Courseiva

Palo Alto Networks Certified Network Security Engineer PCNSE (PCNSE) — Questions 301–319

319 questions total · 5pages · All types, answers revealed

Page 4

Page 5 of 5

301
MCQhard

During a security audit, it is discovered that a custom application signature matches too broadly, causing benign traffic to be classified as the custom app. What change should be made to narrow the signature?

A.Remove the protocol field from the signature.
B.Use a wider port range and remove data patterns.
C.Add a data pattern filter to match a specific payload signature.
D.Expand the port range to include more traffic.
AnswerC

A data pattern filter constrains the signature to a distinctive payload string, so matching requires the specific byte sequence rather than broad context alone. This narrows detection to the intended application, preventing benign sessions that merely resemble the app from being classified as the custom app.

Why this answer

Adding a data pattern filter allows the custom App-ID signature to match on a specific payload string or byte sequence, which narrows the scope of traffic classified as that application. Without a data pattern, the signature may rely solely on IP protocol, port, or other broad criteria, causing false positives. By requiring a unique payload signature, only traffic containing that exact data pattern is identified as the custom application.

Exam trap

The trap here is that candidates mistakenly think expanding port ranges or removing protocol fields will narrow the signature, when in fact those actions broaden the match criteria and worsen false positives.

How to eliminate wrong answers

Option A is wrong because removing the protocol field would make the signature even broader, potentially matching any IP traffic regardless of protocol (TCP, UDP, etc.), increasing false positives. Option B is wrong because using a wider port range and removing data patterns would expand the matching criteria, making the signature less specific and more likely to misclassify benign traffic. Option D is wrong because expanding the port range includes more traffic, which would broaden the signature and worsen the over-matching issue, not narrow it.

302
MCQmedium

Based on the exhibit, what caused the last failover?

A.The HA2 link went down.
B.A preemption event occurred.
C.The peer firewall was rebooted.
D.The HA1 keepalive from the peer was lost.
AnswerD

The HA1 keepalive carries the heartbeat between peers; its loss makes the firewall conclude the peer is down, triggering failover. The exhibit shows HA1 link failure, so the peer's keepalive never arrived, which is the direct cause of the last failover.

Why this answer

The exhibit shows 'HA1 keepalive from the peer was lost' as the last failover reason. In an active/passive HA pair, the passive firewall monitors HA1 keepalive messages from the active peer. When these keepalives are not received within the configured hello interval (default 1 second) and hold timer (default 3 seconds), the passive firewall assumes the active peer has failed and initiates a failover to become active.

Exam trap

The trap here is that candidates often confuse the HA1 link (control link for keepalives) with the HA2 link (data link for session sync), leading them to incorrectly select Option A when the actual failover trigger is loss of HA1 keepalive, not HA2 link failure.

How to eliminate wrong answers

Option A is wrong because the HA2 link is used for session synchronization and state propagation, not for keepalive monitoring; a HA2 link failure alone does not trigger a failover unless it also causes HA1 keepalive loss. Option B is wrong because a preemption event would be logged as 'Preempted by local firewall' or 'Preempted by peer firewall', not as a keepalive loss; preemption is a configuration-based event that occurs when the higher-priority firewall comes back online. Option C is wrong because if the peer firewall was rebooted, the failover reason would typically show 'Peer firewall rebooted' or 'HA1 keepalive from the peer was lost' only if the reboot caused keepalive failure, but the direct cause logged is the keepalive loss, not the reboot itself.

303
MCQhard

A security administrator is configuring a firewall to inspect traffic between two internal zones. The administrator wants to ensure that the firewall performs application identification and content inspection on all allowed traffic. Which configuration is required to achieve this?

A.Configure a Decryption policy to forward traffic to a content inspection engine.
B.Create a security policy with the action 'allow' and enable 'Log at Session End'.
C.Enable SSL decryption on the firewall for all traffic between the zones.
D.Create a security policy that allows the traffic and attach a Security Profile Group to the policy.
AnswerD

To perform application identification and content inspection, a security policy must be created that allows the traffic and has a Security Profile Group attached. The Security Profile Group includes profiles for antivirus, anti-spyware, vulnerability protection, URL filtering, and file blocking. Without attaching these profiles, the firewall only performs App-ID but not content inspection.

