PCNSE Core Concepts and Architecture Practice Question
An administrator configures the management interface with IP 192.168.1.1/24 and can ping it from a host on the same subnet, but cannot access the web interface. What is the likely cause?
⚠ Common exam trap
Test-takers frequently assume a reachable IP (via ping) implies all management services are accessible, but Palo Alto separates ICMP from HTTP/HTTPS in the management profile, so ping success does not guarantee web access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HTTP/HTTPS is not enabled in the interface management profile.
The management interface on a Palo Alto Networks firewall requires an explicit management profile that enables HTTP/HTTPS access. Even if the interface has a valid IP and is reachable via ping (ICMP), the web server will not respond to HTTP/HTTPS requests unless the corresponding services are enabled in the interface management profile. By default, the management interface may have a profile that allows only ping, not web access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The web server is not running.
Why it's wrong here
A stopped web server explains unreachable HTTPS while ICMP still replies, but the stem implies a fresh management configuration, where the default cause is an interface management-service profile lacking HTTP/HTTPS. It is tempting because disabling the web service does produce identical symptoms, and it would be correct if the service had been deliberately turned off.
- ✗
The host is not in the allowed IP list.
Why it's wrong here
Permitted IP addresses restrict which hosts may reach the management interface, so a blocked host would also fail to ping it, contradicting the stem. It is tempting because permitted-IP lists genuinely gate management access, and it would be the answer if ping succeeded from one host but the web UI refused a different, unlisted host.
- ✗
The firewall is in FIPS mode.
Why it's wrong here
FIPS mode restricts cryptographic algorithms, not management-plane access; ICMP replies would still succeed and the web UI would remain reachable. It is tempting because FIPS mode genuinely affects firewall operation, and it would be the answer if the scenario involved non-compliant ciphers or certificate failures rather than a silent web service.
- ✓
HTTP/HTTPS is not enabled in the interface management profile.
Why this is correct
Ping succeeds because ICMP is permitted by default on the management interface, but the web interface requires HTTP or HTTPS explicitly enabled within the interface management profile; without that service permitted, management access is refused.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.