Courseiva

CCNA Deploy and Configure Firewalls Questions

35 questions · Deploy and Configure Firewalls · All types, answers revealed

1
MCQeasy

A security administrator notices that traffic to a specific website is being denied. The traffic log shows that the application is 'ssl' and the action is 'deny' with the rule being 'Allow-SSL'. What is the most likely cause?

A.The destination IP is in a blacklist.
B.The security rule is placed too low in the rulebase.
C.The security rule 'Allow-SSL' has 'service' set to 'application-default' but the website uses port 8443.
D.The SSL certificate is expired.
AnswerC

With 'application-default' as the service, the rule permits only the standard ports for ssl (443). Traffic on port 8443 is not application-default, so it fails the service match and is denied despite the rule name.

Why this answer

The security rule 'Allow-SSL' is configured with 'service' set to 'application-default', which means it only permits traffic on the default port for SSL (TCP 443). Since the website uses port 8443, the traffic is denied because the rule does not match the non-standard port. The firewall's application identification still correctly identifies the traffic as 'ssl', but the service constraint prevents the rule from applying, resulting in a deny action.

Exam trap

The trap here is that candidates assume the 'Allow-SSL' rule should match all SSL traffic regardless of port, but Palo Alto Networks tests the nuance that 'application-default' restricts the rule to only the default port for that application, causing a deny on non-standard ports like 8443.

How to eliminate wrong answers

Option A is wrong because a blacklist would cause traffic to be denied by a different rule (e.g., a block rule based on IP), not by a rule named 'Allow-SSL' that is explicitly allowing SSL traffic. Option B is wrong because the rule is being matched (the log shows rule 'Allow-SSL'), so its position in the rulebase is irrelevant; the issue is that the rule's service condition is not satisfied. Option D is wrong because an expired SSL certificate would cause browser warnings or TLS handshake failures, but the firewall would still allow the traffic if the rule matches; the firewall does not validate certificate expiration at the rule enforcement level.

2
MCQhard

An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?

A.The source address 10.0.0.0/8 is not included in the source zone.
B.The destination address is set to 'any', which is not valid.
C.The traffic is intra-zone, not inter-zone.
D.A rule with a 'deny' action appears earlier in the security policy.
AnswerD

Palo Alto Networks evaluates security policy top-down and stops at the first matching rule. A deny rule positioned above the intended allow rule matches the traffic first, so the allow rule never appears in the log as a hit, explaining the observed denial.

Why this answer

The most likely reason the inter-zone rule is not matched is that a preceding rule with a 'deny' action is matching the traffic first. In Palo Alto Networks firewalls, security rules are evaluated in order from top to bottom, and the first matching rule determines the action. If an earlier rule denies the traffic, the later allow rule will never be evaluated, even if it would otherwise match.

Exam trap

The trap here is that candidates often assume the rule itself is misconfigured (e.g., source or destination issues) rather than recognizing that a higher-priority deny rule is preempting the intended allow rule.

How to eliminate wrong answers

Option A is wrong because the source address 10.0.0.0/8 is a prefix, not a zone; the source zone is 'Trust', and the rule's source address is independent of whether the address is included in the zone definition. Option B is wrong because 'any' is a valid destination address in a security rule, meaning all destinations are matched. Option C is wrong because the traffic is explicitly described as inter-zone (Trust to Untrust), and intra-zone traffic would involve the same zone, which is not the case here.

3
MCQeasy

A medium-sized enterprise recently deployed a PA-5250 firewall in a data center as the primary internet gateway. The network team configured the security policies to allow all outbound web traffic (HTTP/HTTPS) from the internal trust zone to the untrust zone, with URL filtering and threat prevention enabled. After the deployment, users complain that some legitimate websites, such as banking and healthcare portals, are being blocked. The team checks the URL filtering logs and sees that these sites are categorized as 'web-hosting' or 'dynamic-dns', which are in the block list. The company's compliance requires that all web traffic be inspected. What should the network engineer do to resolve the issue without reducing security?

A.Add the specific URLs to the 'Allow List' in the URL filtering profile
B.Set the URL filtering profile action for 'web-hosting' to 'alert' instead of 'block'
C.Create a URL category override for each legitimate site to reclassify it as 'business-economy' or 'health-medicine'
D.Remove the 'web-hosting' and 'dynamic-dns' categories from the block list
AnswerC

Override changes the category for specific URLs, so they are no longer blocked by the 'web-hosting' or 'dynamic-dns' categories, while still being subject to other security checks.

Why this answer

URL category overrides allow you to reclassify specific URLs into a more appropriate category (e.g., 'health-medicine') without altering the global block action for 'web-hosting' or 'dynamic-dns'. This preserves the security posture by keeping the broad categories blocked for unknown or risky sites, while permitting the legitimate sites that were miscategorized by the Palo Alto Networks URL filtering database.

Exam trap

The trap here is that candidates often choose to add URLs to an allow list (Option A) without realizing that this bypasses all security inspections, failing the compliance requirement for full traffic inspection.

How to eliminate wrong answers

Option A is wrong because adding specific URLs to the 'Allow List' in the URL filtering profile would bypass all URL filtering and threat prevention for those URLs, violating the compliance requirement that all web traffic be inspected. Option B is wrong because setting the action for 'web-hosting' to 'alert' would allow all sites in that category, including potentially malicious ones, reducing security by permitting unvetted traffic. Option D is wrong because removing 'web-hosting' and 'dynamic-dns' from the block list would globally allow all sites in those categories, including malicious ones, which undermines the security policy and compliance requirements.

4
MCQhard

An administrator wants to ensure that all traffic from the 'Trust' zone to the 'Untrust' zone is inspected by WildFire. Which configuration is required?

A.Create a separate WildFire rule.
B.Enable WildFire on the security rule.
C.Configure a WildFire profile and attach it to the security rule.
D.Enable WildFire globally under Device > Setup.
AnswerC

Attaching a WildFire profile to the security rule enforces inspection for traffic matching that rule, satisfying the Trust-to-Untrust requirement. WildFire profiles are applied per-rule, so the profile analyses eligible file types inline or submits them for cloud sandboxing, providing verdicts without altering zone-based policy logic.