Why this answer

To perform application identification and content inspection on allowed traffic, a security policy must allow the traffic and have a Security Profile Group attached. The Security Profile Group contains the necessary profiles for antivirus, anti-spyware, vulnerability protection, URL filtering, and file blocking. Without these profiles, the firewall only identifies the application but does not inspect the content for threats.

Exam trap

The trap here is confusing SSL decryption with content inspection; decryption is only needed for encrypted traffic, while content inspection requires Security Profiles.

304
MCQmedium

A firewall is configured with a destination NAT rule to translate public IP 203.0.113.10 to internal server 10.0.0.5 on port 443. Internal users from 10.0.0.0/24 can access the server using its private IP, but cannot access using the public IP. What should be configured to allow internal users to reach the server using the public IP?

A.Configure a source NAT rule that translates the internal source IP to the firewall's interface IP when the destination is the public IP.
B.Create a policy-based forwarding (PBF) rule to send the traffic to the server.
C.Add a security policy allowing traffic from internal zone to the public IP.
D.Add a static route on the firewall for the public IP pointing to the internal server.
AnswerA

Internal clients hitting the public IP create a flow where the server replies directly to the private source, bypassing the firewall and breaking the session. Source NAT rewrites the source to the firewall interface IP, forcing return traffic back through the firewall for correct translation.

Why this answer

When internal users send traffic to the public IP (203.0.113.10), the firewall performs destination NAT, translating the destination to 10.0.0.5. However, the return traffic from the server is sent directly to the internal user's IP (since they are on the same subnet), bypassing the firewall and causing asymmetric routing. A source NAT rule (often called NAT hairpin or NAT reflection) translates the internal source IP to the firewall's interface IP, forcing return traffic to go through the firewall and maintain session state.

Exam trap

The trap here is that candidates often think a security policy or route is sufficient, but they miss the fundamental requirement for symmetric routing in stateful firewalls, where the return traffic must traverse the same firewall that performed the NAT.

How to eliminate wrong answers

Option B is wrong because policy-based forwarding (PBF) is used to route traffic based on criteria like source/destination IP or application, not to solve NAT hairpin issues; it would not fix the asymmetric routing problem. Option C is wrong because a security policy alone does not address the NAT or routing issue; the traffic is already allowed if the server is reachable via private IP, and the problem is that the return traffic bypasses the firewall. Option D is wrong because adding a static route for the public IP pointing to the internal server would cause the firewall to route traffic directly to the server without performing NAT, breaking the translation and potentially causing routing loops or incorrect forwarding.

305
MCQmedium

The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?

A.The VLAN ID is misconfigured as 20 instead of 10.
B.The IP netmask is /24 but should be /16.
C.The zone is incorrectly named 'VLAN10'.
D.The virtual router is not correctly set.
AnswerA

The sub-interface's VLAN tag must match the VLAN ID carried in the 802.1Q frame. Tagging it as VLAN 20 means frames arriving with VLAN 10 tags are dropped, so no traffic reaches the 192.168.10.1/24 gateway and routing fails.

Why this answer

The exhibit shows the sub-interface is configured with VLAN ID 20, but the administrator intended VLAN 10. In Palo Alto Networks firewalls, sub-interfaces use 802.1Q VLAN tagging, and the VLAN ID must match the tag on incoming frames. Mismatched VLAN IDs cause the firewall to drop or ignore traffic because the sub-interface only processes frames with the configured tag.

Exam trap

The trap here is that candidates often confuse the VLAN ID on the sub-interface with the IP subnet or zone name, assuming a mismatch in IP addressing or zone naming is the root cause, when in fact the VLAN tag mismatch is the direct and immediate reason traffic is not processed.

How to eliminate wrong answers

Option B is wrong because the /24 netmask is correct for a /24 subnet (192.168.10.0/24); a /16 would incorrectly expand the subnet to 192.168.0.0/16, causing routing issues but not preventing VLAN 10 traffic from reaching the interface. Option C is wrong because the zone name 'VLAN10' is purely a logical label and has no effect on VLAN tagging or traffic forwarding; zones are security boundaries, not VLAN identifiers. Option D is wrong because the virtual router assignment is independent of VLAN tagging; even if the virtual router were misconfigured, traffic would still reach the sub-interface and be processed, but routing would fail later—not the cause of traffic not being routed through the interface.

