Courseiva

PCNSE · domain

Core Concepts and Architecture

Core Concepts and Architecture covers the PAN-OS dataplane and control plane: security zones, virtual routers and virtual systems, interface types, session setup and teardown, and management-plane access. Questions are scenario-based exhibits showing session details, routing between virtual routers, or management interface reachability, requiring you to identify the specific PAN-OS component or setting responsible.

54 questions18 easy21 medium15 hard

Focused practice

Practice Core Concepts and Architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Core Concepts and Architecture

Be able to read session details and map each end reason to its cause, trace traffic between virtual routers, and verify management interface services and profiles. The single most important thing: know that aged-out is a normal timeout, not a block.

Session end reasons such as aged-out, policy-deny, and tcp-fin in the session details view

Inter-virtual-router routing between VR1 and VR2 via shared interfaces or static routes

Management interface access requiring permitted services (HTTPS, SSH, ping) on the management profile

Security zone and interface configuration for Layer 2, Layer 3, virtual wire, and tunnel modes

Watch out for

Common Core Concepts and Architecture exam traps

  • ▸Assuming aged-out means the session was denied by policy; it actually means the session timed out after inactivity and is normal traffic behavior.
  • ▸Believing two virtual routers exchange routes automatically; traffic between VRs needs explicit routes or an inter-VR path, not just shared subnets.
  • ▸Forgetting that the management interface needs an allowed service in its management profile before HTTPS or SSH access works, even when ping succeeds.

Question index

All Core Concepts and Architecture questions (54)

Click any question to see the full explanation, or start a practice session above.

1

A network security engineer is deploying a Palo Alto Networks firewall in a high-availability (HA) active/passive configuration. The engineer wants to ensure that the passive firewall takes over seamlessly if the active firewall fails. Which of the following is a requirement for HA active/passive configuration?

Hard
2

Which THREE of the following are key differences between the Palo Alto Networks Next-Generation Firewall and Cloud-Delivered Security Services (CDSS)?

Hard
3

A help desk ticket reports that a user cannot access the firewall's web management interface (HTTPS) from the management network. The management interface is on a dedicated MGMT network. Which setting must be enabled on the firewall to allow this access?

Easy
4

A security engineer is designing a Palo Alto Networks firewall deployment for a multi-tenant environment. The engineer needs to ensure that each tenant's traffic is isolated and that security policies can be applied per tenant. The engineer plans to use Virtual Systems (vsys) to achieve this. Which two statements about Virtual Systems (vsys) are true? (Choose two.)

Hard
5

An organization uses User-ID with agent-based mapping on a Palo Alto Networks firewall. Users authenticate to a domain but some user-to-IP mappings are not showing up in the firewall's user cache. The firewall can reach the domain controllers. What is the most likely cause?

Hard
6

An organization is implementing SSL Forward Proxy decryption to inspect outbound HTTPS traffic. They want to exclude traffic to specific internal applications that cannot handle decryption due to certificate pinning. The firewall is configured with a decryption policy that decrypts all traffic from the internal network to the internet. To exclude the pinned applications, which approach is best practice?

Hard
7

A security engineer is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for inspection. The firewall is deployed in a forward proxy mode. The engineer wants to ensure that the firewall can decrypt traffic without generating certificate errors on client browsers. Which configuration is required to achieve this?

Medium
8

A network security engineer is deploying a PA-5220 firewall in a data center. The firewall must inspect traffic between two internal segments (trust and dmz) and also provide security for outbound internet access. The engineer wants to ensure that when a packet arrives, the firewall properly identifies the application and enforces security policies. Which component is responsible for identifying the application regardless of port, protocol, or encryption?

Medium
9

A security engineer is troubleshooting a traffic drop issue on a Palo Alto Networks firewall. The traffic is allowed by the security policy, but the session is being terminated. Which two features could cause this behavior? (Choose two.)

Medium
10

A security engineer wants to identify applications in SSL/TLS encrypted traffic without decrypting the payload. Which method can be used?

Medium
11

A network administrator is configuring a new Palo Alto Networks firewall in a high-availability active/passive setup. The firewall will be placed in Layer 3 mode. Which THREE steps are required to ensure proper operation? (Choose three.)

Hard
12

A security administrator is configuring a new Palo Alto Networks firewall and needs to enable App-ID to identify applications traversing the network. The administrator wants to ensure that App-ID can correctly identify applications even when they use non-standard ports or encryption. Which feature must be enabled to allow App-ID to inspect encrypted traffic?