Why this answer

WildFire inspection is applied via a security rule using a WildFire Analysis profile. The profile defines the file types and verdict actions (e.g., alert, block) for files submitted to WildFire. Attaching this profile to the security rule that governs Trust-to-Untrust traffic ensures all matching traffic is inspected by WildFire.

Exam trap

The trap here is that candidates confuse WildFire's global registration settings (Device > Setup > WildFire) with the per-rule profile attachment required for actual traffic inspection, leading them to select the global enablement option.

How to eliminate wrong answers

Option A is wrong because WildFire does not use separate rules; it is a profile-based feature attached to security rules. Option B is wrong because there is no toggle to 'enable WildFire on the security rule' directly; you must configure and attach a WildFire Analysis profile. Option D is wrong because WildFire is not enabled globally under Device > Setup; global settings for WildFire are configured under Objects > WildFire Analysis Profiles or Device > WildFire, but the inspection itself requires profile attachment to a security rule.

5
MCQhard

A firewall receives traffic with IP options enabled. How does the firewall handle this traffic by default?

A.It drops the traffic
B.It forwards the traffic normally
C.It logs and alerts
D.It strips the IP options and forwards
AnswerA

By default, PAN-OS drops packets carrying IP options rather than forwarding them, since these options can be abused for reconnaissance or routing manipulation. This default behaviour satisfies the scenario's constraint of unconfigured handling, so the traffic is discarded before any policy evaluation.

Why this answer

By default, Palo Alto Networks firewalls drop traffic with IP options enabled because IP options can be used to bypass security controls or evade inspection. The firewall treats such packets as a potential security risk and discards them to prevent IP option-based attacks, such as source routing or timestamp manipulation.

Exam trap

The trap here is that candidates may assume the firewall forwards or strips IP options like a router, but Palo Alto Networks firewalls prioritize security by default and drop such packets to prevent IP option-based attacks.

How to eliminate wrong answers

Option B is wrong because forwarding traffic with IP options normally would allow potential evasion of security policies and is not the default behavior. Option C is wrong because while logging and alerting may be configured, the default action is to drop, not just log. Option D is wrong because stripping IP options and forwarding is not a default behavior; the firewall does not modify IP headers by default and instead drops the packet.

6
MCQmedium

Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?

A.rule4
B.rule3
C.rule1
D.rule2
AnswerD

Rule2 allows SSL for anyone, so it matches the HTTPS traffic.

Why this answer

Rule2 is correct because it is the first rule in the security policy that matches the traffic from the trust zone (source zone trust) to the external server (destination zone untrust) for HTTPS (destination port 443). Palo Alto Networks firewalls evaluate rules in top-down order, and rule2 explicitly permits HTTPS traffic from trust to untrust, while rule1 only permits HTTP (port 80). Rule3 and rule4 do not match because they are either for different zones or deny the traffic.

Exam trap

Palo Alto Networks often tests the first-match rule evaluation order, where candidates mistakenly think a deny rule later in the policy (rule4) will block traffic, forgetting that a preceding permit rule (rule2) already matched and allowed the session.

How to eliminate wrong answers

Option A is wrong because rule4 denies all traffic from trust to untrust, but since rule2 matches first and permits the HTTPS traffic, rule4 is never evaluated. Option B is wrong because rule3 applies to traffic from the DMZ zone, not the trust zone, so it does not match the user's traffic. Option C is wrong because rule1 only permits HTTP (port 80), not HTTPS (port 443), so it does not match the HTTPS request.

7
MCQhard

A security administrator is configuring a Palo Alto Networks firewall to perform DNS sinkholing to detect and block malware callbacks. The firewall is deployed with a default route to the internet. The administrator wants to ensure that when an internal host attempts to resolve a known malicious domain, the firewall returns a sinkhole IP address (10.10.10.10) and logs the event. Which configuration is required to achieve this?

A.Create a NAT rule that redirects DNS queries for malicious domains to 10.10.10.10.
B.Enable DNS sinkholing in the firewall's DNS proxy settings and specify the sinkhole IP address.
C.Create an Anti-Spyware profile with DNS sinkhole enabled and set the sinkhole IPv4 address to 10.10.10.10, then apply it to a security policy rule.
D.Configure a custom URL category with the malicious domains and set the action to 'sinkhole' in a URL filtering profile.
AnswerC

DNS sinkholing is configured within an Anti-Spyware profile. The profile includes a DNS sinkhole setting where you specify the sinkhole IPv4 address. When the firewall detects a DNS query for a malicious domain (as identified by the threat signature), it responds with the sinkhole IP. Applying the profile to a security rule enables the feature for matching traffic. This is the correct method to implement DNS sinkholing.

Why this answer

DNS sinkholing is implemented through an Anti-Spyware profile. The profile's DNS sinkhole settings allow the firewall to respond to DNS queries for malicious domains with a specified sinkhole IP address. This enables detection and logging of malware callbacks.

Other methods like URL filtering, DNS proxy, or NAT do not provide the same selective inspection and response based on threat signatures.

Exam trap

The trap here is assuming that URL filtering or NAT can perform DNS sinkholing, when it is actually a function of the Anti-Spyware profile.

8
MCQmedium

An administrator adds a new security rule to allow outbound 'web-browsing' and 'ssl' traffic. After committing, users report that some HTTPS sites are still blocked. Traffic logs show that the traffic matches the new rule but is denied. What is the most likely cause?

A.The service 'application-default' does not match the port used by the site.
B.A decryption policy is required for HTTPS traffic.
C.The application filter does not include 'ssl'.
D.The rule is placed too low in the rulebase.
AnswerA

The rule permits only ports 80 and 443 via the web-browsing and ssl applications, but application-default enforces those standard ports. HTTPS sites on non-standard ports therefore match the rule yet fail the service check, producing the deny. Defining a custom service, or using any, resolves the mismatch.

Why this answer

When a security rule uses the 'application-default' service, the firewall only allows traffic that matches the default port for the specified application. For 'web-browsing' (HTTP), the default port is TCP 80, and for 'ssl' (HTTPS), the default port is TCP 443. If an HTTPS site uses a non-standard port (e.g., TCP 8443), the traffic matches the rule based on the application but is denied because the service 'application-default' does not recognize that port as valid for the application.