306
Multi-Selecthard

Which THREE of the following can cause App-ID to incorrectly identify traffic?

Select 3 answers
A.Multiple security rules are configured for the same traffic.
B.Asymmetric routing causes the firewall to see only one direction of traffic.
C.SSL decryption is not enabled for the traffic.
D.IP fragmentation occurs before the firewall.
E.Traffic is forwarded through an HTTP proxy.
AnswersB, C, D

Asymmetric routing can prevent the firewall from seeing the full session, causing inaccurate identification.

Why this answer

Asymmetric routing causes App-ID to see only one direction of traffic (e.g., SYN but no SYN-ACK). App-ID relies on bidirectional flow inspection to identify applications; without seeing both directions, the firewall cannot complete the application signature match or protocol handshake, leading to incorrect or failed identification.

Exam trap

The trap here is that candidates often think IP fragmentation is a rare or non-impactful scenario, but it directly prevents App-ID from seeing complete application headers, making it a common cause of misidentification in real-world networks.

307
MCQmedium

A network engineer is configuring App-ID for a custom application that uses a proprietary protocol over TCP port 12345. The application's traffic is not being identified as expected. Which configuration change should the engineer make to ensure the firewall correctly identifies this application?

A.Create a security policy rule with an application override to match the port.
B.Define a custom application with the appropriate protocol, port, and optionally a signature.
C.Enable SSL decryption on the traffic to inspect encrypted payloads.
D.Add the port to the default application's 'port' field in the application object.
AnswerB

App-ID identifies applications by signature and protocol behaviour, not port alone. Since the proprietary protocol runs on a non-standard TCP port, a custom application object must be defined with the correct protocol, port and, where possible, a signature so the firewall can match and classify the traffic correctly.

Why this answer

When a custom application uses a proprietary protocol over a non-standard port, the firewall cannot rely on its built-in App-ID signatures. By defining a custom application object with the correct protocol (TCP), port (12345), and optionally a protocol-level signature (e.g., a byte pattern or sequence), the firewall can accurately identify the traffic. This ensures that App-ID can match the traffic even if the port is not commonly associated with any known application.

Exam trap

The trap here is that candidates often confuse 'application override' (which disables App-ID) with 'custom application' (which enhances App-ID), leading them to choose option A when they should instead define a new application object with the correct port and signature.

How to eliminate wrong answers

Option A is wrong because an application override bypasses App-ID entirely, forcing the firewall to treat all traffic on that port as the specified application, which defeats the purpose of dynamic identification and can lead to misclassification or security gaps. Option C is wrong because SSL decryption is irrelevant for a proprietary protocol that does not use TLS/SSL; decrypting encrypted payloads would not help if the traffic is not encrypted or if the protocol is not HTTP-based. Option D is wrong because modifying the default application's 'port' field would incorrectly associate a custom protocol with a built-in application, potentially causing false positives and breaking App-ID's ability to distinguish between applications.

308
MCQmedium

An organization uses a SaaS application that runs on a dynamic set of IP addresses. The application traffic is currently identified as ssl and not as the specific application. How can the administrator improve application identification for this SaaS application?

A.Disable App-ID for that traffic to reduce overhead.
B.Create a custom application with hostname conditions.
C.Use a port-based application override.
D.Configure a URL filtering category for the application.
AnswerB

Hostname conditions inspect the TLS SNI or HTTP Host header, which stays constant even as the SaaS provider rotates IP addresses. This lets App-ID identify the application by name rather than relying on static IPs, resolving the dynamic-address constraint that currently forces classification as generic ssl.

Why this answer

App-ID can identify SaaS applications by hostname conditions when the application uses a dynamic set of IP addresses. By creating a custom application with hostname conditions (e.g., matching the FQDN of the SaaS service), the firewall can accurately identify the traffic as that specific application rather than generic SSL, even as the backend IPs change. This leverages the firewall's ability to inspect the Server Name Indication (SNI) field in the TLS handshake or the HTTP Host header.

Exam trap

The trap here is that candidates often assume port-based overrides (Option C) are the only way to identify traffic, but they fail to recognize that hostname-based conditions in custom applications provide a more precise and dynamic identification method for SaaS applications with changing IP addresses.