Easy
13

A network security engineer is designing a multi-vsys Palo Alto Networks firewall deployment to provide both advanced security and virtual routing separation for three different departments. Each department requires its own routing table and separate security policy enforcement. The engineer must decide which component is responsible for enforcing security policies and providing threat inspection across all virtual systems. Which component of the Palo Alto Networks Next-Generation Firewall performs this function?

Medium
14

An administrator is reviewing the firewall's session table and notices many sessions in a 'discard' state. What is the most likely cause of this session state?

Medium
15

A firewall administrator notices that traffic from a specific subnet is being unexpectedly dropped. The firewall log shows a 'flow_drop' reason of 'packet too long for interface MTU'. The interface MTU is set to 1500, and the packets are 1500 bytes. What is the most likely cause?

Hard
16

A company needs to deploy a firewall in transparent inline mode to filter traffic between two switches without requiring any IP address changes on existing devices. Which interface type should be configured?

Easy
17

A security administrator wants to block traffic from IP address 192.168.1.100 to the internet. The firewall has a security policy that allows all outbound traffic. Which action should be taken to most efficiently block this specific host?

Easy
18

A network administrator is setting up a new Palo Alto Networks firewall. The administrator needs to configure the firewall so that it can resolve domain names for its own management traffic, such as for updates and logging. Which type of interface should be configured with a default gateway to allow the firewall to reach external services?

Easy
19

Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?

Easy
20

A company has two Palo Alto Networks firewalls configured in an active/passive HA pair. Traffic fails over correctly, but after a failover, existing sessions from external users to internal servers are broken. The security team wants to prevent this disruption. Which feature must be enabled?

Medium
21

A firewall is configured with multiple virtual systems (vsys). The administrator notices that one vsys is consuming excessive dataplane resources, affecting others. Which feature should be used to guarantee each vsys a minimum share of CPU and session capacity?

Hard
22

Two Palo Alto Networks firewalls are configured in an active/passive HA pair. During a scheduled maintenance, the network team reboots both firewalls simultaneously. After reboot, both firewalls appear as 'active' in the HA state. What is the most likely cause and the correct troubleshooting step?

Hard
23

A network security administrator is deploying a new PA-3220 firewall in a data center. The security team requires that all traffic traversing the firewall be inspected for threats, but they want to minimize latency for trusted internal traffic that is already known to be benign. The administrator decides to create a security policy rule that allows traffic from the 'Trust' zone to the 'DMZ' zone without any security profiles attached. Which statement accurately describes the behavior of this rule?

Easy
24

A company implements SSL Forward Proxy decryption. Users complain that accessing certain websites, such as video streaming and software updates, is slow. Which action should the administrator take to improve performance?

Medium
25

An administrator configures the management interface with IP 192.168.1.1/24 and can ping it from a host on the same subnet, but cannot access the web interface. What is the likely cause?

Easy
26

A security administrator is designing a zero trust architecture using Palo Alto Networks Next-Generation Firewalls. They need to ensure that all traffic between the internal network and the internet is inspected, and that users are identified regardless of location. Which two components are required to achieve user identification for both on-premises and remote users? (Choose two.)

Medium
27

A network security administrator is configuring a new Palo Alto Networks firewall and wants to ensure that traffic between two internal subnets is inspected by the firewall. The subnets are on different interfaces. What must be configured to allow the firewall to inspect this traffic?

Easy
28

Which Panorama deployment mode allows centralized management of firewalls while storing logs locally on each firewall instead of sending them to the Panorama log collector?

Easy
29

A security administrator configures a new network template in Panorama and assigns it to a template stack. The template stack is associated with a device group containing several firewalls. After committing the Panorama configuration and pushing to devices, some firewalls in the device group do not have the new template settings. What is the most likely cause?

Medium
30

A network security engineer is troubleshooting why a Palo Alto Networks firewall is not enforcing a security policy that should block traffic from the untrust zone to the trust zone. The policy is configured correctly, and the firewall is receiving traffic. The engineer suspects that the traffic is being allowed by a different policy due to policy evaluation order. Which factor determines the order in which security policies are evaluated?

Hard
31

An administrator is troubleshooting why a Security policy rule that allows traffic from the 'trust' zone to the 'untrust' zone is not matching for certain sessions. The administrator notices that the sessions are being denied by an interzone rule. What is the most likely cause?

Medium
32

Which component of the PAN-OS architecture is responsible for processing security policies and performing packet inspection?

Easy
33

Which THREE of the following are core components of the GlobalProtect solution? (Choose exactly three.)

Easy
34

A security administrator is configuring a Palo Alto Networks firewall and needs to ensure that traffic from the trust zone to the untrust zone is inspected for threats. The administrator wants to enable threat prevention profiles on the security policy. Which Palo Alto Networks feature is responsible for detecting and preventing threats such as viruses, spyware, and command-and-control traffic?