Exam trap

The trap here is that candidates often assume 'application-default' allows any port for the application, when in reality it strictly enforces the default port, causing denial for HTTPS on non-standard ports.

How to eliminate wrong answers

Option B is wrong because a decryption policy is not required for HTTPS traffic to be allowed; decryption is optional and used for inspection, not for basic forwarding. Option C is wrong because the application filter does not need to include 'ssl' separately; the rule already specifies 'ssl' as an application, and the issue is with the service, not the application filter. Option D is wrong because the traffic logs show the traffic matches the new rule, indicating the rule is being evaluated and matched; placement lower in the rulebase would cause a different rule to match first, not a match with denial.

9
MCQmedium

An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?

A.Enable the 'Permitted IP Addresses' setting under Device > Setup > Management and enter 10.0.0.0/24.
B.Add a static route for 10.0.0.0/24 pointing to the MGT interface and enable strict routing.
C.Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.
D.Create a security policy rule from the management zone to the management zone allowing only the 10.0.0.0/24 subnet.
AnswerC

An Interface Management profile defines which management services (HTTPS, SSH, etc.) are enabled and from which source networks they are reachable. Assigning it to the MGT interface with permitted IP addresses 10.0.0.0/24 restricts management access to that subnet. This is the correct method to limit management access on a Palo Alto Networks firewall.

Why this answer

Management access on Palo Alto Networks firewalls is controlled by Interface Management profiles, which specify allowed services and permitted source IP addresses. Assigning such a profile to the MGT interface ensures only hosts in 10.0.0.0/24 can reach the web interface and SSH. Security policies and static routes do not govern management plane traffic, and the global permitted IP list is less granular.

Exam trap

The trap here is assuming that security policy rules or static routes control management interface access, when in fact an Interface Management profile is the correct mechanism.

10
MCQmedium

A security administrator is deploying a PA-5220 firewall with a single external zone and several internal zones. The requirement is to allow DNS queries to any external DNS server while ensuring that responses are permitted only when they match an existing session. Which security policy configuration meets this requirement?

A.Create a security rule from the internal zones to the external zone with application 'dns' and service 'application-default'. No other rules are needed because the firewall automatically allows return traffic.
B.Create two security rules: one from internal zones to external zone allowing application 'dns', and another from external zone to internal zones allowing application 'dns' to permit responses.
C.Create a security rule from internal zones to external zone with service 'dns' (UDP 53) and application 'any'. This ensures DNS queries are allowed and responses are permitted by the stateful engine.
D.Create a security rule from internal zones to external zone with application 'dns' and service 'any'. The firewall will automatically restrict the service to DNS ports based on the application.
AnswerA

This rule permits DNS queries from internal zones to any external DNS server. Using application 'dns' with service 'application-default' ensures the correct ports (UDP/TCP 53) are allowed. The firewall's stateful inspection automatically allows return traffic for established sessions, so no separate inbound rule is required. This is the standard best practice for outbound DNS.

Why this answer

The correct configuration allows DNS queries from internal to external zones using the application 'dns' and service 'application-default'. The firewall's stateful nature automatically permits return traffic for established sessions, so no inbound rule is required. Specifying the application ensures only DNS traffic is allowed, and application-default service restricts to standard DNS ports, maintaining security.

Exam trap

The trap here is assuming that return traffic needs an explicit inbound security rule, which would unnecessarily expose the internal network and violate stateful firewall principles.

11
MCQhard

An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?

A.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and configure a separate NAT rule for inbound traffic from untrust to trust with destination address '203.0.113.5' and translated destination '10.1.1.0/24'.
B.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5'. No destination translation.
C.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and set the destination translation to the original destination. This ensures return traffic is routed correctly.
D.Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and enable 'Bi-directional' option to allow return traffic.
AnswerB

This rule translates the source IP of outbound packets from 10.1.1.0/24 to the external interface IP 203.0.113.5. The original packet zones identify traffic from trust to untrust. The firewall automatically handles return traffic by reversing the translation for established sessions. This is the standard source NAT configuration for hide NAT.

Why this answer

For source NAT, the correct configuration is a NAT rule that translates the source IP of outbound packets from the internal subnet to the external interface IP. The firewall automatically handles return traffic by reversing the translation for established sessions, so no additional rules are needed. This provides hide NAT, allowing multiple internal hosts to share a single public IP.

Exam trap

The trap here is thinking that a separate inbound NAT rule or bi-directional option is needed for return traffic, when the stateful firewall automatically manages it for source NAT.

12
MCQhard

A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?

A.The custom application signature is not associated with the security rule.
B.The firewall is running in L2 mode.
C.The traffic is not matching the app's protocol or port in the signature.
D.The application timeout is too short.
AnswerC

Custom application signatures match on protocol and port criteria; if the session's UDP port or protocol differs from the signature definition, App-ID cannot identify it, so the session is logged as unknown rather than matching the custom app.

Why this answer

The custom application definition specifies UDP port 12345, but if the actual traffic uses a different port or does not match the protocol (UDP) defined in the signature, the firewall will classify it as 'unknown'. The security rule allows the application, but the traffic must first be identified by the App-ID engine based on the signature's protocol and port criteria; a mismatch here prevents proper classification.

Exam trap

The trap here is that candidates assume a security rule referencing a custom application will automatically classify all traffic on that rule as the application, but App-ID requires the traffic to match the signature's protocol and port criteria first.

How to eliminate wrong answers

Option A is wrong because custom application signatures are automatically associated with the security rule when the rule references the application; no separate association step is needed. Option B is wrong because L2 mode does not affect App-ID classification; the firewall still performs application identification regardless of the deployment mode. Option D is wrong because the application timeout controls how long a session remains active after traffic stops, not whether the traffic is initially identified as the custom application.

13
Multi-Selecthard

Which THREE of the following are mandatory components for GlobalProtect client connectivity?

Select 3 answers
A.Authentication profile.
B.Client certificate.
C.DNS suffix.
D.Gateway configuration.
E.Portal configuration.
AnswersA, D, E

An authentication profile is mandatory because GlobalProtect must verify user identity before granting tunnel access. It binds the portal or gateway to a specific authentication method, such as LDAP, SAML or Kerberos, satisfying the requirement that every client connection is authenticated. Without it, no user credential validation occurs and connectivity cannot be established.