How to eliminate wrong answers

Option A is wrong because disabling App-ID would prevent all application identification, making the traffic even less identifiable and defeating the purpose of improving application identification. Option C is wrong because a port-based application override maps traffic to an application based solely on the destination port (e.g., TCP 443), which would not distinguish this SaaS application from any other HTTPS traffic and would not leverage hostname or SNI. Option D is wrong because URL filtering categories are based on URL patterns and categories, not on application identity; configuring a URL filtering category would not change how App-ID classifies the traffic, and the traffic would still be identified as ssl rather than the specific application.

309
MCQmedium

Refer to the exhibit. An engineer configures HA with link monitoring and path monitoring. However, failover does not occur when ethernet1/2 goes down. What is the likely reason?

A.The HA group-id is not unique in the network
B.HA2 link is down preventing failover
C.Path monitoring interval is set too high, causing delayed failover
D.'link-monitoring' is configured under the high-availability hierarchy but not explicitly enabled
AnswerD

In PAN-OS, link monitoring must be enabled with 'enable yes' under high-availability; interfaces alone do not enable it.

Why this answer

In Palo Alto Networks HA configuration, link monitoring is not enabled by default even when the 'link-monitoring' block is present under the 'high-availability' hierarchy. The engineer must explicitly set 'enabled yes' within the 'link-monitoring' configuration to activate it. Without this explicit enable, the firewall will not monitor the specified interfaces for link state changes, so a failure on ethernet1/2 will not trigger a failover.

Exam trap

The trap here is that candidates assume that simply adding the 'link-monitoring' configuration stanza under the HA hierarchy automatically enables link monitoring, when in fact the 'enabled yes' parameter is required to activate it.

How to eliminate wrong answers

Option A is wrong because a non-unique HA group-id would cause both peers to attempt to be active or passive simultaneously, leading to split-brain or failover issues, but it would not prevent failover when a monitored link goes down; the failover would still occur if link monitoring were properly enabled. Option B is wrong because the HA2 link is used for session synchronization and heartbeat, not for link monitoring; if the HA2 link were down, the firewalls would lose heartbeat and potentially both become active, but this would not prevent a link-monitoring-based failover from occurring when ethernet1/2 goes down. Option C is wrong because the path monitoring interval controls how often the firewall checks the reachability of monitored paths (e.g., ping to a next-hop IP), not the link state of an interface; link monitoring reacts immediately to link state changes (up/down) and is not affected by the path monitoring interval.

310
MCQhard

A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?

A.Add the banking site's certificate to the firewall's trusted certificate list and set the decryption policy to 'decrypt'.
B.Create a decryption policy rule with the action 'no-decrypt' and match the banking site's URL category or FQDN.
C.Configure a decryption profile with 'Block Untrusted Issuers' enabled and apply it to the decryption policy rule.
D.Modify the existing decryption policy rule to exclude the banking site by adding its IP address to the source field.
AnswerB

A decryption policy rule with action 'no-decrypt' allows specific traffic to bypass decryption based on criteria such as URL category, source, destination, or service. Placing this rule above the decryption rule ensures that traffic to the banking site is excluded from decryption while other HTTPS traffic is still decrypted. This is the correct method to selectively bypass decryption.

Why this answer

To exclude specific traffic from SSL decryption, a decryption policy rule with the action 'no-decrypt' must be created and placed above the decryption rule. This rule can match on various criteria such as URL category, FQDN, or source/destination. This ensures that the banking site's traffic bypasses decryption while other HTTPS traffic continues to be decrypted.

Exam trap

The trap here is confusing decryption profiles with decryption policy actions; profiles control how to handle decrypted traffic, while policy rules determine whether to decrypt or not.

311
MCQeasy

A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?

A.Check the security policy rulebase order and matching
B.Verify the user-ID agent is mapping the IP correctly
C.Check the service configuration for the destination port
D.Check the NAT configuration for the user's subnet
AnswerA

Security policies are evaluated top-down, so a deny rule above the permit rule for 10.1.1.0/24 would block this user despite the allow existing. Verifying rulebase order and matching confirms which rule actually handles the session, satisfying the need to identify why permitted subnet traffic is dropped.

