Increase the session timeout for TCP sessions.
D.Enable hardware offload for session setup.
AnswerB

Sessions in a discard state often result from a security policy rule with an action of 'deny' and no notification to the client, such as a 'drop' action. When the firewall silently drops packets, sessions may linger until they time out, consuming resources. Reviewing the security policy to identify such rules and adjusting them to send a reset or ICMP unreachable can clear sessions faster and reduce CPU load.

Why this answer

Sessions in a discard state are often caused by a security policy rule that silently drops traffic without sending a response. This can lead to a large number of sessions lingering in the session table, consuming dataplane CPU. Reviewing and adjusting the security policy to send resets or ICMP unreachable messages can help clear these sessions more quickly and reduce CPU utilization.

Exam trap

The trap here is assuming that session timeouts or hardware offload are the primary causes of high CPU due to discard sessions.

227
MCQeasy

A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?

A.The URL is not allowed in the decryption policy.
B.The user's browser proxy settings are incorrect.
C.The application uses certificate pinning which rejects the firewall's decryption certificate.
D.The firewall's decryption is causing excessive latency.
AnswerC

Certificate pinning hard-codes the expected server certificate or public key within the application, so the firewall's re-signed certificate fails validation and the connection is dropped. This directly explains the partial loading described, where pinned resources break while unpinned content still loads after SSL decryption is enabled.

Why this answer

Certificate pinning is a security mechanism where an application embeds the exact certificate or public key of the server it expects to communicate with. When SSL decryption is enabled, the firewall replaces the original server certificate with its own decryption certificate. The application detects this mismatch and rejects the connection, causing it to fail to load completely.

This is a common issue with applications that implement strict certificate pinning, such as banking apps or certain mobile applications.

Exam trap

The trap here is that candidates often confuse certificate pinning with general certificate validation or assume that any decryption policy misconfiguration (like URL filtering) is the cause, rather than recognizing the specific application-level security mechanism that explicitly rejects the firewall's decryption certificate.

How to eliminate wrong answers

Option A is wrong because the URL being allowed or not in the decryption policy controls whether decryption is applied, but does not cause partial loading failures; if the URL is not allowed, decryption is simply not performed and the traffic passes through normally. Option B is wrong because incorrect browser proxy settings would typically cause a complete failure to reach any HTTPS sites, not selective failures with specific web applications after SSL decryption is enabled. Option D is wrong while excessive latency can degrade performance, it would not cause web applications to fail to load completely; the failure is due to certificate validation rejection, not timing out.

228
MCQmedium

A security administrator is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for a specific user group. The administrator creates a decryption policy with source user group 'Finance', destination any, and action 'ssl-forward-proxy'. However, after committing, users in the Finance group report that they can still access HTTPS sites without any certificate warnings, and the firewall logs show no decryption. The administrator verifies that the decryption policy is placed correctly and that the forward trust certificate is installed and trusted by the clients. What is the most likely reason decryption is not occurring?

A.The user group 'Finance' is not properly mapped to IP addresses via User-ID, so the policy does not match.
B.The decryption policy action should be 'ssl-inbound-inspection' instead of 'ssl-forward-proxy'.
C.The decryption policy is missing a service definition for HTTPS.
D.The forward trust certificate is not installed on the firewall.
AnswerA

Decryption policies can use user groups as source criteria. For the policy to match, the firewall must know which IP addresses correspond to users in the 'Finance' group. This requires User-ID to be configured and functioning, mapping users to IPs. If User-ID is not enabled or the group mapping is not present, the policy will not match, and traffic will not be decrypted. The lack of certificate warnings and no decryption logs indicate the policy is not being applied.

Why this answer

Decryption policies that use user groups require User-ID to map users to IP addresses. If User-ID is not configured or the group mapping is missing, the policy will not match, and traffic will not be decrypted. The absence of certificate warnings and decryption logs supports this.

Other options are less likely because the service is typically 'any', the certificate is verified as installed, and the action is correct for outbound decryption.

Exam trap

The trap here is assuming that decryption policies based on user groups work without User-ID; the firewall cannot enforce user-based policies without proper user mapping.

229
MCQmedium

An engineer wants to block the use of file-sharing application BitTorrent, but allow file transfers over SFTP which also uses port 22. What is the most effective way to achieve this using App-ID?

A.Create an application filter that matches sftp.
B.Use QoS to limit BitTorrent traffic.
C.Use an application override to classify all port 22 traffic as sftp.
D.Create a security rule that denies application 'bittorrent' and allows application 'sftp'.
AnswerD

App-ID classifies by application signature, not port, so a single rule can deny bittorrent while allowing sftp even though both may traverse port 22. This satisfies the requirement to block BitTorrent without disrupting legitimate SFTP transfers.

Why this answer

D is correct because App-ID identifies applications by their unique signatures, not just ports. By creating a security rule that denies 'bittorrent' and allows 'sftp', the firewall can block BitTorrent traffic even if it uses non-standard ports, while permitting SFTP on port 22 based on its distinct application signature.

Exam trap

The trap here is that candidates assume port-based rules are sufficient, but App-ID is designed to identify applications by their unique signatures, not ports, so a port-based approach (like an application override) would fail to block BitTorrent if it uses the same port as SFTP.

How to eliminate wrong answers

Option A is wrong because an application filter that matches 'sftp' would only allow SFTP traffic but would not block BitTorrent; it does not deny the unwanted application. Option B is wrong because QoS only prioritizes or limits bandwidth for BitTorrent traffic, it does not block it, leaving the application accessible. Option C is wrong because an application override forces all port 22 traffic to be classified as 'sftp', which would incorrectly allow BitTorrent if it also uses port 22, defeating the purpose of blocking it.

230
MCQeasy

A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?

A.Confirm that the proxy IDs are correctly configured on both peers.
B.Verify that the IPsec crypto profile uses the same encryption algorithm as the peer.
C.Check the IKE Phase 1 and Phase 2 status to ensure the tunnel is fully established.
D.Verify that the security policy allows traffic from the tunnel zone to the internal zone.
AnswerD

In a route-based VPN, traffic entering the tunnel interface is associated with a security zone. A security policy must permit traffic from the tunnel zone to the destination zone. If the policy is missing or incorrect, traffic will be dropped even though the tunnel is up and routes are correct. Checking the security policy is a fundamental troubleshooting step.

Why this answer

When a route-based VPN tunnel is up and routes are correct, the next troubleshooting step is to check security policies. Traffic entering the tunnel interface is subject to security policy rules based on the tunnel zone. If no rule permits the traffic, it will be dropped.

Other options like rechecking tunnel status or crypto profiles are unnecessary because the tunnel is already established.

Exam trap

The trap here is continuing to focus on VPN tunnel parameters such as proxy IDs or crypto profiles, even though the tunnel is already up, instead of moving to policy and routing checks that affect traffic flow.

231
MCQhard

An organization has deployed GlobalProtect with certificate authentication. Users on macOS report that after updating their client, they cannot connect and see error 'Certificate validation failed: The certificate hash does not match.' What is the most likely cause?

A.The certificate pinning configuration on the gateway has a hash mismatch
B.The root CA certificate is not trusted on the client
C.The CRL is not reachable
D.The GlobalProtect gateway certificate is expired
AnswerA

Certificate pinning enforces specific hash; client update may change the hash.

Why this answer

The error 'Certificate validation failed: The certificate hash does not match' specifically indicates a certificate pinning mismatch. GlobalProtect certificate pinning allows the gateway to enforce that the client's certificate matches a specific hash (SHA-256 fingerprint). When the client updates, its certificate may change (e.g., due to a new key pair or renewal), causing the hash stored in the gateway's pinning configuration to no longer match, resulting in this exact error.

Exam trap

The trap here is that candidates often confuse certificate pinning failures with general certificate validation issues (like trust or expiry), but the specific error message 'certificate hash does not match' is unique to pinning and not to standard PKI validation steps.

How to eliminate wrong answers

Option B is wrong because if the root CA certificate were not trusted on the client, the error would typically be 'untrusted root' or 'certificate not trusted', not a hash mismatch. Option C is wrong because an unreachable CRL would cause a revocation check failure (e.g., 'CRL not available' or 'certificate revoked'), not a hash mismatch. Option D is wrong because an expired gateway certificate would produce an 'expired certificate' error, not a hash mismatch; the hash mismatch error is specific to the client certificate's fingerprint not matching the pinned value.

232
MCQeasy

An administrator wants to view real-time CPU and memory usage on the firewall. Which CLI command should be used?

A.show system info
B.show routing route
C.show log system
D.show system resources
AnswerD

show system resources displays real-time CPU utilisation, memory usage and load averages for the firewall's dataplane and management plane. It satisfies the administrator's requirement to view live CPU and memory consumption directly from the CLI.

Why this answer

The 'show system resources' command displays real-time CPU and memory utilization on a Palo Alto Networks firewall, including load averages, memory usage, and process-level details. This is the correct command for monitoring live resource consumption, as opposed to static system information or logs.

Exam trap

The trap here is that candidates confuse 'show system info' (static system details) with 'show system resources' (dynamic resource usage), as both commands start with 'show system' and seem related to system health.

How to eliminate wrong answers

Option A is wrong because 'show system info' displays static system information such as model, serial number, software version, and uptime, not real-time CPU or memory usage. Option B is wrong because 'show routing route' displays the routing table entries, which is unrelated to system resource monitoring. Option C is wrong because 'show log system' displays system event logs (e.g., configuration changes, alarms), not real-time CPU or memory metrics.

233
MCQeasy

A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?

A.SSL Inbound Inspection
B.App-ID with TLS 1.3 only
C.DNS Sinkhole
D.SSL Forward Proxy decryption
AnswerD

SSL Forward Proxy decryption allows the firewall to intercept and decrypt outbound TLS sessions, inspect the ClientHello and server certificate, and apply App-ID to the decrypted traffic. This enables identification of applications that use HTTPS on port 443, such as sanctioned SaaS apps, by examining the actual application payload and certificate attributes rather than just the port.

Why this answer

To differentiate applications that both use HTTPS on port 443, the firewall must decrypt the traffic and inspect the TLS handshake and certificate. SSL Forward Proxy decryption enables this by acting as a man-in-the-middle for outbound connections, allowing App-ID to identify the application based on its unique characteristics. This is the correct approach for identifying sanctioned SaaS applications.

Exam trap

The trap here is assuming that App-ID can identify all HTTPS applications without decryption, when in fact many applications require SSL Forward Proxy decryption to be properly identified.

234
MCQhard

Refer to the exhibit. Based on the log entry, what action was taken on this traffic?

A.The traffic was allowed with a reset.
B.The action could not be determined.
C.The traffic was dropped.
D.The traffic was allowed and logged.
AnswerC

The log records a drop action, meaning the firewall's security policy denied the session and no packet was forwarded to its destination. This satisfies the stem's requirement to identify the action taken on the exhibited traffic.

Why this answer

The log entry shows the action field as 'drop', which indicates the firewall denied the traffic. In Palo Alto Networks firewalls, a 'drop' action means the packet was silently discarded without sending a TCP reset or ICMP unreachable message. Therefore, option C is correct.

Exam trap

Palo Alto Networks often tests the distinction between 'drop' and 'reset' actions, where candidates may mistakenly assume a dropped packet generates a TCP reset, but in Palo Alto firewalls, 'drop' is silent and 'reset' explicitly sends RST packets.

How to eliminate wrong answers

Option A is wrong because 'reset' would appear in the action field as 'reset-both', 'reset-client', or 'reset-server', not 'drop'. Option B is wrong because the action is explicitly logged as 'drop', so it can be determined. Option D is wrong because 'allow' would appear as 'allow' in the action field, and the traffic was dropped, not allowed.

235
MCQeasy

A security administrator needs to configure the firewall to send an email alert whenever a critical threat is detected. The administrator wants to ensure that the email includes the threat details and is sent immediately. Which configuration step is required to achieve this?

A.Enable SNMP traps on the firewall and configure the management server to receive them.
B.Configure a Syslog server profile and assign it to the security policy to receive threat logs.
C.Configure an Email profile in Device > Server Profiles > Email and assign it to the security policy that detects the threat.
D.Create a Log Forwarding profile that includes an email server profile and attach it to the security policy that detects the threat.
AnswerD

A Log Forwarding profile specifies where to send logs, including email. By attaching it to the security policy, the firewall will forward threat logs via email as soon as they are generated. This ensures immediate notification with threat details included in the email body.

Why this answer

To send email alerts for critical threats, the administrator must configure a Log Forwarding profile that includes an Email server profile and apply it to the security policy. This ensures that when a threat is detected, the corresponding threat log is forwarded via email immediately, including all relevant details.

Exam trap

The trap here is confusing the Email server profile with the Log Forwarding profile; the Email server profile alone does not trigger alerts without being referenced in a Log Forwarding profile attached to a policy.