Why this answer

Option A (Authentication profile) is correct because the GlobalProtect portal and/or gateway must reference an authentication profile to authenticate users before granting access, making it a mandatory component for client connectivity. Option D (Gateway configuration) is correct because the GlobalProtect gateway is the actual security enforcement point that terminates the client tunnel and provides access to protected resources; without it, clients cannot establish connectivity. Option E (Portal configuration) is correct because the portal is the initial connection point that delivers client configuration and gateway information to the GlobalProtect agent, and it is required for the client to discover and connect to gateways.

Option B (Client certificate) is not mandatory because certificate-based authentication is only one possible method; username/password or other authentication methods can be used instead. Option C (DNS suffix) is not mandatory because it is an optional configuration setting used for split-DNS or internal name resolution, not a requirement for establishing GlobalProtect connectivity.

Exam trap

The trap here is that candidates often confuse optional features like client certificates or DNS suffixes with mandatory components, but the exam specifically tests that only the portal, gateway, and authentication profile are required for the client to establish connectivity.

14
MCQmedium

A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?

A.Multiple virtual routers
B.ECMP with route metrics
C.Policy-based forwarding (PBF) with source criteria
D.Subinterfaces per ISP
AnswerC

Policy-based forwarding evaluates source addresses before the routing table, so matching traffic is forced out ISP-1 regardless of load-balancing or route metrics. This directly satisfies the requirement that specific sources always egress via one ISP, which ECMP or failover alone cannot guarantee.

Why this answer

Policy-based forwarding (PBF) allows you to override the routing table for specific traffic based on criteria such as source IP, destination IP, or application. By configuring a PBF rule with source criteria, you can force traffic from certain sources to always egress via ISP-1, regardless of the load-balancing configuration. This is the correct method for source-based path selection in a multi-ISP setup.

Exam trap

The trap here is that candidates often confuse ECMP load balancing with source-based path selection, assuming that route metrics or multiple virtual routers can achieve deterministic egress control, when in fact only PBF provides the necessary policy override for specific source traffic.

How to eliminate wrong answers

Option A is wrong because multiple virtual routers are used to maintain separate routing tables for different network segments or administrative domains, not to selectively forward traffic from specific sources to a particular ISP. Option B is wrong because ECMP with route metrics distributes traffic across multiple equal-cost paths based on a hash algorithm (e.g., source-destination IP), but it cannot guarantee that traffic from specific sources always uses ISP-1; it is designed for load balancing, not deterministic source-based routing. Option D is wrong because subinterfaces per ISP are used to segment traffic at Layer 2 or for VLAN tagging, not to enforce egress path selection based on source criteria; they do not influence the routing decision.

15
MCQeasy

A company needs to provide internet access to 500 internal users using a single public IP address. Which NAT method should be configured?

A.Dynamic NAT (1:1 pool)
B.Static NAT (1:1)
C.Destination NAT
D.Source NAT with IP and port translation (PAT)
AnswerD

Source NAT with port translation multiplexes 500 internal sessions onto one public address by rewriting source ports, so each flow is uniquely identified in the translation table. This satisfies the stem's single-public-IP constraint, which static or dynamic IP-only NAT cannot, since those require one public address per internal host.

Why this answer

Source NAT with IP and port translation (PAT) allows 500 internal users to share a single public IP address by translating each private source IP:port combination to the public IP with a unique source port. This conserves public IPv4 addresses and is the standard method for large-scale internet access from a private network.

Exam trap

The trap here is that candidates confuse Dynamic NAT (which still requires a pool of public IPs) with PAT, assuming any 'dynamic' method can share a single IP, but only PAT performs port-level multiplexing to achieve this.

How to eliminate wrong answers

Option A is wrong because Dynamic NAT (1:1 pool) maps each internal IP to a unique public IP from a pool, requiring at least 500 public IPs, not a single one. Option B is wrong because Static NAT (1:1) provides a fixed one-to-one mapping between a private IP and a public IP, which also requires a public IP per user and does not scale. Option C is wrong because Destination NAT translates the destination IP/port of inbound traffic, not the source address of outbound traffic, and thus cannot provide internet access for internal users.

16
MCQhard

A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?

A.Configure a security policy rule with application 'ssl' and attach the URL filtering profile.
B.Enable SSL decryption for the trust zone and apply a decryption policy for HTTPS traffic.
C.Enable 'HTTP Header Logging' in the URL filtering profile and commit.
D.Create a custom URL category with the malware sites and apply it to a security policy rule.
AnswerB

URL filtering for HTTPS requires visibility into the full URL, which is encrypted. SSL decryption (forward proxy or inbound inspection) is necessary to decrypt the traffic so the firewall can inspect the HTTP Host header and path. Without decryption, the firewall can only use the SNI or certificate CN, which may not provide the full URL. Therefore, enabling SSL decryption with a decryption policy is required.

Why this answer

To filter HTTPS based on the full URL, the firewall must decrypt the traffic to inspect the HTTP Host header and path. SSL decryption, configured via a decryption policy, allows the firewall to act as a forward proxy. Without decryption, URL filtering for HTTPS is limited to server name indication or certificate information, which may not cover the full URL.

Therefore, enabling SSL decryption is the necessary step.

Exam trap

The trap here is believing that attaching a URL filtering profile to a security rule that allows SSL traffic is sufficient for HTTPS URL filtering, when decryption is actually required.

17
MCQhard

The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?

A.The 'interface-address' option requires a specific translated address.
B.The rule is missing a 'from' zone specification.
C.The rule should be under 'destination-nat' instead of 'source-nat'.
D.The 'to-interface' should be 'any'.
AnswerB

Source NAT rules must include the source zone to determine when to translate.

Why this answer

A source NAT rule in PAN-OS requires a 'from' zone specification to match traffic. Without it, the rule does not know which zone the traffic originates from, so it will not be applied. In this case, the traffic from 10.1.1.1 to the internet likely originates from a zone (e.g., 'trust') that is not specified in the rule, causing the translation to fail.