Why this answer

The first thing to verify is the security policy rulebase order and matching because Palo Alto Networks firewalls evaluate rules in a top-down order and apply the first matching rule. Even if a rule exists that allows traffic from subnet 10.1.1.0/24 to any, a preceding rule with a deny action or a more specific match could be blocking the traffic from 10.1.1.100. Checking rule order ensures that the intended allow rule is actually being hit before investigating other potential issues.

Exam trap

The trap here is that candidates often jump to NAT or service configuration issues, but the PCNSE exam emphasizes that rule order and first-match logic are the most common root cause of unexpected blocks, especially when a seemingly correct allow rule exists.

How to eliminate wrong answers

Option B is wrong because verifying the User-ID agent mapping is only relevant if the security policy uses user-based criteria (e.g., source user), but the rule in question is based on source IP (subnet 10.1.1.0/24), not user identity. Option C is wrong because checking the service configuration for the destination port is secondary; if the rule is not matched due to order, service configuration is irrelevant until the correct rule is identified. Option D is wrong because NAT configuration affects the translated IP address, not the pre-NAT source IP used for policy matching; the firewall applies security policy before NAT, so NAT issues would not cause the traffic to be blocked by a policy that matches the original source IP.

312
MCQeasy

A firewall administrator is troubleshooting a connectivity issue where users cannot reach a web server. The administrator checks the traffic log and sees that the session is being denied by a security policy rule. The administrator verifies that the rule is correctly configured to deny the traffic. However, the administrator wants to see which rule is blocking the traffic. Which action should the administrator take?

A.Use the 'test security-policy-match' command with the source and destination IP addresses.
B.Check the system log for a policy deny message.
C.Run 'show session all filter source <user-ip>' and look at the 'rule' column.
D.Check the traffic log details for the session and look at the 'Rule' field.
AnswerD

The traffic log includes a 'Rule' field that specifies the name of the security policy rule that matched the session. By examining the log details, the administrator can identify exactly which rule denied the traffic. This is the most direct method. The log entry will also show the action taken. This is a fundamental troubleshooting step for policy-related issues.

Why this answer

The traffic log contains detailed information about each session, including the name of the security policy rule that matched. By viewing the log details, the administrator can see the 'Rule' field and identify the blocking rule. This is the standard method for determining which policy rule is affecting traffic.

Other commands like 'test security-policy-match' are for simulation, and session table output does not include rule names.

Exam trap

The trap here is using the session table or system logs to find the rule, but the rule name is only available in the traffic log details.

313
Multi-Selecthard

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Select 3 answers
A.Active/Passive HA with floating IP
B.ECMP with equal cost routes
C.Policy Based Forwarding combined with path monitoring
D.Active/Passive HA with virtual router synchronization
E.Use of multiple public IPs with NAT rules
AnswersA, B, C

Active/passive HA keeps the standby firewall ready, and the floating IP moves to the passive device on failover, so outbound traffic continues through the surviving peer. This satisfies redundancy at the device level rather than the path level.

Why this answer

Active/Passive HA with floating IP (Option A) is valid because the passive firewall assumes the active firewall's IP address upon failover, ensuring outbound traffic continues via the same default gateway. ECMP with equal cost routes (Option B) distributes outbound traffic across multiple paths and provides redundancy by automatically failing over if one path is lost. Policy Based Forwarding combined with path monitoring (Option C) allows you to define forwarding policies based on traffic attributes and monitor path health, redirecting traffic if a monitored path fails.

Exam trap

The trap here is that candidates confuse virtual router synchronization (which only replicates routing tables) with actual failover mechanisms like floating IPs or path monitoring, assuming that synchronized routing alone provides redundancy for outbound traffic.

314
MCQmedium

An engineer checks the application counter and sees that my-custom-app has zero packets, but they expected traffic from 10.0.0.0/24 to 10.1.0.0/24 to be identified as my-custom-app. What is the most likely reason?

A.The traffic is being identified as ssl instead.
B.The application override rule does not have the correct port.
C.The security policy does not allow the traffic.
D.The custom application my-custom-app is not committed.
AnswerB

Application override rules match on the port defined in the override, not the signature's default. If the configured port differs from the actual destination port carrying the traffic, the override never triggers, so the custom app counter stays at zero despite matching source and destination subnets.