236
MCQeasy

A firewall administrator is configuring a new security zone for a DMZ. The requirement is that the DMZ zone should not be able to initiate connections to the internal trusted zone, but the trusted zone should be able to initiate connections to the DMZ. Which configuration achieves this with the least administrative effort?

A.Assign the DMZ interface to the same zone as the trust interface, and use security policies to control traffic between them.
B.Create a security policy from trust to DMZ allowing the required applications, and rely on the implicit deny for DMZ to trust.
C.Create two security policies: one from trust to DMZ allowing all applications, and one from DMZ to trust denying all applications.
D.Configure the DMZ zone with a zone protection profile that blocks all traffic from the DMZ to the trust zone.
AnswerB

The firewall's default behavior is to deny interzone traffic unless explicitly allowed. By creating only the trust-to-DMZ allow policy, the administrator leverages the implicit deny rule to block DMZ-to-trust traffic. This is the simplest and most efficient configuration, requiring only one policy.

Why this answer

The default security posture of a Palo Alto Networks firewall is to deny all interzone traffic except intrazone traffic. By creating only the necessary allow rule from trust to DMZ, the administrator ensures that the trusted zone can initiate connections to the DMZ, while the DMZ cannot initiate connections to the trust zone because of the implicit deny. This minimizes configuration and reduces the risk of misconfiguration.

Exam trap

The trap here is believing that an explicit deny rule is required to block traffic between zones, when the implicit deny already handles it.

237
MCQhard

Based on the exhibit, what is the most likely cause of the warnings?

A.The HA3 link is misconfigured
B.Configuration synchronization is failing
C.Both the primary and backup HA2 links are down
D.The HA2 keepalive timer is set too low
AnswerC

Warnings for both indicate link failure.

Why this answer

The exhibit shows warnings indicating that both the primary and backup HA2 links are down. HA2 is the control link used for session synchronization and configuration state exchange in an active/passive or active/active firewall pair. When both HA2 links fail, the firewalls cannot synchronize session tables, leading to warnings about potential asymmetric traffic and failover issues.

Option C correctly identifies this as the most likely cause.

Exam trap

The trap here is that candidates often confuse HA2 (control link) with HA3 (data link) or assume that a single link failure is the cause, but the exhibit explicitly shows warnings for both primary and backup HA2 links being down, making C the only correct answer.

How to eliminate wrong answers

Option A is wrong because the HA3 link is the dataplane link used for forwarding traffic in active/active mode or for asymmetric routing; misconfiguration of HA3 would cause traffic forwarding issues, not the specific warnings shown. Option B is wrong because configuration synchronization failing would typically generate a different set of warnings related to config mismatch or sync failure, not the HA2 link down warnings. Option D is wrong because the HA2 keepalive timer being set too low would cause flapping or false failovers, but the exhibit shows persistent warnings indicating the links are down, not intermittent keepalive failures.

238
MCQeasy

By default, what is the action on traffic between two different zones without any security rule?

A.deny
B.allow
C.depends on the application
D.prompt
AnswerA

Inter-zone traffic is governed by security policy, and PAN-OS applies an implicit deny when no rule matches, so packets crossing from one zone to another are dropped. This default satisfies the scenario's constraint of no configured security rule, unlike intra-zone traffic, which the implicit allow permits by default.

Why this answer

By default, Palo Alto Networks firewalls implement an implicit deny rule for inter-zone traffic. This means that if no security rule explicitly matches traffic between two different zones, the firewall drops the packet and logs it as a deny action. This default behavior ensures that all cross-zone traffic must be explicitly allowed by a security policy, enforcing a zero-trust model.

Exam trap

The trap here is that candidates often confuse the default inter-zone action with intra-zone traffic (which is allowed by default) or assume that the firewall will prompt or log a warning, when in fact it silently denies without any user notification.

How to eliminate wrong answers

Option B is wrong because allowing inter-zone traffic by default would violate the principle of least privilege and create a security hole; Palo Alto firewalls never allow traffic without an explicit allow rule. Option C is wrong because the action is not dependent on the application; the firewall applies a default deny regardless of the application ID, and application identification only occurs after a rule match. Option D is wrong because the firewall does not prompt or ask for user input for inter-zone traffic; it silently drops the packet based on the implicit deny rule.

239
MCQeasy

Refer to the exhibit. What does the serial number '0123456789' indicate?

A.The MAC address of the management interface
B.The model number of the firewall
C.The firmware version installed
D.The unique hardware identifier for licensing and support
AnswerD

The serial number uniquely identifies the physical chassis, tying it to its licences, support entitlement and warranty record. It is not an IP address, HA group identifier or software version, so it satisfies the licensing and support-tracking requirement in the exhibit.

Why this answer

The serial number '0123456789' is a unique hardware identifier assigned to each Palo Alto Networks firewall during manufacturing. It is used for licensing, support entitlement, and device identification in the Palo Alto Networks support portal, not for network-level addressing or software versioning.

Exam trap

The trap here is that candidates often confuse the serial number with the model number or MAC address, especially when the exhibit shows a generic string like '0123456789' that lacks the typical format of a Palo Alto Networks serial number (e.g., starting with 'PA' or a specific prefix).

How to eliminate wrong answers

Option A is wrong because the MAC address of the management interface is a separate, network-layer identifier used for Layer 2 communication, not the serial number. Option B is wrong because the model number (e.g., PA-5250) is a different alphanumeric string that identifies the hardware platform, not the unique serial number. Option C is wrong because the firmware version (e.g., PAN-OS 10.2.3) is a software release identifier displayed in the dashboard or CLI, not the hardware serial number.

240
MCQhard

A firewall administrator is troubleshooting an issue where a PA-3260 is experiencing high dataplane CPU utilization. The administrator runs 'show running resource-monitor' and sees that the CPU is consistently above 90%. Which command should the administrator use to identify the top applications contributing to the high CPU usage?

A.show system resources
B.show running resource-monitor application
C.show session all filter application
D.show running resource-monitor ingress-backlogs
AnswerB

This command displays resource monitoring statistics per application, including CPU usage. It is specifically designed to show which applications are consuming the most resources, making it ideal for identifying the top applications contributing to high dataplane CPU. It provides a breakdown that helps pinpoint the cause.

Why this answer

The command 'show running resource-monitor application' provides per-application resource utilization, including CPU. This allows the administrator to see which applications are consuming the most dataplane CPU. Other commands like 'show system resources' give overall usage, and 'show session all filter application' lists sessions but not CPU impact.

The ingress-backlogs command is for queue monitoring, not CPU attribution.

Exam trap

The trap here is confusing overall system resource monitoring with per-application resource monitoring, which is needed to attribute CPU usage to specific applications.

241
Multi-Selecteasy

Which TWO components are part of the PAN-OS management plane?

Select 2 answers
A.SSL decryption engine
B.Packet buffer
C.Log collection and reporting
D.Management interface
E.App-ID engine
AnswersC, D

Log collection and reporting is a management plane function in PAN-OS, handling log ingestion, storage, and report generation. It is distinct from the data plane, which processes traffic, and the control plane, which handles routing and protocol operations.

Why this answer

The PAN-OS management plane handles administrative and control functions rather than the actual data forwarding path. Option C, log collection and reporting, is correct because the management plane is responsible for gathering logs from the dataplane and generating reports, which administrators access via the management interface or external log collectors. Option D, the management interface, is correct because it is the dedicated out-of-band interface (typically MGT) used for administrative access such as SSH, HTTPS/WebUI, and API, and it belongs to the management plane.

The other options do not belong: the SSL decryption engine (A) and App-ID engine (E) are dataplane security processing functions that inspect and classify traffic, and the packet buffer (B) is a dataplane memory resource used for queuing and forwarding packets, not a management-plane component.

Exam trap

The trap here is that candidates often confuse data plane functions (like SSL decryption, App-ID, and packet buffering) with management plane responsibilities, leading them to select options A, B, or E instead of recognizing that log collection and the management interface are purely management plane components.

242
MCQeasy

A company is deploying GlobalProtect for remote users and wants to enforce that only users with valid certificates are allowed to connect. Which configuration is required on the GlobalProtect gateway?

A.Define a tunnel interface with an IP address that matches the certificate subject
B.Set the gateway's IP pool to require certificate authentication
C.Configure a certificate profile in the gateway's authentication settings
D.Configure client authentication in the portal with a certificate profile
AnswerC

A certificate profile bound to the gateway's authentication settings makes the firewall validate the client certificate chain against the specified trusted CA, rejecting connections without a valid certificate. This enforces certificate-based authentication for GlobalProtect remote users.

Why this answer

A certificate profile must be configured in the gateway's authentication settings to enforce certificate-based authentication. This profile defines the trusted Certificate Authority (CA) and validation criteria (e.g., CRL checking, OCSP), ensuring only clients presenting a valid certificate issued by that CA can establish a GlobalProtect tunnel. Without this, the gateway would fall back to username/password or other configured authentication methods.

Exam trap

The trap here is that candidates often confuse portal authentication settings with gateway authentication settings, assuming that configuring a certificate profile on the portal will automatically enforce certificate-based access on the gateway, but the gateway requires its own separate authentication configuration.

How to eliminate wrong answers

Option A is wrong because a tunnel interface IP address does not need to match the certificate subject; the certificate subject is used for identity mapping, not for IP assignment. Option B is wrong because the IP pool is used for assigning client IP addresses from a defined range, not for requiring certificate authentication; certificate enforcement is handled separately in the authentication profile. Option D is wrong because client authentication in the portal controls web-based access to the portal interface, not the gateway tunnel; gateway authentication settings are independent and must be configured directly on the gateway.

243
MCQmedium

An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?

A.The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.
B.The security rule is missing a service definition; the application 'any' does not automatically include all services.
C.The security rule is missing an application override because the server's traffic is not being identified correctly.
D.The security rule is missing a destination zone; the firewall requires a destination zone to be specified for outbound traffic.
AnswerA

When a server with a private IP address (10.10.10.5) initiates traffic to the internet, the firewall must perform source NAT to translate the private IP to a public IP. Without a NAT rule, the packet is forwarded with the private source IP, which is not routable on the internet. Return traffic would be dropped by upstream routers. The security rule alone does not provide address translation; a NAT policy is required.

Why this answer

For a server with a private IP address to access the internet, the firewall must perform source NAT to translate the private IP to a routable public IP. Without a NAT rule, return traffic cannot be routed back to the server. The security rule permits the traffic, but NAT is a separate configuration.

The other options are less likely because application 'any' does not require a service, application override is not needed for basic connectivity, and the destination zone is typically part of the rule.

Exam trap

The trap here is assuming that a security rule allowing traffic is sufficient for outbound internet access, forgetting that source NAT is required for private IP addresses.

244
MCQmedium

A security administrator is troubleshooting why a custom application that uses SSL/TLS on TCP port 9443 is being identified as 'ssl' instead of the custom App-ID. The firewall has a security policy that allows 'ssl' and the custom application. The administrator has already confirmed that the traffic passes through the firewall and that SSL decryption is not enabled. Which action should the administrator take to allow App-ID to correctly identify the application?

A.Enable SSL decryption on the firewall to inspect the encrypted traffic.
B.Modify the security policy to allow only the custom application and remove the 'ssl' rule.
C.Create a custom App-ID signature for the application using the known SSL/TLS attributes.
D.Configure the firewall to use the 'ssl' application as a dependency for the custom application.
AnswerC

Creating a custom App-ID signature is the correct approach when an application uses SSL/TLS and cannot be identified by existing signatures. The administrator can define a custom signature based on SSL/TLS attributes such as server certificate CN, issuer, or other TLS handshake characteristics. This allows the firewall to recognize the application without decrypting traffic, which aligns with the scenario where SSL decryption is not enabled.

Why this answer

When an application uses SSL/TLS and the firewall cannot identify it beyond 'ssl', a custom App-ID signature based on SSL/TLS attributes is the appropriate solution without decryption. This allows the firewall to match the application based on certificate details or other handshake information. Enabling decryption is not necessary and may not be desired.

Removing the 'ssl' rule or using dependencies does not address the identification problem.

Exam trap

The trap here is assuming that SSL decryption is always required to identify applications using SSL/TLS, when in fact App-ID can use SSL/TLS fingerprints and custom signatures without decryption.

245
MCQhard

A security team needs to capture traffic for forensic analysis of a specific application that uses non-standard ports. The administrator wants to capture packets on the firewall for that application only, without affecting performance. Which method should be used?

A.Set up a port mirror on the upstream switch
B.Create an application override policy
C.Configure a PCAP filter in the firewall's packet capture feature
D.Use tcpdump on the management interface
AnswerC

A PCAP filter narrows capture to traffic matching the application's specific ports and addresses, so only relevant packets are recorded. This satisfies the requirement to target the non-standard-port application without the performance overhead of capturing all traffic.