Exam trap

The trap here is that candidates often assume source NAT rules only need a source IP range and an egress interface, overlooking the mandatory 'from' zone specification that PAN-OS requires for rule matching.

How to eliminate wrong answers

Option A is wrong because the 'interface-address' option does not require a specific translated address; it dynamically uses the IP address of the egress interface (ethernet1/1) as the translated source address, which is valid. Option C is wrong because the scenario describes source NAT (translating source IP of outbound traffic), not destination NAT (which translates destination IP of inbound traffic), so placing it under 'destination-nat' would be incorrect. Option D is wrong because setting 'to-interface' to 'any' would not fix the missing 'from' zone; the 'to-interface' specifies the egress interface for the translated traffic, and ethernet1/1 is appropriate for internet-bound traffic.

18
MCQmedium

Refer to the exhibit. A user in the 10.0.0.0/8 network is unable to access a web server at 172.16.1.10 which is in the DMZ zone. The firewall's security policy is shown: source zone trust, destination zone untrust, application web-browsing, action allow. What is the most likely reason for the failure?

A.The source IP range 10.0.0.0/8 is misconfigured.
B.The policy specifies the 'untrust' zone instead of the 'dmz' zone.
C.The policy is missing a 'permit' action.
D.The application 'web-browsing' is not the correct application for the traffic.
AnswerB

The policy's destination zone is 'untrust', but the web server is in the 'dmz' zone, so the traffic does not match this policy, causing the failure.

Why this answer

The policy's destination zone is 'untrust', but the server is in the 'dmz' zone, so the traffic does not match this policy. Option A is incorrect because the source IP range 10.0.0.0/8 includes the user's IP, so it is not misconfigured. Option C is incorrect because the policy has an 'allow' action, so it is not missing a permit.

Option D is incorrect because 'web-browsing' is the correct application for HTTP traffic.

19
MCQmedium

A company uses User-ID to map users to IPs. Some users report that their traffic is being blocked even though they are in the correct user group for access. The security policy uses user-based conditions. What is a likely cause?

A.The security policy order is incorrect
B.The firewall is not configured to use the User-ID agent
C.The User-ID agent is not running
D.The user's IP is not in the User-ID mapping table
AnswerD

User-ID policy enforcement depends on a valid IP-to-user mapping. If the source IP is absent from the mapping table, the firewall cannot resolve the user, so user-based rules fail to match and traffic is blocked.

Why this answer

When a security policy uses user-based conditions, the firewall must have a valid User-ID mapping for the user's IP address to enforce the rule. If the user's IP is not in the User-ID mapping table, the firewall cannot associate the traffic with a user group, and it will either match a default deny rule or fail to match the intended allow rule, resulting in blocked traffic. This is the most direct cause given that the user group assignment is correct but the mapping is missing.

Exam trap

The trap here is that candidates often assume the issue is with the User-ID agent's configuration or status, but the question specifies that some users are affected, pointing to a per-user mapping gap rather than a global agent failure.

How to eliminate wrong answers

Option A is wrong because security policy order affects which rule matches first, but if the correct user-based rule exists and the user's IP is unmapped, the rule will not match regardless of order. Option B is wrong because if the firewall were not configured to use the User-ID agent, no user mappings would exist at all, but the issue is specific to some users, implying the agent is configured. Option C is wrong because if the User-ID agent were not running, no mappings would be populated for any user, but the problem is isolated to certain users, indicating the agent is operational.

20
Multi-Selectmedium

Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?

Select 2 answers
A.Two physical or subinterfaces assigned to the vwire.
B.A management profile must be applied to the vwire.
C.A zone must be assigned to the vwire.
D.The interfaces must be of type 'aggregate'.
E.No IP addresses configured on the interfaces used in the vwire.
AnswersA, E

A vwire requires exactly two interfaces.

Why this answer

A virtual wire (vwire) requires exactly two interfaces to function as a transparent bridge between two network segments. These interfaces can be physical or subinterfaces, and they must be assigned to the vwire to pass traffic without Layer 3 processing. Without two interfaces, the vwire cannot forward frames between the connected devices.

Exam trap

The trap here is that candidates often assume a vwire needs a zone or management profile because they confuse it with a Layer 3 interface, but Palo Alto vwires are purely Layer 2 constructs that require only two interfaces and no IP addresses.

21
Multi-Selectmedium

An administrator is configuring a Palo Alto Networks firewall to enforce security policies based on user identity. The environment uses Active Directory, and the administrator plans to deploy User-ID. Which TWO actions are required to enable User-ID to map IP addresses to usernames? (Choose two.)

Select 2 answers
A.Ensure the firewall can communicate with the domain controllers over the required ports for User-ID (e.g., RPC, WMI).
B.Configure the firewall to use LDAP to query the domain controller for user group memberships.
C.Create a security policy that includes user or group objects in the Source User field.
D.Configure a User-ID Agent or enable the firewall's integrated User-ID agent to connect to the domain controllers.
E.Enable User-ID on the zone(s) where users reside by applying a User-ID enabled zone configuration.
AnswersA, D

The User-ID agent (integrated or external) must communicate with domain controllers to read security logs and query sessions. This requires network connectivity and appropriate firewall rules to allow protocols such as RPC and WMI. Without this communication, the agent cannot retrieve user mapping information, making it a prerequisite for User-ID to operate.

Why this answer

To enable User-ID mapping, the firewall must have a User-ID agent (integrated or external) configured to connect to domain controllers and the necessary network access to those controllers. These two actions allow the firewall to learn user-to-IP mappings from Active Directory security logs. Other steps like zone configuration or LDAP are for enforcement or group mapping, not for enabling the basic mapping function.

Exam trap

The trap here is assuming that enabling User-ID on a zone or creating user-based policies is required to start mapping users, when the core prerequisites are the agent and connectivity to domain controllers.

22
MCQeasy

A network administrator is deploying a new Palo Alto Networks firewall and needs to configure the data-plane interfaces. The firewall will be placed between the internal network and the internet. The internal network uses private IP addresses and must be translated to a public IP address for outbound traffic. Which type of NAT should the administrator configure on the firewall?