Easy
35

An administrator needs to allow FTP traffic from the internal network to an external server. The firewall is configured with a security policy that has the application 'ftp' and service 'service-http'. What is the most likely cause of the traffic being denied?

Easy
36

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that management traffic is separated from data traffic. Which interface type should be used for out-of-band management?

Easy
37

A company has a Palo Alto Networks firewall with two virtual systems (vsys) configured. The administrator wants to ensure that traffic between vsys1 and vsys2 is inspected by the firewall. What must be configured to allow this inter-vsys traffic?

Medium
38

Which TWO of the following are true regarding Panorama's templates and device groups?

Medium
39

A firewall administrator is configuring a new security zone for a DMZ. The requirement is that the DMZ zone should not be able to initiate connections to the internal trusted zone, but the trusted zone should be able to initiate connections to the DMZ. Which configuration achieves this with the least administrative effort?

Easy
40

Refer to the exhibit. What does the serial number '0123456789' indicate?

Easy
41

Which TWO components are part of the PAN-OS management plane?

Easy
42

A security administrator is designing a zero-trust architecture using Palo Alto Networks firewalls. They want to ensure that traffic between two internal zones is inspected and that access is granted based on user identity and device posture rather than IP address alone. Which two PAN-OS features must be implemented to meet these requirements? (Choose two.)

Hard
43

A security engineer needs to deploy a Palo Alto Networks firewall in a high-availability (HA) pair with active/passive mode. The firewall will inspect traffic for multiple tenants, each requiring separate routing and policy configuration. Which feature should be used to isolate tenant configurations while using a single pair of firewalls?

Medium
44

A firewall has two virtual routers: VR1 (for internal networks) and VR2 (for DMZ). An internal server in VR1 needs to reach a DMZ server in VR2. Both virtual routers have routes to each other's subnets via a shared inter-connect. The firewall is receiving traffic but is dropping packets between the virtual routers. What configuration is missing?

Medium
45

An administrator is configuring a Palo Alto Networks firewall to perform SSL decryption for outbound traffic. The administrator wants to ensure that traffic to certain categories, such as financial services, is not decrypted due to privacy concerns. What should the administrator configure?

Hard
46

A network security engineer is troubleshooting why a newly installed Palo Alto Networks firewall is not inspecting traffic between two internal subnets. The engineer confirms that the traffic is routed through the firewall, security policies are configured to allow and inspect the traffic, and no drop counters are incrementing. However, the firewall's session table shows sessions in an 'ACTIVE' state but with no application identified. Which component of the Palo Alto Networks Next-Generation Firewall is responsible for identifying the application in this scenario?

Medium
47

Which TWO statements correctly describe the role of the data plane in PAN-OS architecture?

Medium
48

Refer to the exhibit. What does the 'Session End Reason: aged-out' indicate about the traffic?

Hard
49

Arrange the steps to perform a factory reset on a Palo Alto Networks firewall.

Medium
50

An enterprise requires separate administrative domains within a single firewall chassis for different business units. Each domain must have its own virtual router, security policies, and interface configuration. What is the appropriate PAN-OS feature?

Hard
51

During a traffic spike, the firewall CPU utilization remains below 30% but the dataplane packet buffer usage is consistently above 90%. What is the most likely impact on firewall performance?

Medium
52

A security administrator is configuring a firewall to inspect traffic between two internal zones. The administrator wants to ensure that the firewall performs application identification and content inspection on all allowed traffic. Which configuration is required to achieve this?

Hard
53

A firewall is configured with a destination NAT rule to translate public IP 203.0.113.10 to internal server 10.0.0.5 on port 443. Internal users from 10.0.0.0/24 can access the server using its private IP, but cannot access using the public IP. What should be configured to allow internal users to reach the server using the public IP?

Medium
54

A network engineer is configuring App-ID for a custom application that uses a proprietary protocol over TCP port 12345. The application's traffic is not being identified as expected. Which configuration change should the engineer make to ensure the firewall correctly identifies this application?

Medium

Frequently asked questions

What does the Core Concepts and Architecture domain cover on the PCNSE exam?
Be able to read session details and map each end reason to its cause, trace traffic between virtual routers, and verify management interface services and profiles. The single most important thing: know that aged-out is a normal timeout, not a block.
How many questions are in this domain?
This page lists all 54 Core Concepts and Architecture questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Core Concepts and Architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
paloalto-pcnse PALOALTO-PCNSE core concepts architecture Practice Questions