Why this answer

The firewall's built-in packet capture feature with a PCAP filter allows the administrator to capture only traffic matching specific criteria (e.g., application, source/destination IP, port) directly on the data plane, without impacting overall performance. This is the correct method because it isolates the target application's traffic for forensic analysis without requiring external devices or altering traffic flow.

Exam trap

The trap here is that candidates confuse a management-plane tool (tcpdump on the management interface) with a data-plane capture, or they assume port mirroring is the only way to capture traffic, overlooking the firewall's native, performance-friendly PCAP filter feature.

How to eliminate wrong answers

Option A is wrong because port mirroring on an upstream switch copies all traffic from the monitored port, not just the specific application, and it introduces additional load on the switch and firewall, potentially affecting performance. Option B is wrong because an application override policy changes how the firewall identifies and handles the application (e.g., by specifying a custom port), but it does not capture or log packet-level data for forensic analysis. Option D is wrong because tcpdump on the management interface only captures traffic destined to or originating from the management plane, not the data-plane traffic flowing through the firewall's forwarding path.

246
MCQeasy

A user reports that they cannot access a specific website. The firewall security policy allows web traffic. The administrator checks the traffic log and sees that the session is being denied due to a 'URL Filtering' block. What should the administrator do to allow access?

A.Disable URL filtering on the existing security rule
B.Check the user-ID mapping to ensure the user is authenticated
C.Create a new security rule allowing the user's IP to any
D.Add the URL to an allow list in the URL filtering profile
AnswerD

The traffic log shows the session denied by URL Filtering rather than the security policy, so the URL category is blocked in the URL filtering profile. Adding the specific URL to the allow list in that profile permits access while the security policy remains unchanged.

Why this answer

The traffic log explicitly indicates a 'URL Filtering' block, meaning the firewall's URL filtering profile is denying the request based on the URL category or specific URL. Adding the URL to an allow list within the URL filtering profile overrides the block, allowing access while keeping the security rule and other filtering policies intact. This approach preserves security controls for other traffic and avoids disabling URL filtering entirely.

Exam trap

The trap here is that candidates may assume disabling URL filtering entirely (Option A) is the quickest fix, but the PCNSE exam tests the understanding that URL filtering profiles should be modified granularly using allow/block lists rather than disabling the feature completely.

How to eliminate wrong answers

Option A is wrong because disabling URL filtering on the existing security rule would remove all URL-based controls for that rule, potentially exposing the network to malicious or inappropriate websites, which is an overreaction to a single blocked URL. Option B is wrong because the user-ID mapping is irrelevant to a URL filtering block; URL filtering decisions are based on the URL category or list, not user authentication status, and the traffic log already shows the session is denied due to URL filtering, not authentication. Option C is wrong because creating a new security rule allowing the user's IP to any would bypass all security policies, including URL filtering, but it is an insecure and overly permissive solution that ignores the specific URL filtering block and could allow unrestricted access to any destination.

247
Multi-Selecthard

A security administrator is designing a zero-trust architecture using Palo Alto Networks firewalls. They want to ensure that traffic between two internal zones is inspected and that access is granted based on user identity and device posture rather than IP address alone. Which two PAN-OS features must be implemented to meet these requirements? (Choose two.)

Select 2 answers
A.Enable App-ID to identify applications regardless of port or protocol.
B.Configure User-ID to map users to IP addresses via GlobalProtect or AD agent.
C.Deploy GlobalProtect with HIP profiles to assess device posture.
D.Configure a DNS sinkhole to block malicious domains.
E.Enable SSL decryption to inspect encrypted traffic.
AnswersB, C

User-ID is essential for enforcing policy based on user identity rather than IP. By integrating with Active Directory or GlobalProtect, the firewall learns which user is associated with each IP address. Security policies can then reference users or groups directly. This is a core requirement for zero-trust because it ensures that access decisions are tied to authenticated identity, not just network location, and it enables dynamic policy that follows the user.

Why this answer

Zero-trust access based on user identity and device posture requires User-ID to map users to IP addresses and GlobalProtect with HIP profiles to assess endpoint compliance. User-ID provides the identity context, while HIP provides posture context. Together, they allow security policies to grant or deny access based on both who the user is and the security state of their device, which is the essence of zero-trust.

Exam trap

The trap here is confusing inspection features like App-ID or SSL decryption with identity and posture features, when only User-ID and HIP provide the required context for zero-trust access decisions.

248
MCQhard

A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?

A.The firewall must be rebooted for the custom App-ID to take effect.
B.An application override rule has not been configured to associate the traffic with the custom App-ID.
C.The custom App-ID must be enabled in the 'Applications' section of the firewall settings.
D.The firewall cannot identify applications over UDP.
AnswerB

Application override is required to bypass signature-based identification and assign the custom App-ID.

Why this answer

The custom App-ID is correctly configured and committed, but the firewall still does not identify the traffic because App-IDs are based on application signatures and behavioral analysis. For a proprietary protocol over UDP, the firewall may not have a signature to match it, so an application override rule is required to explicitly associate the traffic (based on IP, port, or protocol) with the custom App-ID. Without this override, the firewall will continue to treat the traffic as unknown or attempt to match it against built-in App-IDs.

Exam trap

The trap here is that candidates assume a correctly configured custom App-ID will automatically identify traffic, but they overlook the need for an Application Override rule to explicitly bind the traffic to that App-ID when the firewall cannot match it via signatures.

How to eliminate wrong answers

Option A is wrong because rebooting the firewall is unnecessary; custom App-IDs take effect immediately after commit, not requiring a reboot. Option C is wrong because custom App-IDs are not enabled in a separate 'Applications' section; they are created and applied via Security policy rules or Application Override rules. Option D is wrong because Palo Alto Networks firewalls can identify applications over UDP; App-ID supports both TCP and UDP protocols, and the issue is specifically about the lack of a signature for this proprietary protocol.

249
MCQeasy

A network administrator is reviewing the firewall's logs and notices that many sessions are being denied by the security policy. The administrator wants to quickly identify the top source IP addresses that are being denied. Which feature in the PAN-OS web interface should the administrator use to accomplish this?

A.The Application Command Center (ACC) with a filter for denied traffic.
B.The Traffic log with a filter for denied sessions and then sorting by source IP.
C.The Threat log with a filter for denied traffic.
D.The Session Browser with a filter for denied sessions.
AnswerB

The Traffic log displays all session details. By filtering for denied sessions (e.g., action eq deny) and then sorting or using the log viewer's aggregation feature to group by source IP, the administrator can quickly see the top source IP addresses. This is the most direct and efficient method to identify top denied sources from the log data.

Why this answer

The Traffic log records all sessions, including those denied by security policy. By applying a filter for denied actions and then using the log viewer's aggregation or sorting capabilities, the administrator can quickly identify the top source IP addresses. This is a standard operational task in PAN-OS.

Other logs or tools do not provide the same direct access to denied session data.

Exam trap

The trap here is confusing the Threat log with the Traffic log; denied sessions by policy are not threats and are only in the Traffic log.

250
Drag & Dropmedium

Arrange the steps to configure a new administrator account with role-based access.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a new administrator with role-based access on a Palo Alto firewall, you must first create the administrator account by navigating to Device > Administrators and clicking Add. Then enter the username and password. Next, assign a role (e.g., Superuser, Read‑Only, or a custom role) to define the access level.

Finally, commit the changes to apply the configuration. This sequence ensures the account is fully defined before committing.

251
MCQmedium

An administrator is configuring HA on a pair of PA-5220 firewalls. They want to ensure that the HA1 link is redundant and can survive a single link failure. Which configuration should they use?

A.Configure HA1 on a dedicated interface and enable HA1 backup.
B.Configure HA1 on an aggregate interface (AE) with multiple physical links.
C.Configure HA1 on a loopback interface and enable BFD.
D.Configure HA1 on a VLAN interface and enable LACP.
AnswerA

HA1 backup allows the configuration of a secondary HA1 link on a different interface. If the primary HA1 link fails, the backup takes over, providing redundancy. This is a best practice for HA1 to avoid a single point of failure. The firewall supports HA1 backup on a separate interface, which can be a physical port or an aggregate interface.

Why this answer

HA1 backup allows a secondary HA1 link to be configured on a different interface. If the primary HA1 link fails, the backup link is used, ensuring control link redundancy. This is the recommended configuration for HA1 redundancy.

Exam trap

The trap here is thinking that link aggregation on HA1 provides redundancy, but HA1 backup is the supported and recommended method.

252
MCQhard

A security team uses Panorama to push policy to 40 managed firewalls. An administrator commits a policy change from Panorama, and the commit succeeds on Panorama but fails on 12 firewalls with a validation error. The administrator wants to identify which firewalls failed and the specific error each reported without opening each device individually. Which Panorama feature should the administrator use?

A.The Config Audit under the Panorama tab, which compares the candidate configuration to the running configuration on each device.
B.The Log Collector group configuration, which aggregates commit-related system logs from all managed firewalls into one searchable view.
C.The Managed Devices summary under the Panorama tab, which shows the connection status and software version of each firewall.
D.The Task Manager under the Panorama tab, which lists commit job results and per-device error details for the pushed changes.
AnswerD

Panorama's Task Manager records each commit job, its scope, and the outcome for every managed device. When a pushed commit fails validation on individual firewalls, the job details list the affected devices and the specific error returned by each, allowing centralized troubleshooting without logging into every firewall individually. This is the intended workflow for this scenario.

Why this answer

Panorama pushes configuration to managed devices as commit jobs, and the Task Manager retains the result of each job, including which devices succeeded and which failed along with the error each returned. Reviewing the job detail centrally avoids logging into each firewall. Config Audit, Managed Devices status, and Log Collector aggregation serve different purposes and do not present per-device commit validation failures.

Exam trap

The trap here is assuming that a successful commit on Panorama means the policy applied everywhere, when per-device validation can still fail and is only visible in the commit job results.

253
MCQmedium

A network engineer is configuring HA on a pair of PA-5220 firewalls. The company requires that the HA1 control link be secured and that the firewalls authenticate each other. Which action should the engineer take?

A.Use the management interface for HA1 traffic and enable SSL/TLS encryption on the management plane.
B.Configure the HA1 link to use IPsec by creating a tunnel between the management interfaces.
C.Enable HA1 encryption by setting a pre-shared key in the HA configuration.
D.Enable HA1 encryption by selecting the 'Encrypt HA1' checkbox and generating a self-signed certificate.
AnswerC

Setting a pre-shared key enables encryption of HA1 control traffic and provides mutual authentication between peers. This satisfies both the security and authentication requirements. The pre-shared key is configured under Device > High Availability > General > Control Link. Without it, HA1 messages are sent in clear text and any device could potentially spoof HA messages.

Why this answer

HA1 control link encryption and authentication are achieved by configuring a pre-shared key. This ensures that only the paired firewalls can exchange HA control messages and that the messages are encrypted. The pre-shared key must match on both peers.

This is the standard method to secure HA1 and is a best practice when the HA1 link traverses untrusted networks.

Exam trap

The trap here is assuming that HA1 encryption requires certificates or IPsec, when it is actually enabled by a simple pre-shared key.

254
Drag & Dropmedium

Order the steps to configure a security policy allowing HTTP traffic from the inside to the outside zone.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Configuring a security policy on Palo Alto Networks firewalls involves defining the traffic flow by specifying source and destination zones, then selecting the application and service, setting the action (allow or deny), and finally committing the changes. The correct order ensures logical consistency and proper policy enforcement. Common mistakes include swapping zones, setting action before application, or placing destination after application.

255
Multi-Selecthard

An engineer is configuring HA on a pair of firewalls and wants to ensure that the HA1 link is secure and redundant. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Configure HA1 backup on a separate interface.
B.Enable HA1 link aggregation using LACP.
C.Set the HA1 link to use UDP port 29281.
D.Configure HA2 encryption.
E.Configure HA1 encryption.
AnswersA, E

HA1 backup provides redundancy for the control link. If the primary HA1 link fails, the backup link is used. This ensures that the HA pair remains operational and can still exchange heartbeats and synchronize configuration. It is a recommended practice for high availability.

Why this answer

To secure HA1, enable HA1 encryption. To provide redundancy, configure HA1 backup on a separate interface. These two actions ensure that the control link is both protected and resilient.

Exam trap

The trap here is confusing HA1 and HA2 features; HA2 encryption and aggregation are not applicable to HA1 security and redundancy.

256
MCQmedium

A security engineer needs to deploy a Palo Alto Networks firewall in a high-availability (HA) pair with active/passive mode. The firewall will inspect traffic for multiple tenants, each requiring separate routing and policy configuration. Which feature should be used to isolate tenant configurations while using a single pair of firewalls?