A.Destination NAT (DNAT)
B.U-Turn NAT
C.No NAT; use a security policy to allow outbound traffic
D.Source NAT (SNAT)
AnswerD

Source NAT translates the source IP address of outbound packets, allowing internal private addresses to be represented by a public IP address on the internet. This is exactly what is needed to enable internal hosts to access external resources while hiding their private addresses. SNAT is the standard method for outbound internet access from a private network.

Why this answer

Source NAT (SNAT) translates the source IP address of outbound packets to a public IP address, enabling internal hosts with private addresses to communicate with external networks. This is the correct choice because the scenario requires outbound traffic from a private network to be translated to a public address. SNAT is the standard NAT type for internet access from private networks.

Exam trap

The trap here is confusing source NAT with destination NAT; outbound traffic requires source address translation, not destination translation.

23
MCQhard

Refer to the exhibit. An administrator has configured this decryption policy but users in the 10.1.1.0/24 subnet receive certificate warnings when accessing HTTPS sites. What is the most likely cause?

A.The rule should be at the top of the rulebase
B.The destination address should be specific
C.The application should be web-browsing
D.The decryption certificate is not trusted by clients
AnswerD

An untrusted forward-trust certificate causes browsers to reject the firewall's re-signed certificates, triggering warnings. Since the policy decrypts traffic from 10.1.1.0/24, clients must trust the CA issuing the decryption certificate; without that trust chain installed, every HTTPS site presents an untrusted certificate.

Why this answer

Certificate warnings occur when the decryption certificate used by the firewall is not trusted by the client machines. In a forward proxy decryption scenario, the firewall generates a new certificate on-the-fly for each HTTPS session, and if that certificate is not installed in the client's trusted root store, the browser will display a security warning. This is the most common cause of certificate warnings in decryption deployments.

Exam trap

Palo Alto Networks often tests the distinction between rule configuration issues (like order or application matching) and certificate trust issues, leading candidates to focus on policy settings rather than the fundamental requirement that clients must trust the decryption CA.

How to eliminate wrong answers

Option A is wrong because rule order affects which rule matches traffic, but moving the rule to the top would not resolve certificate trust issues; the warning is caused by the certificate itself, not by rule precedence. Option B is wrong because making the destination address more specific would only narrow the scope of decryption, but the certificate warning would still occur for any traffic that matches the rule if the certificate is not trusted. Option C is wrong because the application 'web-browsing' is typically used for HTTP/HTTPS traffic, but the decryption policy already uses 'ssl' as the service, which correctly identifies HTTPS traffic; changing the application would not address the certificate trust problem.

24
MCQmedium

In an Active/Passive HA pair, which statement is true regarding configuration synchronization?

A.Configuration is not synced automatically; the administrator must export and import.
B.Only committed changes on the active are synced to the passive.
C.All configuration changes on the active peer are automatically synced to the passive.
D.The passive peer initiates the sync.
AnswerB

Committed configuration on the active firewall synchronises automatically to the passive peer, ensuring both devices hold identical running configurations for seamless failover. Uncommitted candidate changes remain local and are never propagated, satisfying the requirement that the passive stays ready to assume traffic without manual intervention.

Why this answer

In an Active/Passive HA pair, configuration synchronization occurs only after changes are committed on the active firewall. The passive peer then receives the committed configuration via the HA control link (using TCP port 2928 by default). This ensures that only validated, committed changes are propagated, preventing the passive from receiving uncommitted or partial configurations that could cause instability.

Exam trap

The trap here is that candidates often assume all configuration changes (including uncommitted candidate changes) are synced in real time, but Palo Alto Networks only syncs committed configurations to maintain consistency and prevent partial or broken configurations from being applied to the passive peer.

How to eliminate wrong answers

Option A is wrong because configuration synchronization in Active/Passive HA is automatic after a commit on the active peer, not requiring manual export/import. Option C is wrong because not all changes are synced automatically; only committed changes are synced—uncommitted changes (e.g., pending candidate config) are not propagated to the passive. Option D is wrong because the active peer initiates the sync after a commit, not the passive; the passive passively receives the configuration updates.

25
MCQeasy

A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?

A.A Layer 2 interface with a VLAN interface configured for DNS.
B.A virtual wire interface pair with a management profile allowing DNS.
C.A loopback interface with a management profile allowing DNS.
D.A Layer 3 interface with an IP address and a default route pointing to the next-hop gateway.
AnswerD

For the firewall to send DNS queries to external DNS servers, it needs a routable interface with an IP address and a default route to reach the internet. In Layer 3 mode, the firewall uses the interface's IP as the source for DNS queries. The default route ensures that traffic to unknown destinations, including DNS servers, is forwarded to the next-hop gateway. This is the standard configuration for outbound management traffic.

Why this answer

The firewall requires a Layer 3 interface with an IP address and a default route to send DNS queries to external servers. The interface provides the source IP, and the default route directs traffic to the next-hop gateway. Other interface types like loopback, virtual wire, or Layer 2 do not provide the necessary routable connectivity for outbound DNS resolution.

Exam trap

The trap here is confusing management access with outbound connectivity; a loopback or management interface alone does not provide a path for DNS queries.

26
MCQmedium

A security administrator is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for a specific user group. The administrator creates a decryption policy with source user group 'Finance', destination any, and action 'ssl-forward-proxy'. However, after committing, users in the Finance group report that they can still access HTTPS sites without any certificate warnings, and the firewall logs show no decryption. The administrator verifies that the decryption policy is placed correctly and that the forward trust certificate is installed and trusted by the clients. What is the most likely reason decryption is not occurring?

A.The user group 'Finance' is not properly mapped to IP addresses via User-ID, so the policy does not match.
B.The decryption policy action should be 'ssl-inbound-inspection' instead of 'ssl-forward-proxy'.
C.The decryption policy is missing a service definition for HTTPS.
D.The forward trust certificate is not installed on the firewall.
AnswerA

Decryption policies can use user groups as source criteria. For the policy to match, the firewall must know which IP addresses correspond to users in the 'Finance' group. This requires User-ID to be configured and functioning, mapping users to IPs. If User-ID is not enabled or the group mapping is not present, the policy will not match, and traffic will not be decrypted. The lack of certificate warnings and no decryption logs indicate the policy is not being applied.

