PCNSE · domain
Deploy and Configure Firewalls
This domain covers initial firewall deployment and day-to-day configuration on PAN-OS: zones, interfaces, virtual routers, security and NAT policy, URL filtering, and redundancy. Questions present real topologies (DMZ web server, branch office, outbound internet) and ask you to choose the correct policy, interface mode, or high-availability design to satisfy the stated requirement.
Focused practice
Practice Deploy and Configure Firewalls questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Deploy and Configure Firewalls
Be able to build a working policy set: define zones and interfaces, write security and NAT rules that match real traffic, attach URL Filtering profiles, and design HA or redundant egress. The single most important thing is getting zone, address, and NAT matching correct so traffic is actually allowed and translated.
Security policy rule order and zone-based matching from Untrust to DMZ
NAT policy for inbound destination translation and outbound source translation
Interface types and modes: L3, L2, virtual wire, tap, and subinterfaces
High availability, virtual router redundancy, and policy-based forwarding for outbound redundancy
Watch out for
Common Deploy and Configure Firewalls exam traps
- ▸Assuming a security policy alone permits inbound traffic; the matching NAT rule and destination zone must also be correct.
- ▸Forgetting that URL filtering requires the traffic to match a security policy with a URL Filtering profile attached.
- ▸Confusing active/passive HA with active/active, or missing that redundant paths need separate virtual routers or PBF.
Question index
All Deploy and Configure Firewalls questions (35)
Click any question to see the full explanation, or start a practice session above.
A security administrator notices that traffic to a specific website is being denied. The traffic log shows that the application is 'ssl' and the action is 'deny' with the rule being 'Allow-SSL'. What is the most likely cause?
Easy2An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?
Hard3A medium-sized enterprise recently deployed a PA-5250 firewall in a data center as the primary internet gateway. The network team configured the security policies to allow all outbound web traffic (HTTP/HTTPS) from the internal trust zone to the untrust zone, with URL filtering and threat prevention enabled. After the deployment, users complain that some legitimate websites, such as banking and healthcare portals, are being blocked. The team checks the URL filtering logs and sees that these sites are categorized as 'web-hosting' or 'dynamic-dns', which are in the block list. The company's compliance requires that all web traffic be inspected. What should the network engineer do to resolve the issue without reducing security?
Easy4An administrator wants to ensure that all traffic from the 'Trust' zone to the 'Untrust' zone is inspected by WildFire. Which configuration is required?
Hard5A firewall receives traffic with IP options enabled. How does the firewall handle this traffic by default?
Hard6Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?
Medium7A security administrator is configuring a Palo Alto Networks firewall to perform DNS sinkholing to detect and block malware callbacks. The firewall is deployed with a default route to the internet. The administrator wants to ensure that when an internal host attempts to resolve a known malicious domain, the firewall returns a sinkhole IP address (10.10.10.10) and logs the event. Which configuration is required to achieve this?
Hard8An administrator adds a new security rule to allow outbound 'web-browsing' and 'ssl' traffic. After committing, users report that some HTTPS sites are still blocked. Traffic logs show that the traffic matches the new rule but is denied. What is the most likely cause?
Medium9An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?
Medium10A security administrator is deploying a PA-5220 firewall with a single external zone and several internal zones. The requirement is to allow DNS queries to any external DNS server while ensuring that responses are permitted only when they match an existing session. Which security policy configuration meets this requirement?
Medium11An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?
Hard12A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?
Hard13Which THREE of the following are mandatory components for GlobalProtect client connectivity?
Hard14A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?
Medium15A company needs to provide internet access to 500 internal users using a single public IP address. Which NAT method should be configured?
Easy16A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?
Hard17The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?
Hard18Refer to the exhibit. A user in the 10.0.0.0/8 network is unable to access a web server at 172.16.1.10 which is in the DMZ zone. The firewall's security policy is shown: source zone trust, destination zone untrust, application web-browsing, action allow. What is the most likely reason for the failure?
Medium19A company uses User-ID to map users to IPs. Some users report that their traffic is being blocked even though they are in the correct user group for access. The security policy uses user-based conditions. What is a likely cause?
Medium20Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?
Medium21An administrator is configuring a Palo Alto Networks firewall to enforce security policies based on user identity. The environment uses Active Directory, and the administrator plans to deploy User-ID. Which TWO actions are required to enable User-ID to map IP addresses to usernames? (Choose two.)
Medium22A network administrator is deploying a new Palo Alto Networks firewall and needs to configure the data-plane interfaces. The firewall will be placed between the internal network and the internet. The internal network uses private IP addresses and must be translated to a public IP address for outbound traffic. Which type of NAT should the administrator configure on the firewall?
Easy23Refer to the exhibit. An administrator has configured this decryption policy but users in the 10.1.1.0/24 subnet receive certificate warnings when accessing HTTPS sites. What is the most likely cause?
Hard24In an Active/Passive HA pair, which statement is true regarding configuration synchronization?
Medium25A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?
Easy26A security administrator is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for a specific user group. The administrator creates a decryption policy with source user group 'Finance', destination any, and action 'ssl-forward-proxy'. However, after committing, users in the Finance group report that they can still access HTTPS sites without any certificate warnings, and the firewall logs show no decryption. The administrator verifies that the decryption policy is placed correctly and that the forward trust certificate is installed and trusted by the clients. What is the most likely reason decryption is not occurring?
Medium27By default, what is the action on traffic between two different zones without any security rule?
Easy28An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?
Medium29An organization has a firewall in HA active-passive mode. After a failover, the new active firewall does not have the latest session table. What should be configured to ensure session synchronization?
Hard30Which TWO factors can cause a firewall to not show any User-ID mapping for a user who is actively logged in?
Medium31A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?
Easy32A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?
Hard33The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?
Medium34Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?
Hard35Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)
EasyOther domains
All PCNSE exam domains
Frequently asked questions
- What does the Deploy and Configure Firewalls domain cover on the PCNSE exam?
- Be able to build a working policy set: define zones and interfaces, write security and NAT rules that match real traffic, attach URL Filtering profiles, and design HA or redundant egress. The single most important thing is getting zone, address, and NAT matching correct so traffic is actually allowed and translated.
- How many questions are in this domain?
- This page lists all 35 Deploy and Configure Firewalls questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Deploy and Configure Firewalls questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.