A.Create separate virtual systems (VSYS) for each tenant on the same firewall.
B.Deploy multiple VM-Series firewalls as separate instances on the same hypervisor.
C.Use active/active HA mode to assign each tenant to a different firewall.
D.Configure multiple virtual routers (VRFs) within the same virtual system.
AnswerA

Separate VSYS instances partition a single firewall into independent logical firewalls, each with its own routing table, zones, policies and administrator roles. This satisfies the multi-tenant isolation requirement while retaining one active/passive HA pair, since VSYS share the underlying hardware and failover state.

Why this answer

Virtual systems (VSYS) allow a single Palo Alto Networks firewall to be partitioned into multiple independent logical firewalls, each with its own routing table, security policies, and administrative domains. This enables tenant isolation on a single HA pair without requiring separate hardware or instances, making option A correct for the described requirement.

Exam trap

The trap here is that candidates often confuse virtual routers (VRFs) with full tenant isolation, not realizing that VRFs only separate routing tables, while VSYS provides complete separation of policies, objects, and administration required for multi-tenant environments.

How to eliminate wrong answers

Option B is wrong because deploying multiple VM-Series firewalls as separate instances on the same hypervisor would require separate management and licensing for each instance, defeating the purpose of using a single HA pair and increasing complexity. Option C is wrong because active/active HA mode does not assign tenants to different firewalls; both firewalls in an active/active pair share the same configuration and forward traffic together, so tenant isolation would still require VSYS or other segmentation. Option D is wrong because multiple virtual routers (VRFs) within the same virtual system can separate routing tables but do not isolate security policies, administrative access, or other tenant-specific configurations; VSYS is required for full tenant isolation.

257
MCQeasy

A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?

A.Network > Virtual Routers
B.Policy Optimizer > Test Policy Match
C.Monitor > Logs > Traffic
D.Device > Setup > Management
AnswerB

Policy Optimizer's Test Policy Match simulates a flow against the current ruleset, returning the exact security policy that would apply for specified source, destination, application and port. This directly satisfies the stem's requirement to identify which policy matches 10.0.1.0/24 traffic, exposing any missing or shadowed rule causing the outage.

Why this answer

The 'Test Policy Match' tool under Policy Optimizer allows an administrator to simulate a specific traffic flow (source/destination IP, port, protocol) and see which security policy rule it matches. This directly addresses the need to verify whether a missing or misconfigured policy is blocking internet access for the 10.0.1.0/24 subnet.

Exam trap

The trap here is that candidates often confuse the 'Test Policy Match' tool with traffic logs (Option C), thinking logs can predict future policy matches, but logs only show past events and cannot simulate a flow that hasn't occurred yet.

How to eliminate wrong answers

Option A is wrong because Virtual Routers manage routing tables and next-hop decisions, not security policy matching; it cannot test which security rule applies to a traffic flow. Option C is wrong because Monitor > Logs > Traffic shows historical logs of already-processed traffic, not a proactive test of policy matching for a hypothetical flow. Option D is wrong because Device > Setup > Management configures administrative settings (e.g., management interfaces, authentication) and has no capability to simulate or test security policy matching.

258
Multi-Selecteasy

Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?

Select 2 answers
A.Certificate
B.RADIUS
C.SAML
D.LDAP
E.Pre-shared key
AnswersA, E

Certificate-based authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, using X.509 certificates exchanged during IKE to authenticate peers. This satisfies the scenario's requirement for a supported method, since both firewalls can validate each other's identity via a trusted certificate authority rather than pre-shared keys.

Why this answer

Option A (Certificate) is correct because Palo Alto Networks firewalls support certificate-based authentication for IPSec VPN IKE peers, where each firewall presents an X.509 certificate and validates the peer's certificate against a trusted CA profile during IKE Phase 1. Option E (Pre-shared key) is correct because PSK authentication is a native, commonly used IKE Phase 1 authentication method for site-to-site IPSec tunnels between Palo Alto firewalls, configured under the IKE Gateway's authentication settings. Options B (RADIUS), C (SAML), and D (LDAP) are not valid IKE peer authentication methods for IPSec tunnel establishment; these are user authentication mechanisms used for GlobalProtect, administrative access, or User-ID, and they operate at the application/user layer rather than authenticating the IKE gateway peer itself.

Exam trap

The trap here is that candidates confuse user authentication methods (RADIUS, SAML, LDAP) with device-to-device IPsec tunnel authentication, which only supports pre-shared keys and certificates on Palo Alto firewalls.

259
MCQeasy

A network engineer is troubleshooting an HA pair where the passive firewall is showing a state of 'suspended'. The active firewall is functioning normally. What is the most likely reason for the suspended state?

A.The HA2 link is down.
B.A path monitoring failure has occurred.
C.The passive firewall has a lower HA priority.
D.The HA1 link is down.
AnswerB

Path monitoring is used to monitor critical IP addresses or interfaces. If a monitored path fails on the passive firewall, it can cause the firewall to enter a suspended state to prevent it from becoming active and potentially causing a network outage. This is a safety mechanism. The active firewall is functioning normally, so the passive firewall's path monitoring failure is likely the cause.

Why this answer

A path monitoring failure on the passive firewall can cause it to enter a suspended state. This prevents the firewall from becoming active if the active firewall fails, avoiding a potentially worse network situation. The active firewall is functioning normally, so the passive firewall's suspension is likely due to its own path monitoring.

Exam trap

The trap here is confusing suspended state with non-functional state; suspended is often due to path monitoring, while non-functional is due to HA link or configuration issues.

260
MCQmedium

A firewall has two virtual routers: VR1 (for internal networks) and VR2 (for DMZ). An internal server in VR1 needs to reach a DMZ server in VR2. Both virtual routers have routes to each other's subnets via a shared inter-connect. The firewall is receiving traffic but is dropping packets between the virtual routers. What configuration is missing?

A.Redistribution of routes between the virtual routers
B.Enabling packet forwarding on the virtual router interfaces
C.A security policy allowing traffic between the zones associated with the virtual routers
D.A static route on both virtual routers pointing to each other's subnets
AnswerC

Inter-VR routing alone does not permit transit; the firewall still evaluates zone-to-zone traffic against security policy. Because VR1 and VR2 interfaces sit in separate zones, the missing rule is a security policy permitting the internal zone to the DMZ zone, satisfying the stem's requirement that packets traverse virtual routers.

Why this answer

In Palo Alto Networks firewalls, virtual routers handle routing decisions independently, but traffic between zones (e.g., internal and DMZ) must be explicitly allowed by a security policy. Even if routes exist between VR1 and VR2, the firewall will drop inter-zone traffic without a policy that permits the session. This is a fundamental security enforcement mechanism that separates routing from access control.

Exam trap

The trap here is that candidates confuse routing (Layer 3) with security policy (Layer 4-7), assuming that if routes exist, traffic will flow, but Palo Alto firewalls enforce zone-based policies independently of routing.

How to eliminate wrong answers

Option A is wrong because route redistribution is not required when static or direct routes already exist between the virtual routers; redistribution is used to share routes dynamically between routing protocols, not to enable packet forwarding. Option B is wrong because packet forwarding is enabled by default on virtual router interfaces in Palo Alto firewalls; there is no separate 'enable forwarding' toggle. Option D is wrong because the question states both virtual routers already have routes to each other's subnets via a shared inter-connect, so adding more static routes would be redundant and not address the packet drop.

261
Multi-Selectmedium

An engineer is configuring App-ID for a network that uses both standard and custom applications. Which of the following are best practices for using App-ID effectively? (Choose three.)

Select 3 answers
A.Rely solely on default application signatures for all traffic identification.
B.Use application filters to create dynamic application groups based on characteristics.
C.Use application groups to simplify policy management for related applications.
D.Disable App-ID for traffic on well-known ports to reduce processing overhead.
E.Regularly update Application and Threats content to keep signatures current.
AnswersB, C, E

Application filters group applications dynamically by shared characteristics such as category, risk, or technology, so policy automatically includes new or custom applications matching those traits. This satisfies the scenario's need to manage both standard and custom applications without manually updating static groups whenever custom App-IDs are added.

Why this answer

Option B is correct because application filters let you build dynamic application groups that automatically match applications by characteristics such as category, subcategory, technology, risk, or behavioral attributes, so the group stays current as new App-IDs are added without manual edits. Option C is correct because application groups bundle related applications (for example, business apps or sanctioned SaaS) into a single object referenced in security policy, which simplifies rule management and reduces policy sprawl while still enforcing App-ID per application. Option E is correct because App-ID identification depends on the Application and Threats content database; regularly updating it ensures signatures for new and evolving applications, including custom and evasive apps, are available so the firewall can correctly identify and control traffic.

Option A is not a best practice because relying solely on default signatures ignores custom applications and the need for custom App-ID signatures, application filters, and groups to handle organization-specific traffic. Option D is not a best practice because App-ID should not be disabled on well-known ports; attackers and applications commonly use ports like 80 and 443 for non-standard traffic, and App-ID is designed to inspect and identify applications regardless of port, so disabling it would weaken security.

Exam trap

The trap here is that candidates may think disabling App-ID on well-known ports reduces overhead (Option D), but App-ID is designed to identify applications irrespective of port, and disabling it creates a security gap that attackers can exploit via port hopping.

262
MCQmedium

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?

A.A self-signed certificate generated by the firewall
B.Forward untrust certificate
C.Forward trust certificate
D.The internal web server's certificate and private key
AnswerD

For SSL Inbound Inspection, the firewall must have the internal server's certificate and its private key to decrypt the traffic. The firewall acts as the server to the client, decrypting the session, inspecting it, and then re-encrypting it to the server. This requires the server's private key to be imported into the firewall.

Why this answer

For SSL Inbound Inspection, the firewall must have the internal web server's certificate and private key. This allows the firewall to decrypt the inbound SSL traffic, inspect it, and then re-encrypt it to the server. The forward trust and untrust certificates are used for forward proxy decryption, not inbound inspection.

Exam trap

The trap here is confusing SSL Inbound Inspection with SSL Forward Proxy decryption, leading to the selection of forward trust or untrust certificates instead of the server's own certificate and private key.

263
MCQeasy

A company has deployed two PA-3220 firewalls in an active/passive high availability configuration. During normal operation, the active firewall (FW-A) handles all traffic. The network team notices that after a brief power outage, both firewalls report as active in the HA pair, causing network instability. The administrator needs to resolve this issue and prevent it from recurring. Which course of action should the administrator take?

A.Reboot both firewalls simultaneously to reset the HA state.
B.Disable link speed and duplex settings on the HA interfaces to force a failover.
C.Configure the HA mode with the 'preemptive' option and set the device priority higher on the intended active firewall.
D.Set the HA mode to 'active/active' to allow both firewalls to process traffic.
AnswerC

Preemptive ensures the higher-priority device becomes active after recovery, preventing both firewalls from staying active.

Why this answer

Configuring the HA mode with the 'preemptive' option ensures that when both firewalls recover from a power outage, the firewall with the higher device priority (the intended active unit) will automatically preempt the other and become active. Without preemption, both firewalls may come up as active if they lose HA heartbeat synchronization during the outage, leading to a split-brain scenario. Setting the device priority higher on FW-A guarantees it is preferred as the active unit upon recovery.

Exam trap

The trap here is that candidates often assume rebooting or resetting the HA state (Option A) is sufficient, but they overlook the need for preemption to automatically resolve the split-brain condition after a power failure, which is a common cause of HA instability in production environments.

How to eliminate wrong answers

Option A is wrong because rebooting both firewalls simultaneously does not resolve the underlying split-brain condition; it only temporarily resets the HA state and the problem will recur if the root cause (lack of preemption) is not addressed. Option B is wrong because disabling link speed and duplex settings on HA interfaces would disrupt the HA heartbeat link, potentially causing both firewalls to assume active state due to loss of communication, which worsens the issue rather than fixing it. Option D is wrong because setting the HA mode to 'active/active' would allow both firewalls to process traffic simultaneously, which is not the intended design for this active/passive deployment and would cause asymmetric routing and network instability, not resolve the split-brain problem.

264
MCQmedium

A company has deployed two Palo Alto Networks firewalls in an active/passive HA configuration. During a failover test, the engineer notices that the passive firewall did not take over when the active firewall's data plane interface went down. The engineer reviews the HA configuration and sees that the HA1 link is up and the HA2 link is up. What is the most likely reason for the failover not occurring?

A.The HA2 link is not configured for session synchronization.
B.The HA1 link is not configured with a backup path.
C.Link monitoring is not enabled on the data plane interface.
D.The passive firewall is in a suspended state.
AnswerC

For the firewall to trigger a failover when a data plane interface goes down, link monitoring must be enabled on that interface in the HA configuration. Without link monitoring, the firewall does not detect the interface failure and thus does not initiate a failover. This is a common oversight in HA setup.