Why this answer

Decryption policies that use user groups require User-ID to map users to IP addresses. If User-ID is not configured or the group mapping is missing, the policy will not match, and traffic will not be decrypted. The absence of certificate warnings and decryption logs supports this.

Other options are less likely because the service is typically 'any', the certificate is verified as installed, and the action is correct for outbound decryption.

Exam trap

The trap here is assuming that decryption policies based on user groups work without User-ID; the firewall cannot enforce user-based policies without proper user mapping.

27
MCQeasy

By default, what is the action on traffic between two different zones without any security rule?

A.deny
B.allow
C.depends on the application
D.prompt
AnswerA

Inter-zone traffic is governed by security policy, and PAN-OS applies an implicit deny when no rule matches, so packets crossing from one zone to another are dropped. This default satisfies the scenario's constraint of no configured security rule, unlike intra-zone traffic, which the implicit allow permits by default.

Why this answer

By default, Palo Alto Networks firewalls implement an implicit deny rule for inter-zone traffic. This means that if no security rule explicitly matches traffic between two different zones, the firewall drops the packet and logs it as a deny action. This default behavior ensures that all cross-zone traffic must be explicitly allowed by a security policy, enforcing a zero-trust model.

Exam trap

The trap here is that candidates often confuse the default inter-zone action with intra-zone traffic (which is allowed by default) or assume that the firewall will prompt or log a warning, when in fact it silently denies without any user notification.

How to eliminate wrong answers

Option B is wrong because allowing inter-zone traffic by default would violate the principle of least privilege and create a security hole; Palo Alto firewalls never allow traffic without an explicit allow rule. Option C is wrong because the action is not dependent on the application; the firewall applies a default deny regardless of the application ID, and application identification only occurs after a rule match. Option D is wrong because the firewall does not prompt or ask for user input for inter-zone traffic; it silently drops the packet based on the implicit deny rule.

28
MCQmedium

An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?

A.The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.
B.The security rule is missing a service definition; the application 'any' does not automatically include all services.
C.The security rule is missing an application override because the server's traffic is not being identified correctly.
D.The security rule is missing a destination zone; the firewall requires a destination zone to be specified for outbound traffic.
AnswerA

When a server with a private IP address (10.10.10.5) initiates traffic to the internet, the firewall must perform source NAT to translate the private IP to a public IP. Without a NAT rule, the packet is forwarded with the private source IP, which is not routable on the internet. Return traffic would be dropped by upstream routers. The security rule alone does not provide address translation; a NAT policy is required.

Why this answer

For a server with a private IP address to access the internet, the firewall must perform source NAT to translate the private IP to a routable public IP. Without a NAT rule, return traffic cannot be routed back to the server. The security rule permits the traffic, but NAT is a separate configuration.

The other options are less likely because application 'any' does not require a service, application override is not needed for basic connectivity, and the destination zone is typically part of the rule.

Exam trap

The trap here is assuming that a security rule allowing traffic is sufficient for outbound internet access, forgetting that source NAT is required for private IP addresses.

29
MCQhard

An organization has a firewall in HA active-passive mode. After a failover, the new active firewall does not have the latest session table. What should be configured to ensure session synchronization?

A.Packet capture on active
B.Session setup on both peers
C.HA session sync
D.Commit force sync
AnswerC

HA session sync replicates the session table from the active firewall to the passive peer, so after failover the newly active device already holds established sessions. Without it, traffic matching existing sessions is dropped, breaking continuity for stateful flows.

Why this answer

HA session synchronization (session sync) is the feature that replicates active session state from the active firewall to the passive firewall in an active-passive HA pair. Without this configuration, after a failover the new active firewall has no knowledge of existing sessions, causing all active connections to be dropped and requiring clients to re-establish them. Enabling session sync ensures the passive firewall maintains a synchronized session table, allowing seamless traffic continuation after failover.

Exam trap

The trap here is that candidates often confuse configuration synchronization (commit force sync) with runtime state synchronization (session sync), leading them to select Option D, but commit force sync only pushes configuration changes, not dynamic session data.

How to eliminate wrong answers

Option A is wrong because packet capture is a troubleshooting tool used to inspect traffic, not a mechanism to replicate session state between HA peers. Option B is wrong because session setup on both peers is not a configurable feature; session creation occurs naturally on the active firewall, and without session sync the passive peer does not receive those sessions. Option D is wrong because commit force sync is used to force a configuration synchronization from the active to the passive firewall, but it does not synchronize dynamic runtime data like session tables.

30
Multi-Selectmedium

Which TWO factors can cause a firewall to not show any User-ID mapping for a user who is actively logged in?

Select 2 answers
A.The user is using a VPN connection from a remote location
B.The firewall's User-ID agent is in collector mode
C.The User-ID agent is not configured with the firewall's IP as a client
D.The user's traffic is being decrypted by SSL decryption
E.The domain controller is not forwarding security events to the User-ID agent
AnswersC, E

The agent must have the firewall listed as a client to send mappings.

Why this answer

The User-ID agent must be configured with the firewall's IP address as a client to forward user-to-IP mappings. Without this configuration, the firewall will not receive the mapping data from the agent, even if the user is actively logged in and the agent is collecting security events from the domain controller.

Exam trap

The trap here is that candidates often confuse 'collector mode' with a failure to send mappings, but collector mode actually aggregates and forwards data, so it does not cause missing mappings; the real issue is the missing client IP configuration on the agent.

31
MCQeasy

A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?

A.allow
B.reset-both
C.deny
D.drop
AnswerA

Permitting the session satisfies the requirement to admit inbound HTTPS from Untrust to the DMZ web server. A security policy action of allow passes matching traffic and applies the profile group, whereas deny or drop would block it. Since the destination is a specific server IP, this action forwards the connection to the web server.

Why this answer

The correct action is 'allow' because the security engineer needs to permit inbound HTTPS traffic from the Untrust zone to the DMZ web server. In Palo Alto Networks firewalls, the security policy action 'allow' explicitly permits the traffic to pass through the firewall, which is required for legitimate inbound web traffic.