Why this answer

An application override rule explicitly maps traffic to a custom application based on IP address, protocol, and port. If the port in the override rule does not match the actual destination port used by the traffic (e.g., TCP/8080 instead of TCP/80), the firewall will not classify the traffic as my-custom-app, resulting in zero packets for that application counter. The traffic may still pass but will be identified by App-ID as another application or remain unidentified.

Exam trap

The trap here is that candidates often assume the issue is with the security policy blocking traffic (Option C) or with the application not being committed (Option D), but the zero-packet counter specifically for the custom app points to a matching failure in the override rule, not a policy or commit problem.

How to eliminate wrong answers

Option A is wrong because if the traffic were identified as ssl, the application counter for my-custom-app would still show zero packets, but the question states the engineer expected the traffic to be identified as my-custom-app, implying an override or custom signature is in place; SSL identification would only occur if no override matched and App-ID detected SSL handshake, which is not the most likely reason given the expectation of a custom app. Option C is wrong because if the security policy did not allow the traffic, the packets would be dropped and the application counter for my-custom-app would still show zero, but the engineer would likely see deny logs or zero byte counts across all counters, not just the custom app; the question focuses on identification, not permission. Option D is wrong because if my-custom-app were not committed, the application object would not exist in the running configuration, and the firewall would not have a counter for it at all; the fact that the counter exists and shows zero packets indicates the object is committed but not matching traffic.

315
Multi-Selecteasy

A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Create a syslog server profile under Device > Server Profiles > Syslog.
B.Create an SNMP trap profile under Device > Server Profiles > SNMP Trap.
C.Directly apply the syslog server profile to each Security policy rule.
D.Enable log forwarding under the firewall's Device > Setup > Logging and Reporting settings.
E.Create a Log Forwarding profile that references the syslog server profile and apply it to Security policy rules.
AnswersA, E

A syslog server profile is required to define the destination syslog server.

Why this answer

A syslog server profile must first be created under Device > Server Profiles > Syslog to define the external syslog server's IP address, port (default 514), and transport protocol (UDP/TCP). This profile is a prerequisite for any log forwarding to an external syslog server.

Exam trap

The trap here is that candidates mistakenly think a syslog server profile can be applied directly to a Security policy rule, but the PCNSE exam requires understanding that a Log Forwarding profile is the mandatory intermediary object.

316
MCQmedium

A firewall administrator is troubleshooting an issue where users behind a PA-3220 cannot access a public web server. The security policy allows the traffic. The administrator runs 'show session all filter source 10.1.1.50 destination 203.0.113.10' and sees a session with application 'incomplete' and no packets received from the server. Which tool should the administrator use to determine why the firewall is not receiving a response from the server?

A.Use the packet capture feature with a filter on the source and destination IP addresses to capture traffic on both ingress and egress interfaces.
B.Review the traffic logs filtered by the application 'incomplete' to see the session end reason.
C.Check the ARP table for the destination IP address to ensure the next-hop MAC address is resolved.
D.Run 'show counter global filter delta yes' to check for packet buffer drops.
AnswerA

Packet capture allows the administrator to see if the request is leaving the egress interface and whether any response is arriving on the ingress interface. This directly addresses the 'no packets received from server' symptom. By capturing on both interfaces, the administrator can determine if the firewall is dropping the packet or if the server is not responding.

Why this answer

The session shows application 'incomplete' and no packets received from the server, indicating the firewall may not be receiving a response. Packet capture on both ingress and egress interfaces will show if the request is sent and if any reply arrives, helping isolate whether the issue is with the firewall, network path, or server. Other tools like global counters or ARP checks do not provide the same level of detail for this specific flow.

Exam trap

The trap here is assuming that a session with application 'incomplete' always indicates a firewall drop, when it could simply mean the server is not responding or the return path is broken.

317
Multi-Selecteasy

Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)

Select 2 answers
A.Enable Threat Prevention profiles to block known malware
B.Configure logging for all traffic to enable monitoring and troubleshooting
C.Leave the default admin password until the next audit
D.Use the default NAT policies provided by the initial configuration
E.Manually download dynamic updates daily to ensure latest signatures
AnswersA, B

Branch traffic traverses the firewall to reach the internet, so attaching Threat Prevention profiles to the relevant security rules inspects that traffic and drops known malware and vulnerability exploits. This satisfies the requirement to secure the branch against external threats at the enforcement point.