Why this answer

Failover in an active/passive HA pair is triggered by link monitoring and path monitoring. If link monitoring is not enabled on the data plane interface that went down, the firewall does not detect the failure and therefore does not initiate a failover. The HA1 and HA2 links being up only ensure control and data synchronization, not failure detection.

Exam trap

The trap here is assuming that any interface failure automatically triggers failover; actually, link monitoring must be explicitly enabled on the interface.

265
MCQhard

An administrator is configuring a Palo Alto Networks firewall to perform SSL decryption for outbound traffic. The administrator wants to ensure that traffic to certain categories, such as financial services, is not decrypted due to privacy concerns. What should the administrator configure?

A.A decryption policy rule with the action 'no-decrypt' for the financial services category.
B.A decryption profile with the 'no-decrypt' setting for the financial services category.
C.A decryption policy rule with the action 'decrypt' for all traffic except financial services.
D.A Security policy rule with the action 'deny' for the financial services category.
AnswerA

A decryption policy rule with the action 'no-decrypt' allows the administrator to exclude specific traffic from SSL decryption based on criteria such as URL category. By placing this rule above the decryption rule, traffic to financial services will be exempt from decryption, addressing privacy concerns. This is the correct way to selectively bypass decryption for certain categories.

Why this answer

To exclude specific traffic from SSL decryption, the administrator should create a decryption policy rule with the action 'no-decrypt' for the desired category or traffic. This rule must be placed above the decryption rule that would otherwise decrypt the traffic. This ensures that traffic to financial services is not decrypted while other traffic can still be decrypted as needed.

The no-decrypt action is specifically designed for this purpose, allowing selective bypass of decryption.

Exam trap

The trap here is confusing decryption policy with Security policy; a Security policy deny would block traffic, not just bypass decryption, and decryption profiles do not control which traffic is decrypted.

266
MCQhard

Two firewalls in an active/passive HA pair are not synchronizing. The administrator checks 'show high-availability state' and sees 'active' on both firewalls. What is the most likely cause?

A.The HA3 control link is misconfigured or down.
B.Session owner is set to 'primary' on both firewalls.
C.Preemptive mode is enabled on both firewalls.
D.Both firewalls have different PAN-OS versions.
AnswerA

Without heartbeat, each firewall assumes the other is down and becomes active.

Why this answer

When both firewalls show 'active' in the HA state, it indicates a split-brain scenario where each firewall believes it is the active unit. The HA3 control link is responsible for heartbeat and state synchronization; if it is misconfigured or down, the firewalls cannot detect each other's presence, causing both to assume active status. This is the most common cause of dual-active HA failures.

Exam trap

The trap here is that candidates often assume both firewalls showing 'active' is caused by a configuration mismatch like PAN-OS versions or preemptive settings, but the core issue is the loss of the HA3 control link, which prevents heartbeat detection and triggers a split-brain condition.

How to eliminate wrong answers

Option B is wrong because 'session owner' is a session distribution setting for active/active HA, not active/passive, and setting it to 'primary' on both does not cause both to show active; it affects session ownership, not HA state. Option C is wrong because preemptive mode controls whether a previously active firewall reclaims active status after a failure recovery; it does not cause both to become active simultaneously. Option D is wrong because different PAN-OS versions prevent HA formation entirely (the pair will not synchronize or form a HA group), but the state would show 'non-functional' or 'not synchronized', not 'active' on both.

267
MCQmedium

A network security engineer is troubleshooting an application that is inconsistently identified as 'unknown-tcp' in the traffic logs. The application uses TCP port 8080 and initiates with a proprietary binary handshake. The engineer confirms that no custom App-ID has been created. Which action should the engineer take to ensure the firewall reliably identifies this application?

A.Configure an Application Override policy for port 8080 to force the firewall to treat the traffic as the desired application.
B.Enable SSL decryption for all traffic on port 8080 to allow the firewall to inspect the payload.
C.Add a security policy rule that allows TCP port 8080 and relies on the firewall's default App-ID for that port.
D.Create a custom App-ID with a signature that matches the proprietary binary handshake and assign it to the application.
AnswerD

Creating a custom App-ID with a signature that matches the proprietary handshake allows the firewall to recognize the application based on its unique traffic pattern, not just port. This is the correct approach because App-ID uses deep packet inspection and protocol decoding; a custom signature ensures reliable identification even if the application uses dynamic ports or encryption. The other options do not provide application-layer identification.

Why this answer

The firewall cannot identify a proprietary application if no signature exists. Creating a custom App-ID with a signature that matches the unique binary handshake enables the firewall to classify the traffic correctly based on application-layer attributes, not just port. This ensures consistent policy enforcement and visibility.

Other options either bypass identification or misapply features like SSL decryption.

Exam trap

The trap here is assuming that allowing the port or enabling decryption will automatically make App-ID recognize a proprietary protocol, when in fact a custom signature is required.

268
Drag & Dropmedium

Order the steps to configure a static route on a Palo Alto Networks firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to configure a static route on a Palo Alto Networks firewall is: navigate to the appropriate virtual router, add a new static route entry, configure the destination address and next-hop, and then commit the configuration. This ensures the route is properly defined and applied.

269
MCQhard

An organization has a firewall in HA active-passive mode. After a failover, the new active firewall does not have the latest session table. What should be configured to ensure session synchronization?

A.Packet capture on active
B.Session setup on both peers
C.HA session sync
D.Commit force sync
AnswerC

HA session sync replicates the session table from the active firewall to the passive peer, so after failover the newly active device already holds established sessions. Without it, traffic matching existing sessions is dropped, breaking continuity for stateful flows.

Why this answer

HA session synchronization (session sync) is the feature that replicates active session state from the active firewall to the passive firewall in an active-passive HA pair. Without this configuration, after a failover the new active firewall has no knowledge of existing sessions, causing all active connections to be dropped and requiring clients to re-establish them. Enabling session sync ensures the passive firewall maintains a synchronized session table, allowing seamless traffic continuation after failover.

Exam trap

The trap here is that candidates often confuse configuration synchronization (commit force sync) with runtime state synchronization (session sync), leading them to select Option D, but commit force sync only pushes configuration changes, not dynamic session data.

How to eliminate wrong answers

Option A is wrong because packet capture is a troubleshooting tool used to inspect traffic, not a mechanism to replicate session state between HA peers. Option B is wrong because session setup on both peers is not a configurable feature; session creation occurs naturally on the active firewall, and without session sync the passive peer does not receive those sessions. Option D is wrong because commit force sync is used to force a configuration synchronization from the active to the passive firewall, but it does not synchronize dynamic runtime data like session tables.

270
MCQhard

Refer to the exhibit. A user at IP 10.10.1.11 is unable to access internal resources that require authentication. The firewall logs show 'no user mapping' for traffic from this IP. Which step should the administrator take first?

A.Configure an authentication policy to trigger captive portal for that IP.
B.Verify that the User-ID agent has network access to the client at 10.10.1.11.
C.Check the Kerberos keytab file.
D.Manually create a static mapping for IP 10.10.1.11.
AnswerB

Verifying the User-ID agent's network access to 10.10.1.11 directly addresses the missing user mapping, since the agent must reach the client to query its logged-in sessions. Without that connectivity, no mapping is generated, so the firewall logs 'no user mapping' and authentication-dependent access fails.

Why this answer

The 'no user mapping' error indicates that the firewall cannot correlate the IP address (10.10.1.11) with a username. The first step is to verify that the User-ID agent can reach the client, because without network connectivity, the agent cannot collect user mappings via probing (e.g., WMI, NetBIOS, or terminal services). Option B directly addresses this root cause.

Exam trap

The trap here is that candidates often jump to configuring authentication policies or static mappings without first verifying the basic connectivity between the User-ID agent and the client, which is the most common root cause of missing user mappings.

How to eliminate wrong answers

Option A is wrong because configuring an authentication policy to trigger captive portal would require the user to actively authenticate, but the issue is that the firewall already lacks a user mapping for the IP; captive portal is a separate mechanism and not the first troubleshooting step. Option C is wrong because checking the Kerberos keytab file is relevant only if the firewall is configured for Kerberos-based authentication (e.g., for GlobalProtect or captive portal), but the core problem is missing user mapping, not a keytab misconfiguration. Option D is wrong because manually creating a static mapping is a workaround, not a diagnostic step; the administrator should first determine why the User-ID agent is not mapping the IP dynamically.

271
MCQeasy

A small business uses a single PA-220 firewall with PAN-OS 10.2. The administrator notices that the firewall is no longer receiving automatic threat updates. The License page shows the Threat Prevention license is active with 200 days remaining. The administrator can manually download updates from the Palo Alto Networks update server. What is the most likely cause?

A.The firewall is behind a proxy that blocks the update service.
B.The update schedule is disabled.
C.The firewall's system clock is incorrect.
D.The DNS settings are misconfigured.
AnswerB

Dynamic updates require a configured schedule to poll the update server automatically. With the licence active and manual downloads working, connectivity and entitlement are fine, so a disabled update schedule is the only remaining cause of missed automatic threat updates.

Why this answer

The most likely cause is that the update schedule is disabled. Even though the Threat Prevention license is active and manual downloads work, the firewall will not automatically check for or download updates if the scheduled update feature is turned off. In PAN-OS 10.2, the administrator must configure a recurring schedule under Device > Dynamic Updates for automatic updates to occur; otherwise, only manual downloads are possible.

Exam trap

The trap here is that candidates assume a valid license guarantees automatic updates, overlooking that the update schedule is a separate configuration setting that must be explicitly enabled.

How to eliminate wrong answers

Option A is wrong because if a proxy were blocking the update service, manual downloads would also fail, as they use the same outbound HTTPS connection to the Palo Alto Networks update server. Option C is wrong because an incorrect system clock would cause SSL certificate validation failures and prevent both automatic and manual updates, but the administrator can manually download updates successfully. Option D is wrong because misconfigured DNS would prevent resolution of the update server's FQDN, breaking both automatic and manual updates, yet manual downloads work.

272
MCQmedium

A network security engineer is troubleshooting why a newly installed Palo Alto Networks firewall is not inspecting traffic between two internal subnets. The engineer confirms that the traffic is routed through the firewall, security policies are configured to allow and inspect the traffic, and no drop counters are incrementing. However, the firewall's session table shows sessions in an 'ACTIVE' state but with no application identified. Which component of the Palo Alto Networks Next-Generation Firewall is responsible for identifying the application in this scenario?

A.User-ID
B.App-ID
C.Content-ID
D.SSL Decryption
AnswerB

App-ID is the Palo Alto Networks traffic classification technology that identifies the application regardless of port, protocol, or evasion technique. In this scenario, sessions are active but no application is identified, meaning App-ID has not yet completed its classification. App-ID uses multiple identification mechanisms including application signatures, protocol decoding, and heuristics. Once App-ID identifies the application, it can enforce security policies based on the application. The lack of application identification could be due to incomplete session setup, asymmetric traffic, or insufficient packets for identification.

Why this answer

App-ID is the Palo Alto Networks technology that identifies applications traversing the firewall. It uses signatures, protocol decoding, and behavioral heuristics to classify traffic accurately. In the scenario, sessions are active but no application is identified, indicating that App-ID has not yet completed its analysis.

This could happen if the session is incomplete, if traffic is asymmetric, or if the application is unknown. Once App-ID identifies the application, the firewall can apply the appropriate security policy. The other options are related technologies but do not perform application identification.

Exam trap

The trap here is confusing App-ID with Content-ID, as both are 'ID' technologies, but only App-ID identifies the application.

273
MCQeasy

An administrator wants to be notified whenever any administrator account is locked out after repeated failed login attempts. The notification must be sent by email to the security team. Which configuration accomplishes this?

A.Configure an Email server profile and a Log Forwarding profile that matches auth log entries, then apply it to the management interface.
B.Configure an Email server profile and enable email notifications for the authentication log under Device > Log Settings.
C.Create a custom report that filters authentication log entries and schedule it to be emailed every five minutes.
D.Enable SNMP traps on the management interface and configure the SNMP manager to interpret authentication failure traps.
AnswerB

The management-plane log settings under Device > Log Settings allow an administrator to specify an Email server profile and choose which system or authentication events generate email alerts. Enabling email notification for authentication log events causes a message to be sent when an administrator account is locked out, which is exactly the required behavior.

Why this answer

Email notification for management-plane events is configured under Device > Log Settings, where an Email server profile is selected and specific log types such as the authentication log are flagged for email alerts. This delivers an immediate message to the security team when an administrator account is locked out, meeting the notification requirement.

Exam trap

The trap here is confusing Log Forwarding profiles, which apply to Security policy session logs, with the management-plane log settings that control event-driven email alerts.

274
MCQhard

A network engineer is troubleshooting an authentication issue where users in a specific group are not being prompted for credentials, even though the authentication policy matches their traffic. The firewall logs show that the traffic is allowed by the security policy. What is the most likely cause?