Exam trap

The trap here is that candidates may confuse 'deny' with 'drop' or think 'reset-both' is a valid way to allow traffic, but only 'allow' actually permits the session to be established and pass through the firewall.

How to eliminate wrong answers

Option B (reset-both) is wrong because it sends TCP RST packets to both the client and server, which would terminate the HTTPS connection rather than allowing it. Option C (deny) is wrong because it discards the traffic and sends a TCP RST to the sender, blocking the inbound HTTPS traffic. Option D (drop) is wrong because it silently discards the traffic without any notification, which would also prevent the HTTPS traffic from reaching the web server.

32
MCQhard

A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?

A.Another rule earlier in the policy matches the traffic and allows it before reaching this rule.
B.The firewall is configured to not log interzone traffic.
C.The source address 10.1.0.0/16 is not part of the 10.0.0.0/8 subnet.
D.The logging profile is not applied to the rule.
AnswerA

PAN-OS evaluates rules top-down and stops at the first match, so an earlier allow rule for 10.1.0.0/16 permits the traffic before the logging rule is reached. Only the matched rule's log setting applies, hence no log entry appears.

Why this answer

In a Palo Alto Networks firewall, security rules are evaluated from top to bottom, and the first matching rule is applied. If an earlier rule in the policy matches the traffic from 10.1.0.0/16 and allows it, the rule with logging at rule end will never be evaluated, and thus no log entry is generated for that traffic.

Exam trap

The trap here is that candidates may assume a subnet like 10.1.0.0/16 is not part of 10.0.0.0/8, but in CIDR notation, 10.1.0.0/16 is indeed a subset of 10.0.0.0/8, so the issue is rule order, not address mismatch.

How to eliminate wrong answers

Option B is wrong because interzone traffic logging is not a global setting that can be disabled; logging is controlled per rule via the log setting at rule start or end. Option C is wrong because 10.1.0.0/16 is a subset of 10.0.0.0/8, so it is included in the source address range. Option D is wrong because the logging profile is not required for basic logging; setting logging at rule end enables logging without a separate profile.

33
MCQmedium

The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?

A.The VLAN ID is misconfigured as 20 instead of 10.
B.The IP netmask is /24 but should be /16.
C.The zone is incorrectly named 'VLAN10'.
D.The virtual router is not correctly set.
AnswerA

The sub-interface's VLAN tag must match the VLAN ID carried in the 802.1Q frame. Tagging it as VLAN 20 means frames arriving with VLAN 10 tags are dropped, so no traffic reaches the 192.168.10.1/24 gateway and routing fails.

Why this answer

The exhibit shows the sub-interface is configured with VLAN ID 20, but the administrator intended VLAN 10. In Palo Alto Networks firewalls, sub-interfaces use 802.1Q VLAN tagging, and the VLAN ID must match the tag on incoming frames. Mismatched VLAN IDs cause the firewall to drop or ignore traffic because the sub-interface only processes frames with the configured tag.

Exam trap

The trap here is that candidates often confuse the VLAN ID on the sub-interface with the IP subnet or zone name, assuming a mismatch in IP addressing or zone naming is the root cause, when in fact the VLAN tag mismatch is the direct and immediate reason traffic is not processed.

How to eliminate wrong answers

Option B is wrong because the /24 netmask is correct for a /24 subnet (192.168.10.0/24); a /16 would incorrectly expand the subnet to 192.168.0.0/16, causing routing issues but not preventing VLAN 10 traffic from reaching the interface. Option C is wrong because the zone name 'VLAN10' is purely a logical label and has no effect on VLAN tagging or traffic forwarding; zones are security boundaries, not VLAN identifiers. Option D is wrong because the virtual router assignment is independent of VLAN tagging; even if the virtual router were misconfigured, traffic would still reach the sub-interface and be processed, but routing would fail later—not the cause of traffic not being routed through the interface.

34
Multi-Selecthard

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Select 3 answers
A.Active/Passive HA with floating IP
B.ECMP with equal cost routes
C.Policy Based Forwarding combined with path monitoring
D.Active/Passive HA with virtual router synchronization
E.Use of multiple public IPs with NAT rules
AnswersA, B, C

Active/passive HA keeps the standby firewall ready, and the floating IP moves to the passive device on failover, so outbound traffic continues through the surviving peer. This satisfies redundancy at the device level rather than the path level.

Why this answer

Active/Passive HA with floating IP (Option A) is valid because the passive firewall assumes the active firewall's IP address upon failover, ensuring outbound traffic continues via the same default gateway. ECMP with equal cost routes (Option B) distributes outbound traffic across multiple paths and provides redundancy by automatically failing over if one path is lost. Policy Based Forwarding combined with path monitoring (Option C) allows you to define forwarding policies based on traffic attributes and monitor path health, redirecting traffic if a monitored path fails.

Exam trap

The trap here is that candidates confuse virtual router synchronization (which only replicates routing tables) with actual failover mechanisms like floating IPs or path monitoring, assuming that synchronized routing alone provides redundancy for outbound traffic.

35
Multi-Selecteasy

Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)

Select 2 answers
A.Enable Threat Prevention profiles to block known malware
B.Configure logging for all traffic to enable monitoring and troubleshooting
C.Leave the default admin password until the next audit
D.Use the default NAT policies provided by the initial configuration
E.Manually download dynamic updates daily to ensure latest signatures
AnswersA, B

Branch traffic traverses the firewall to reach the internet, so attaching Threat Prevention profiles to the relevant security rules inspects that traffic and drops known malware and vulnerability exploits. This satisfies the requirement to secure the branch against external threats at the enforcement point.

Why this answer

Enabling Threat Prevention profiles (A) is correct because it applies IPS signatures to block known malware, exploits, and vulnerabilities inline, which is essential for branch office security without requiring constant manual intervention. Configuring logging for all traffic (B) is correct because it provides visibility for monitoring, troubleshooting, and compliance, and is necessary for effective use of features like ACC and reporting.

Exam trap

The trap here is that candidates may think default NAT policies are acceptable for branch offices or that manual updates are more reliable, but the PCNSE exam emphasizes automation and security best practices, making options D and E incorrect due to their lack of scalability and security posture.

Ready to test yourself?

Try a timed practice session using only Deploy and Configure Firewalls questions.