Why this answer

Enabling Threat Prevention profiles (A) is correct because it applies IPS signatures to block known malware, exploits, and vulnerabilities inline, which is essential for branch office security without requiring constant manual intervention. Configuring logging for all traffic (B) is correct because it provides visibility for monitoring, troubleshooting, and compliance, and is necessary for effective use of features like ACC and reporting.

Exam trap

The trap here is that candidates may think default NAT policies are acceptable for branch offices or that manual updates are more reliable, but the PCNSE exam emphasizes automation and security best practices, making options D and E incorrect due to their lack of scalability and security posture.

318
MCQeasy

A company uses a Palo Alto Networks firewall with App-ID enabled. They have a custom application that communicates over TCP port 5001. The administrator has created a custom App-ID signature and a security rule that allows this application from the internal zone (trust) to the external zone (untrust). Users report that the custom application traffic is being blocked. The administrator checks the traffic logs and sees that the sessions are being matched to a different security rule that denies any traffic from trust to untrust. The deny rule appears before the custom allow rule in the policy list. The custom App-ID signature is properly defined and tested. What should the administrator do to resolve this issue?

A.Modify the custom App-ID signature to match more precisely.
B.Create an application override for the custom application.
C.Add a virtual wire interface to ensure traffic reaches the firewall.
D.Reorder the security rules so the custom allow rule is above the deny rule.
AnswerD

Security rules are evaluated top-down, so the earlier deny rule matches the traffic before the custom allow rule is reached. Moving the allow rule above the deny rule satisfies the requirement that App-ID-permitted traffic be evaluated first, resolving the block.

Why this answer

Security rules in Palo Alto Networks firewalls are evaluated in top-down order, and the first matching rule is applied. Since the deny rule appears before the custom allow rule, all traffic matching the deny rule's criteria (including the custom application) is blocked before reaching the allow rule. Reordering the rules so the custom allow rule is above the deny rule ensures the custom application traffic is permitted as intended.

Exam trap

The trap here is that candidates often focus on App-ID configuration (options A or B) rather than recognizing that the fundamental issue is rule ordering, which is a core concept in Palo Alto Networks policy evaluation.

How to eliminate wrong answers

Option A is wrong because the custom App-ID signature is already properly defined and tested, so modifying it further would not change the rule-matching order; the issue is policy ordering, not signature accuracy. Option B is wrong because an application override bypasses App-ID identification by forcing the firewall to treat traffic as a specific application, but this does not resolve the rule-order problem; the traffic would still hit the deny rule first. Option C is wrong because a virtual wire interface is a deployment mode for transparent inline inspection and does not affect security rule evaluation order or traffic matching; the firewall is already receiving the traffic.

319
MCQeasy

Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?

A.SAML identity provider profile
B.LDAP server profile
C.RADIUS server
D.Kerberos realm
AnswerA

SAML-Auth requires a SAML identity provider profile because the firewall acts as service provider, validating assertions signed by the external IdP. This profile supplies the IdP's certificate and metadata needed to verify signatures, satisfying the exhibit's requirement for SAML-based authentication rather than local or certificate-based methods.

Why this answer

The exhibit shows a SAML-based authentication flow where the firewall redirects the user to an external identity provider (IdP) for authentication. The authentication profile 'SAML-Auth' must reference a SAML identity provider profile to define the IdP metadata, entity ID, SSO URL, and certificate binding. Without this profile, the firewall cannot initiate or validate SAML assertions, making option A the only correct choice.

Exam trap

Palo Alto Networks emphasizes the distinction between authentication profiles (which define the authentication method) and server profiles (which define server connections). Candidates often mistakenly select LDAP or RADIUS profiles instead of the SAML identity provider profile required for SAML-based authentication.

How to eliminate wrong answers

Option B is wrong because LDAP server profiles are used for direct LDAP bind authentication against an on-premises directory, not for SAML-based federated authentication. Option C is wrong because RADIUS server profiles are used for RADIUS-based authentication (e.g., with 802.1X or VPN), which does not support SAML assertions or IdP redirection. Option D is wrong because Kerberos realms are used for Kerberos-based authentication (typically with Active Directory in a domain environment), not for SAML identity provider configuration.

Page 4

Page 5 of 5

All pages