A.The users are in a group that is excluded from authentication in the authentication profile.
B.The captive portal is not enabled on the interface.
C.The user-ID agent is not configured to include that group.
D.The authentication policy is placed after the security rule that allows the traffic.
AnswerA

Group exclusion would apply to the authentication profile, not prevent the prompt altogether.

Why this answer

When an authentication policy matches traffic but users in a specific group are not prompted for credentials, the most likely cause is that the group is excluded from authentication in the authentication profile. An authentication profile can include an allow list/exclusion list; users in an excluded group are not prompted for authentication even though the authentication policy matches. Authentication policies are evaluated before security policies, so a security policy allowing the traffic does not bypass authentication.

Exam trap

Candidates often assume security policies are evaluated before authentication policies, but in Palo Alto Networks firewalls, authentication policies are evaluated first. A matching authentication policy enforces authentication before security policy evaluation, so placing the authentication policy after a security rule does not bypass authentication.

How to eliminate wrong answers

Option A is wrong because if a group is excluded from authentication in the authentication profile, the firewall would not prompt for credentials for that group, but the logs would show the traffic as allowed by security policy without any authentication attempt, which is not the described scenario where users are not prompted despite the policy matching. Option B is wrong because captive portal not being enabled on the interface would prevent the authentication challenge from being presented, but the question states the authentication policy matches the traffic, implying the policy is configured and applied; captive portal is a separate setting that enables the browser-based authentication prompt, but its absence would cause a different symptom (no prompt at all) rather than the traffic being allowed without authentication. Option C is wrong because the User-ID agent not including a group affects user mapping and identification, not the enforcement of authentication policies; the authentication policy can still match based on source IP or other criteria, and the lack of group inclusion would not prevent the authentication prompt from being triggered.

275
Multi-Selectmedium

Which TWO statements correctly describe the role of the data plane in PAN-OS architecture?

Select 2 answers
A.It performs content inspection.
B.It runs routing protocols like OSPF.
C.It handles all packet forwarding and security processing.
D.It stores log files.
E.It manages the web interface and CLI.
AnswersA, C

Content inspection occurs in the data plane, where the packet-processing hardware and software apply App-ID, Content-ID and security profiles to live traffic. This satisfies the stem's requirement for a data plane function, since the management plane handles configuration and logging rather than inspecting sessions.

Why this answer

Option A is correct because the data plane in PAN-OS is responsible for performing content inspection, including App-ID, Content-ID, and threat prevention, on traffic that has been allowed by policy. Option C is correct because the data plane handles all packet forwarding and security processing, executing the security policy decisions made by the control plane on a per-packet basis. Options B, D, and E are incorrect because routing protocols like OSPF run in the control plane, log files are stored on the management plane's logging subsystem, and the web interface and CLI are managed by the management plane.

Exam trap

The trap here is confusing the data plane with the control plane or management plane, as candidates often assume that routing protocols or logging are part of packet forwarding, when in PAN-OS they are strictly separated.

276
MCQeasy

An administrator needs to verify the health of HA links. Which CLI command displays the current status of HA1, HA2, and HA3 links?

A.show session info
B.show running np-ips
C.show device-info
D.show high-availability state
AnswerD

Displays HA status including link states.

Why this answer

The 'show high-availability state' command is the correct CLI command to verify the health of HA1, HA2, and HA3 links because it displays the current status, link state, and any failures for each HA link in a Palo Alto Networks firewall. This command provides a comprehensive view of the HA control link (HA1), data link (HA2), and backup link (HA3), including their operational status and packet statistics, which is essential for troubleshooting high-availability configurations.

Exam trap

The trap here is that candidates often confuse 'show high-availability state' with 'show device-info' or 'show session info', assuming general system or session data includes HA link details, but only the dedicated HA command provides the granular link status required for this verification.

How to eliminate wrong answers

Option A is wrong because 'show session info' displays information about active sessions, such as source/destination IPs and ports, not the status of HA links. Option B is wrong because 'show running np-ips' shows the running configuration of network processor IP addresses, which is unrelated to HA link health verification. Option C is wrong because 'show device-info' provides general system information like model, serial number, and uptime, but does not include the specific status of HA1, HA2, or HA3 links.

277
MCQmedium

An administrator reviews a traffic log entry: 'Source: 10.0.0.10, Destination: 8.8.8.8, Application: web-browsing, Action: allow, Bytes Sent: 500, Bytes Received: 1200'. What does this log entry indicate about the traffic?

A.The traffic was blocked by a security policy.
B.The traffic was only one-way; only received bytes were logged.
C.The traffic was allowed and identified as web-browsing.
D.The application was incorrectly identified.
AnswerC

The log records Action: allow, confirming the firewall permitted the session, and Application: web-browsing, showing App-ID positively identified the traffic as HTTP/HTTPS browsing rather than merely inferring it from port 80 or 443. Bytes Sent and Received simply quantify client-to-server and server-to-client payload volumes for that allowed session.

Why this answer

The log entry shows 'Action: allow', which explicitly indicates the firewall permitted the traffic. The 'Application: web-browsing' field confirms that the Palo Alto Networks firewall correctly identified the traffic as HTTP/HTTPS (web-browsing) using App-ID, not just by port. The presence of both 'Bytes Sent' and 'Bytes Received' with non-zero values confirms bidirectional communication, so the traffic was allowed and properly classified.

Exam trap

The trap here is that candidates may assume traffic to 8.8.8.8 is always DNS and thus think the application was misidentified, but the log explicitly shows 'web-browsing' which is valid for HTTP/HTTPS traffic to any IP, and the 'allow' action confirms the firewall permitted it.

How to eliminate wrong answers

Option A is wrong because the 'Action: allow' field directly contradicts blocking; a blocked session would show 'Action: deny' or 'drop'. Option B is wrong because both 'Bytes Sent: 500' and 'Bytes Received: 1200' are non-zero, proving bidirectional traffic, not one-way. Option D is wrong because the application 'web-browsing' is a standard App-ID for HTTP/HTTPS traffic to a public DNS server (8.8.8.8), and there is no evidence of misidentification; App-ID uses deep packet inspection to verify the application regardless of port.

278
Multi-Selectmedium

Which TWO factors can cause traffic to be classified as 'incomplete' by App-ID? (Choose two.)

Select 2 answers
A.SSL decryption is not enabled for the session.
B.The firewall CPU is too slow to process packets.
C.The content-ID engine has not been licensed.
D.Asymmetric routing where the firewall sees only one direction of traffic.
E.A deny rule that blocks the traffic.
AnswersA, D

Without SSL decryption, the firewall cannot inspect the encrypted payload, so App-ID identifies only the outer protocol and cannot confirm the true application. The session remains incomplete until sufficient context is available, which decryption would otherwise supply.

Why this answer

Option A is correct because App-ID relies on inspecting the application payload to identify the application; when SSL decryption is not enabled, the firewall only sees encrypted traffic and cannot match a signature, so the session is reported as incomplete (ssl or insufficient-data). Option D is correct because App-ID requires seeing both directions of a flow to correlate client-to-server and server-to-client data; with asymmetric routing the firewall only observes one half of the session, so it cannot complete identification and marks the traffic incomplete. Option B is not correct because a slow CPU causes performance degradation or dropped packets, not an 'incomplete' App-ID classification.

Option C is not correct because Content-ID licensing affects threat, URL, and file inspection, not the base App-ID engine that classifies applications. Option E is not correct because a deny rule simply blocks the session; it does not produce an incomplete App-ID result.

Exam trap

The trap here is that candidates often confuse 'incomplete' with 'blocked' or 'error' states, assuming a slow CPU or licensing issue would cause incomplete classification, when in fact incomplete specifically means the firewall lacks sufficient traffic data to identify the application.

279
Multi-Selecteasy

Which TWO are valid methods to troubleshoot a firewall not passing traffic? (Choose two.)

Select 2 answers
A.Reboot the firewall
B.Change the interface IP address
C.Verify the security policy order
D.Check the session table for the traffic
E.Update the threat prevention signature
AnswersC, D

Verifying security policy order confirms that no earlier, broader rule is shadowing the intended permit, since PAN-OS evaluates rules top-down and stops at the first match. This directly satisfies the stem's troubleshooting requirement by ruling out misordering as the cause of dropped traffic.

Why this answer

Option C is correct because firewall policy is evaluated top-down, so a broader or more specific rule placed above the intended rule can shadow it and silently drop or block the traffic; verifying rule order confirms whether the matching permit rule is actually being reached. Option D is correct because the session table (e.g., 'show session all filter source x.x.x.x destination y.y.y.y' on Palo Alto, or 'conntrack -L'/'show conn' on other platforms) reveals whether a session was created, its state, and whether it was denied, which directly indicates where traffic is failing. Option A is not a troubleshooting method since rebooting only clears state temporarily and provides no diagnostic evidence of the root cause.

Option B is not valid because changing the interface IP address alters the configuration rather than diagnosing the existing forwarding or policy problem. Option E is not valid because updating threat prevention signatures addresses content inspection, not the basic forwarding or policy issue being investigated.

Exam trap

The trap here is that candidates often assume rebooting or updating signatures will fix traffic issues, but these actions do not address the most common causes like policy misordering or session state problems, which are directly verifiable through the session table and policy order review.

280
Multi-Selecteasy

Which TWO are best practices when configuring App-ID for a production environment? (Choose two.)

Select 2 answers
A.Disable App-ID for traffic that does not match any known application to improve performance.
B.Configure all security policies based on port only for consistency.
C.Use applications instead of ports in security policies.
D.Enable security profiles (e.g., vulnerability protection) along with App-ID.
E.Limit application usage to only well-known applications to reduce attack surface.
AnswersC, D

App-ID identifies applications by signature regardless of port, so policies referencing applications enforce intent precisely and resist evasion via port hopping. This satisfies production best practice by removing reliance on port numbers, which are unreliable indicators of actual application traffic.

Why this answer

Option C is correct because App-ID's core value is identifying applications regardless of port, protocol, or evasive technique, so security policies should reference applications (or application filters/groups) rather than ports to enforce accurate, consistent control. Option D is correct because App-ID alone only identifies and allows/denies traffic; pairing it with security profiles such as Vulnerability Protection, Antivirus, Anti-Spyware, and URL Filtering provides the threat inspection needed to actually block exploits and malware within allowed applications. Option A is wrong because disabling App-ID for unmatched traffic (e.g., via unknown-tcp/unknown-udp handling) weakens visibility and control rather than being a best practice, and performance is not improved in a way that justifies losing security.

Option B is wrong because port-only policies defeat the purpose of App-ID and are easily bypassed by applications using non-standard ports or port hopping. Option E is wrong because restricting to only well-known applications is not a general best practice; App-ID should be used to identify and control all applications, including sanctioned SaaS and custom/internal apps, based on risk and business need.

Exam trap

The trap here is that candidates often think disabling App-ID for unknown traffic improves performance (Option A), but this actually creates a security gap; the correct approach is to use 'default' rules with security profiles to handle unknown traffic safely.

281
Multi-Selecteasy

Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?

Select 2 answers
A.show system info
B.show vpn ike-sa
C.show routing route
D.show vpn ipsec-sa
E.show interface all
AnswersB, D

The show vpn ike-sa command displays Phase-1 IKE security associations, including peer addresses, state, and remaining lifetime. Inspecting it confirms whether the IKE tunnel itself is established, which is the required status check for an IPSec tunnel.

Why this answer

Option B, 'show vpn ike-sa', is correct because it displays the status of IKE Phase 1 security associations, which are the foundation of an IPSec tunnel and must be established before Phase 2 can come up. Option D, 'show vpn ipsec-sa', is correct because it shows the IPSec Phase 2 security associations, directly confirming whether the tunnel itself is active and passing traffic. Together these two commands let an administrator verify both phases of an IPSec VPN on a Palo Alto Networks firewall.

Option A, 'show system info', only reports general device information such as model, software version, and uptime, not tunnel state. Option C, 'show routing route', displays the routing table and cannot show IKE or IPSec SA status. Option E, 'show interface all', shows interface statistics and link state, which is unrelated to IPSec tunnel status.

Exam trap

The trap here is that candidates often confuse general network commands (like routing or interface status) with VPN-specific commands, assuming that a working route or interface implies a functional IPSec tunnel, when in fact the tunnel may be down due to IKE or IPSec SA failures.

282
MCQhard

Refer to the exhibit. What does the 'Session End Reason: aged-out' indicate about the traffic?

A.The session was terminated by a firewall policy.
B.The session was idle for longer than the timeout threshold.
C.The session was forcibly closed by an administrator.
D.The session ended due to a TCP FIN/RST from the client.
AnswerB

Aged-out means the session sat idle until its configured timeout expired, so PAN-OS removed it from the session table. This satisfies the exhibit's requirement: the session ended because no packets refreshed it within the timeout threshold, not due to a reset or policy denial.

Why this answer

The 'Session End Reason: aged-out' indicates that the firewall terminated the session because it remained idle for longer than the configured timeout threshold. Palo Alto Networks firewalls use application-specific timeouts (e.g., TCP default 3600 seconds, UDP 30 seconds) to free resources from sessions that have stopped transmitting data. This is a normal cleanup mechanism, not a policy or explicit termination.

Exam trap

Palo Alto Networks often tests the misconception that 'aged-out' means the session was terminated by a security policy or explicit reset, but the trap here is that 'aged-out' specifically refers to an idle timeout, not a policy action or TCP handshake termination.

How to eliminate wrong answers

Option A is wrong because a firewall policy termination would show 'Session End Reason: policy-deny' or similar, not 'aged-out'. Option C is wrong because an administrator forcibly closing a session would generate a 'Session End Reason: admin-reset' or 'session-manager clear session' event. Option D is wrong because a TCP FIN/RST from the client would result in 'Session End Reason: tcp-fin' or 'tcp-rst', not 'aged-out', which specifically indicates idle timeout.

283
MCQmedium

Users are unable to authenticate via Captive Portal. The firewall receives authentication requests but they time out. What should be checked first?

A.The certificate used for the Captive Portal page
B.The session timeout for authenticated users
C.The authentication sequence settings in the Captive Portal configuration
D.The User-ID agent mapping
AnswerC

Authentication requests reach the firewall but time out, indicating the firewall cannot reach an authentication service. The authentication sequence defines which servers are queried and in what order, so a misconfigured or unreachable sequence entry is the first thing to verify.

Why this answer

When the firewall receives authentication requests but they time out, the most common cause is a misconfigured authentication sequence. The authentication sequence defines the order of authentication methods (e.g., local database, RADIUS, LDAP) and their timeout settings. If the sequence is incorrect or the servers are unreachable, the firewall will wait for a response until the timeout expires, causing the Captive Portal authentication to fail.

Checking this first isolates the issue efficiently before investigating other components.

Exam trap

The trap here is that candidates often jump to checking the certificate (Option A) because Captive Portal uses HTTPS, but the timeout symptom specifically indicates a backend authentication server issue, not a certificate problem.

How to eliminate wrong answers

Option A is wrong because a certificate issue would typically cause SSL/TLS errors or browser warnings, not authentication request timeouts; the firewall would still process the request but the page might not load securely. Option B is wrong because session timeout controls how long an authenticated user remains active, not the initial authentication process; changing it would not affect the timeout of authentication requests. Option D is wrong because the User-ID agent mapping is used to map IP addresses to usernames after authentication, not to process the initial Captive Portal authentication requests; a timeout during authentication points to the authentication server or sequence, not the mapping agent.

284
MCQhard

Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?

A.The IKE gateway is not configured with the correct peer IP.
B.No security policy allows traffic from the VPN zone.
C.The proxy IDs do not match the remote peer.
D.The tunnel interface is not assigned to a zone.
AnswerB

A tunnel can negotiate successfully at IKE and IPsec phases while user traffic is silently dropped if no security policy permits the VPN zone as source or destination, which is the classic cause of an up-but-passing-no-traffic state.

Why this answer

When a site-to-site VPN tunnel is up but traffic is not passing, the most common cause is the absence of a security policy that permits traffic from the VPN zone to the destination zone. Even if IKE and IPsec SAs are established, the firewall drops the decrypted traffic if no rule explicitly allows it. This is a fundamental Palo Alto Networks concept: tunnel establishment and data forwarding are separate control and data plane functions.

Exam trap

Palo Alto Networks often tests the misconception that a tunnel being up automatically means traffic will pass, but Palo Alto Networks requires an explicit security policy to permit decrypted traffic from the VPN zone.

How to eliminate wrong answers

Option A is wrong because if the IKE gateway had an incorrect peer IP, the tunnel would not come up at all (IKE phase 1 would fail). Option C is wrong because mismatched proxy IDs would cause IPsec SA negotiation to fail, preventing the tunnel from reaching an up state. Option D is wrong because a tunnel interface not assigned to a zone would cause the interface itself to be inactive, and the tunnel would not show as up; the question states the tunnel is up, so the interface must be zoned.

285
MCQmedium

An administrator is analyzing traffic logs on a Palo Alto Networks firewall and notices that a particular session shows an application of 'incomplete' and no bytes received. The session was allowed by the security policy. What is the most likely cause?

A.The application is using a non-standard port and was not detected.
B.The security policy is blocking the application, causing incomplete identification.
C.The application was identified but the session timed out before data was exchanged.
D.The firewall did not receive enough packets to identify the application.
AnswerD

The 'incomplete' application status means the firewall could not identify the application because it did not see enough packets or data. This often happens when the session is terminated early or if the traffic is asymmetric. Without sufficient data, the firewall cannot match the application signature, resulting in 'incomplete'.

Why this answer

An 'incomplete' application status in traffic logs indicates that the firewall could not identify the application because it did not receive enough packets or data to match a signature. This can occur with short-lived sessions, asymmetric routing, or when the session is terminated before the application is fully identified. The security policy allowed the session, but application identification failed.

Exam trap

The trap here is assuming that an allowed session should always have a fully identified application, but application identification requires sufficient data and can be incomplete.

286
MCQeasy

A network administrator wants to allow only specific applications such as 'facebook-base' and 'youtube' while blocking all other applications. Which type of security rule should be used to achieve this?

A.Create a security rule with application conditions set to 'facebook-base' and 'youtube' and action set to 'allow'.
B.Create a security rule with destination port 80 and 443 and action set to 'allow'.
C.Create a security profile that blocks all applications not in the allow list.
D.Create a URL filtering rule to allow 'social-networking' and 'multimedia' categories.
AnswerA

Application-based security rules match traffic by App-ID rather than port or IP, so specifying facebook-base and youtube with an allow action permits only those applications. An implicit deny then blocks all remaining applications, satisfying the allowlist requirement.

Why this answer

App-ID allows you to create a security rule that explicitly allows only the specified applications ('facebook-base' and 'youtube') while implicitly denying all other traffic. Since the default action for any traffic not matching an allow rule is 'deny', this rule achieves the goal of blocking all other applications without needing an explicit block rule.

Exam trap

The trap here is that candidates often confuse port-based rules (Option B) with application-based rules, assuming that allowing ports 80/443 is sufficient to control application access, but App-ID is required to distinguish between applications using the same port.

How to eliminate wrong answers

Option B is wrong because allowing destination ports 80 and 443 would permit all HTTP/HTTPS traffic, including applications like 'facebook-base' and 'youtube', but it would also allow many other web-based applications (e.g., 'twitter', 'dropbox'), failing to block them. Option C is wrong because security profiles (e.g., Antivirus, Vulnerability Protection) do not control which applications are allowed or blocked; they inspect traffic that is already permitted by the security rule's action. Option D is wrong because URL filtering rules control access based on URL categories, not application identities; 'social-networking' and 'multimedia' categories would include many applications beyond just 'facebook-base' and 'youtube', and URL filtering cannot enforce application-level granularity like App-ID can.

287
Drag & Dropmedium

Arrange the steps to configure a new zone on a Palo Alto Networks firewall in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a new zone on a Palo Alto Networks firewall is: first, navigate to Network > Zones; second, click Add to create a new zone object; third, enter the zone name and select the zone type (e.g., Layer3); finally, click OK to save the configuration. This order ensures that the zone is properly created and configured before committing changes.

288
Multi-Selectmedium

Which TWO factors can cause a firewall to not show any User-ID mapping for a user who is actively logged in?

Select 2 answers
A.The user is using a VPN connection from a remote location
B.The firewall's User-ID agent is in collector mode
C.The User-ID agent is not configured with the firewall's IP as a client
D.The user's traffic is being decrypted by SSL decryption
E.The domain controller is not forwarding security events to the User-ID agent
AnswersC, E

The agent must have the firewall listed as a client to send mappings.

Why this answer

The User-ID agent must be configured with the firewall's IP address as a client to forward user-to-IP mappings. Without this configuration, the firewall will not receive the mapping data from the agent, even if the user is actively logged in and the agent is collecting security events from the domain controller.

Exam trap

The trap here is that candidates often confuse 'collector mode' with a failure to send mappings, but collector mode actually aggregates and forwards data, so it does not cause missing mappings; the real issue is the missing client IP configuration on the agent.

289
Multi-Selecthard

Which THREE of the following are capabilities of GlobalProtect Host Information Profile (HIP)?

Select 3 answers
A.Check the user's location
B.Check the browser version
C.Check if antivirus is installed and running
D.Check if disk encryption is enabled
E.Check the operating system version
AnswersC, D, E

HIP collects host posture data via the GlobalProtect agent, including whether antivirus software is installed and actively running. This satisfies the stem's requirement by confirming endpoint security compliance before granting or restricting access through a HIP-enabled security policy.

Why this answer

Option C is correct because HIP collects host data on endpoint security software, including whether antivirus/anti-malware is installed, running, and up to date, which is a core HIP check. Option D is correct because HIP can verify disk encryption status (for example, BitLocker or FileVault) as part of its endpoint compliance data. Option E is correct because HIP reports the operating system version and patch level, allowing security policies to require a minimum OS version.

Option A is not a HIP capability because HIP profiles endpoint host attributes, not the user's geographic location, which is handled by other means such as source region or GlobalProtect gateway selection. Option B is not a HIP capability because HIP does not natively report browser version; browser checks are not part of the standard HIP object categories.

Exam trap

The trap here is that candidates often confuse HIP with GlobalProtect's location-based features or application-level checks, assuming HIP can verify user location or browser versions, when in reality HIP is strictly focused on endpoint security posture attributes like OS, antivirus, disk encryption, and patch management.

290
Drag & Dropmedium

Arrange the steps to perform a factory reset on a Palo Alto Networks firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct factory reset sequence for a Palo Alto Networks firewall is: first locate the physical reset button, then press and hold it with a paperclip, wait for the alarm LED to turn off and back on (indicating the reset is complete), and finally release the button. This ensures all configurations are cleared and the device reboots to factory defaults. Common mistakes include performing steps in the wrong order, such as releasing too early or waiting before pressing.

291
MCQeasy

A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?

A.allow
B.reset-both
C.deny
D.drop
AnswerA

Permitting the session satisfies the requirement to admit inbound HTTPS from Untrust to the DMZ web server. A security policy action of allow passes matching traffic and applies the profile group, whereas deny or drop would block it. Since the destination is a specific server IP, this action forwards the connection to the web server.

Why this answer

The correct action is 'allow' because the security engineer needs to permit inbound HTTPS traffic from the Untrust zone to the DMZ web server. In Palo Alto Networks firewalls, the security policy action 'allow' explicitly permits the traffic to pass through the firewall, which is required for legitimate inbound web traffic.

Exam trap

The trap here is that candidates may confuse 'deny' with 'drop' or think 'reset-both' is a valid way to allow traffic, but only 'allow' actually permits the session to be established and pass through the firewall.

How to eliminate wrong answers

Option B (reset-both) is wrong because it sends TCP RST packets to both the client and server, which would terminate the HTTPS connection rather than allowing it. Option C (deny) is wrong because it discards the traffic and sends a TCP RST to the sender, blocking the inbound HTTPS traffic. Option D (drop) is wrong because it silently discards the traffic without any notification, which would also prevent the HTTPS traffic from reaching the web server.

292
MCQeasy

An administrator wants to receive SNMP traps from the firewall for critical events such as failed login attempts and high CPU usage. Which configuration step is required?

A.Enable SNMP monitoring on the interface.
B.Set up a log forwarding profile with SNMP action.
C.Create an SNMP read-only community string.
D.Configure an SNMP trap destination under Device > Setup > SNMP Trap.
AnswerD

SNMP traps are outbound notifications, so the firewall needs a defined trap destination to know where to send them. Configuring this under Device > Setup > SNMP Trap enables critical events such as failed logins and high CPU usage to reach the monitoring server.

Why this answer

To receive SNMP traps from a Palo Alto Networks firewall, you must configure the trap destination under Device > Setup > SNMP Trap. This step defines where the firewall sends SNMP notifications (traps) for events like failed login attempts and high CPU usage. Without a configured trap destination, the firewall will not transmit any SNMP traps, even if other SNMP settings are enabled.

Exam trap

The trap here is that candidates often confuse SNMP polling (which requires read-only community strings and interface monitoring) with SNMP trap generation (which requires a separate trap destination configuration), leading them to select options A or C instead of D.

How to eliminate wrong answers

Option A is wrong because enabling SNMP monitoring on an interface allows the firewall to be polled via SNMP (e.g., for MIB data), but it does not configure the firewall to send unsolicited traps. Option B is wrong because log forwarding profiles are used to forward logs to external services (e.g., syslog, email), not to send SNMP traps; SNMP trap configuration is separate and does not use log forwarding profiles. Option C is wrong because creating an SNMP read-only community string is required for SNMP polling (read access to MIB objects), but it is not necessary for sending traps; traps use a separate community string (often the same, but the trap destination configuration is the critical step).

293
Multi-Selecthard

A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)

Select 2 answers
A.Enable Multi-Factor Authentication for all admins.
B.Configure role-based access on Panorama.
C.Create an admin role with commit scope limited to specific device groups.
D.Use template stacks to restrict commit permissions.
E.Set the firewall to require approval for commits.
AnswersB, C

Role-based access control on Panorama assigns administrative roles defining which device groups, templates and actions each administrator may use. This satisfies the requirement that only specific administrators can commit changes to devices, because commit rights derive from the assigned role's permissions.

Why this answer

Option B is correct because Panorama's role-based access control (RBAC) is the mechanism that defines what each administrator account is allowed to do, including whether they can push commits to managed devices; without configuring roles on Panorama, no granular restriction of commit rights is possible. Option C is correct because an admin role can be scoped with a commit scope limited to specific device groups (and templates), so administrators assigned that role can only commit changes to those device groups rather than to all managed firewalls. Option A is not required because MFA strengthens authentication but does not restrict which devices an admin can commit to.

Option D is incorrect because template stacks are configuration containers for pushing settings to firewalls, not a permission-control feature. Option E is incorrect because firewalls in a Panorama-managed environment do not have a per-device 'require approval for commits' setting that governs administrator commit permissions.

Exam trap

The trap is confusing authentication (MFA) with authorization (RBAC); MFA does not restrict what an admin can do after login, only how they log in.

294
MCQeasy

Refer to the exhibit. A firewall system log contains a critical license expiration entry for URL Filtering. What will happen to URL Filtering functionality?

A.The firewall will stop passing traffic until the license is renewed.
B.URL Filtering will stop working immediately until a new license is installed.
C.URL Filtering will continue to use the last downloaded URL database but will not receive updates.
D.The firewall will automatically fall back to a basic URL category list.
AnswerC

An expired URL Filtering licence disables database updates only; the firewall retains the last downloaded URL database and continues enforcing it. This satisfies the scenario because filtering still functions, merely growing stale as new URLs are uncategorised.

Why this answer

When a URL Filtering license expires on a Palo Alto Networks firewall, the device does not immediately disable the feature. Instead, it continues to use the last downloaded URL database to categorize URLs, but it will no longer receive periodic database updates from the Palo Alto Networks update server. This ensures that existing traffic policies based on URL categories remain functional, though new or changed URLs may not be accurately categorized until the license is renewed.

Exam trap

A common misconception is that license expiration immediately disables the associated feature, but Palo Alto Networks firewalls are designed to continue using the last known good data to maintain operational continuity until the license is renewed.

How to eliminate wrong answers

Option A is wrong because the firewall does not stop passing all traffic; only the URL Filtering update mechanism is affected, and traffic continues to flow based on existing policies. Option B is wrong because URL Filtering does not stop working immediately; the last downloaded database remains active and continues to be used for URL categorization. Option D is wrong because the firewall does not automatically fall back to a basic URL category list; it retains the full, last-downloaded database without any automatic downgrade to a simpler list.

295
MCQhard

A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?

A.Another rule earlier in the policy matches the traffic and allows it before reaching this rule.
B.The firewall is configured to not log interzone traffic.
C.The source address 10.1.0.0/16 is not part of the 10.0.0.0/8 subnet.
D.The logging profile is not applied to the rule.
AnswerA

PAN-OS evaluates rules top-down and stops at the first match, so an earlier allow rule for 10.1.0.0/16 permits the traffic before the logging rule is reached. Only the matched rule's log setting applies, hence no log entry appears.

Why this answer

In a Palo Alto Networks firewall, security rules are evaluated from top to bottom, and the first matching rule is applied. If an earlier rule in the policy matches the traffic from 10.1.0.0/16 and allows it, the rule with logging at rule end will never be evaluated, and thus no log entry is generated for that traffic.

Exam trap

The trap here is that candidates may assume a subnet like 10.1.0.0/16 is not part of 10.0.0.0/8, but in CIDR notation, 10.1.0.0/16 is indeed a subset of 10.0.0.0/8, so the issue is rule order, not address mismatch.

How to eliminate wrong answers

Option B is wrong because interzone traffic logging is not a global setting that can be disabled; logging is controlled per rule via the log setting at rule start or end. Option C is wrong because 10.1.0.0/16 is a subset of 10.0.0.0/8, so it is included in the source address range. Option D is wrong because the logging profile is not required for basic logging; setting logging at rule end enables logging without a separate profile.

296
MCQhard

An administrator is troubleshooting VPN tunnel flapping. The logs show multiple Phase 2 rekeys. The tunnel uses IKEv2 with pre-shared key. What is the most likely cause?

A.Mismatched IKE version.
B.Dead Peer Detection (DPD) interval too long.
C.The rekey time settings are too short.
D.Incorrect local or peer ID.
AnswerC

IKEv2 Phase 2 rekeys occur when the IPsec security association lifetime expires. Excessively short rekey timers force frequent renegotiation, and if either peer fails to complete it in time, the tunnel drops and re-establishes, producing flapping.

Why this answer

Frequent Phase 2 rekeys indicate that the IPsec security associations (SAs) are being renegotiated too often. With IKEv2, the rekey time settings (e.g., lifetime seconds or kilobytes) control how long a Phase 2 SA remains active before it must be refreshed. If these values are set too short, the tunnel will flap as SAs are constantly re-established, causing intermittent connectivity.

Exam trap

The trap here is that candidates often confuse rekey flapping with DPD or misconfiguration issues, but the specific log entry of 'multiple Phase 2 rekeys' directly points to the SA lifetime being too short, not to peer reachability or identity problems.

How to eliminate wrong answers

Option A is wrong because IKEv2 is explicitly specified in the scenario, and a mismatched IKE version would prevent Phase 2 establishment entirely, not cause flapping after initial setup. Option B is wrong because a DPD interval that is too long would delay detection of a dead peer, potentially causing the tunnel to stay up longer, not trigger frequent rekeys; a too-short DPD interval could cause false timeouts, but the logs show Phase 2 rekeys, not DPD-related failures. Option D is wrong because incorrect local or peer ID would typically cause authentication or identity validation failures during Phase 1 or Phase 2, leading to a complete failure to establish the tunnel, not repeated rekeys of an already-established SA.

297
MCQhard

An enterprise requires separate administrative domains within a single firewall chassis for different business units. Each domain must have its own virtual router, security policies, and interface configuration. What is the appropriate PAN-OS feature?

A.Administrative roles with RBAC
B.Multiple contexts
C.Multiple virtual routers
D.Multiple virtual systems (vsys)
AnswerD

Multiple virtual systems partition one chassis into isolated logical firewalls, each with its own virtual router, security policies and interfaces. This delivers the separate administrative domains the business units require, which a single vsys or interface-level zoning cannot provide.

Why this answer

Virtual Systems (vsys) are the PAN-OS feature that enables partitioning a single physical firewall into multiple independent virtual firewalls. Each vsys operates with its own virtual router, security policies, and interface configuration, meeting the requirement for separate administrative domains for different business units within one chassis.

Exam trap

The trap here is confusing the Cisco term 'multiple contexts' with PAN-OS Virtual Systems, as candidates familiar with Cisco firewalls may incorrectly select Option B, not realizing that PAN-OS uses a different terminology and architecture for multi-tenancy.

How to eliminate wrong answers

Option A is wrong because Administrative roles with RBAC control user permissions and access to the firewall's management functions, but they do not create separate network domains with independent virtual routers, policies, or interfaces. Option B is wrong because 'Multiple contexts' is a Cisco ASA/Firepower term for virtual firewalls, not a PAN-OS feature; PAN-OS uses Virtual Systems (vsys) for this purpose. Option C is wrong because Multiple virtual routers allow separate routing tables within a single firewall instance, but they do not provide isolated security policies, interfaces, or administrative domains—all virtual routers share the same vsys context unless combined with vsys.

298
Multi-Selectmedium

Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)

Select 3 answers
A.Firewall management interface
B.GlobalProtect Gateway
C.GlobalProtect Client
D.GlobalProtect Portal
E.Authentication server
AnswersB, C, D

The GlobalProtect gateway is a core infrastructure component, terminating client tunnels and enforcing security policy for remote users. It satisfies the stem's requirement by providing the data-plane endpoint that agents connect to, distinct from the portal's configuration role. Gateways can be deployed on firewalls or dedicated appliances, scaling across multiple regions.

Why this answer

The three core components of the GlobalProtect infrastructure are the GlobalProtect Portal (D), the GlobalProtect Gateway (B), and the GlobalProtect Client (C). The Portal (D) is the entry point that hosts the agent configuration and delivers settings, client certificates, and the list of available gateways to endpoints. The Gateway (B) is the security enforcement point that provides the actual tunnel (SSL or IPSec) and applies security, decryption, and HIP policies to traffic.

The Client (C) is the endpoint software (GlobalProtect app) installed on user devices that authenticates to the portal, retrieves configuration, and establishes the tunnel to a gateway. The firewall management interface (A) is only the administrative web UI/CLI used to configure the firewall and is not itself a GlobalProtect infrastructure component, and an authentication server (E) is an external identity source (e.g., LDAP, RADIUS, SAML IdP) that GlobalProtect can reference for user authentication but is not a GlobalProtect component.

Exam trap

The trap here is that candidates often confuse external dependencies (like authentication servers or management interfaces) with the core GlobalProtect components, leading them to select options that are not part of the defined infrastructure.

299
MCQmedium

During a traffic spike, the firewall CPU utilization remains below 30% but the dataplane packet buffer usage is consistently above 90%. What is the most likely impact on firewall performance?

A.Reduced new session setup rate.
B.Reduced committed information rate (CIR) on QoS policies.
C.Increased latency for management access.
D.Increased packet drops due to buffer exhaustion.
AnswerD

Sustained dataplane buffer usage above 90% means the firewall cannot queue bursts fast enough, so new packets are discarded before processing. CPU headroom is irrelevant here: buffer exhaustion, not processing capacity, is the binding constraint, producing packet drops and retransmissions during the spike.

Why this answer

When dataplane packet buffer usage exceeds 90% during a traffic spike, the firewall's packet buffers are nearly exhausted, leading to a condition where incoming packets cannot be stored temporarily for processing. This directly causes packet drops because the dataplane has no available buffers to enqueue new packets, even though CPU utilization remains low. Option D correctly identifies this as the primary impact, as buffer exhaustion results in tail-drop behavior for new packets.

Exam trap

The trap here is that candidates often assume high packet buffer usage automatically implies high CPU utilization, but the PCNSE exam tests the understanding that dataplane buffer exhaustion and CPU utilization are independent metrics, and buffer drops can occur even when CPU is idle.

How to eliminate wrong answers

Option A is wrong because reduced new session setup rate is typically caused by high CPU utilization or session table exhaustion, not by high packet buffer usage; the CPU is below 30%, so session setup should not be impaired. Option B is wrong because the committed information rate (CIR) on QoS policies is a traffic-shaping parameter that is not directly affected by packet buffer usage; QoS policies enforce bandwidth limits regardless of buffer occupancy. Option C is wrong because increased latency for management access is associated with high control-plane CPU or management-plane congestion, not with dataplane buffer exhaustion; management traffic uses separate queues and resources.

300
MCQeasy

An administrator wants to generate a report that shows the top applications by bandwidth usage over the last week. Which report type should be used to accomplish this?

A.URL Filtering Report
B.Application Report
C.Traffic Report
D.Threat Report
AnswerB

The Application Report aggregates traffic by application, exposing bandwidth consumption per application over a chosen period. Selecting a one-week timeframe directly satisfies the requirement to rank top applications by bandwidth usage, which other report types do not provide.

Why this answer

The Application Report is designed to provide visibility into application usage, including bandwidth consumption, top applications, and application-level trends over a specified time period. This report type leverages the App-ID engine to classify traffic by application, regardless of port or protocol, making it the correct choice for identifying top applications by bandwidth usage.

Exam trap

The trap here is that candidates often confuse the Traffic Report (which shows raw byte counts) with application-level reporting, failing to realize that only the Application Report uses App-ID to break down bandwidth by application identity rather than by IP or port.

How to eliminate wrong answers

Option A is wrong because the URL Filtering Report focuses on web browsing activity based on URL categories and does not provide application-level bandwidth breakdowns. Option C is wrong because the Traffic Report shows raw traffic volume (bytes, packets, sessions) by source/destination or zone, but it does not natively aggregate or rank by application identity. Option D is wrong because the Threat Report is dedicated to security threats such as intrusions, malware, and vulnerabilities, not application bandwidth usage.

Page 3

Page 4 of 5

Page 5

All pages