PCNSE · domain
Manage, Monitor and Operate
The Manage, Monitor and Operate domain covers day-to-day firewall administration on PAN-OS: generating tech support files, configuring log forwarding, diagnosing resource problems, and making configuration changes like adding zones. Questions are scenario-based, asking you to pick the correct CLI command, required configuration steps, or ordered workflow rather than recite definitions.
Focused practice
Practice Manage, Monitor and Operate questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Manage, Monitor and Operate
You must be able to run the correct operational CLI commands, build and apply log forwarding profiles, and diagnose resource issues by cause. The single most important thing: know which command or configuration step actually produces the required outcome, not just its name.
Using the debug command to generate a tech support file for TAC analysis
Configuring log forwarding profiles and applying them to Security policy rules
Identifying causes of high CPU utilization such as logging, decryption, and threat inspection
Ordering zone configuration steps: create zone, assign interfaces, commit
Watch out for
Common Manage, Monitor and Operate exam traps
- ▸Assuming log forwarding works after only creating a syslog server profile, forgetting to attach the profile to the Security policy rule
- ▸Confusing the tech support file command with packet capture or session dump commands that do not bundle full diagnostics
- ▸Blaming high CPU on hardware when management-plane tasks, logging, or content inspection are the actual drivers
Question index
All Manage, Monitor and Operate questions (59)
Click any question to see the full explanation, or start a practice session above.
A security operations center (SOC) uses Panorama to monitor all firewalls. They notice that some log entries show a severity of 'critical' but the alerting system does not fire. The log forwarding profile on Panorama is configured to send syslog alerts for severity 'critical'. The syslog server receives other logs from Panorama but not these critical logs. The administrator checks the Panorama configuration and finds that the log forwarding profile is applied to the correct log types. What is the most likely issue?
Hard2A company uses Panorama to manage multiple firewalls. An administrator pushes a template that includes a new Security Profiles group, but the firewalls do not receive the profile group. What is the most likely cause?
Hard3Refer to the exhibit. The firewall's disk usage is at 85% overall, and the /opt/panlogs partition is at 92%. The administrator wants to free up space without losing important log data. Which action should be taken first?
Easy4Refer to the exhibit. What does the uptime indicate?
Easy5Which TWO configurations are required for User-ID to work using the Windows User-ID Agent (WUA) in a distributed environment?
Hard6A GlobalProtect gateway is configured as shown. Remote users report that they can connect to the gateway but cannot authenticate. The users are using the GlobalProtect client with certificate authentication. What is the most likely cause?
Hard7A firewall's traffic logs are being forwarded to a Panorama appliance for centralized retention. An administrator notices that logs from one specific firewall are missing from Panorama even though the same firewall's logs appear locally. The firewall is managed by Panorama and shows as connected. Which cause is most likely?
Medium8A network security engineer is validating a newly deployed firewall. The security policy is configured to allow web traffic from the Trust zone to the Untrust zone. After a user reports that a website is unreachable, the engineer runs the CLI command 'show session all filter source 10.1.1.50' and sees no active sessions. Which CLI command should the engineer use next to determine why the session was not established?
Medium9A network administrator needs to verify that the firewall is receiving dynamic updates for applications and threats. Which command should they use from the CLI to check the current update status and schedule?
Easy10A company wants to forward logs from a firewall to a SIEM system with high reliability. Which log forwarding method ensures that logs are not lost if the SIEM is temporarily unreachable?
Medium11An administrator needs to generate a report showing all traffic denied by the firewall over the past week. Which type of report in the firewall web interface should be used?
Easy12A company has a firewall with multiple virtual systems (vsys). The administrator wants to delegate management of one vsys to a junior administrator, allowing them to configure security policies but not access system settings or other vsys. Which administrative role should be assigned?
Medium13An engineer is troubleshooting a security policy that is not matching traffic as expected. The traffic is from source IP 10.1.1.10 to destination 172.16.0.1 port 443. The policy has source zone 'Internal', destination zone 'DMZ', source address '10.1.1.0/24', destination address '172.16.0.0/24', application 'ssl'. The firewall shows the traffic hitting a different rule. What is the most likely cause?
Medium14Two firewalls in an active/passive HA configuration are not synchronizing sessions. The 'show high-availability state' command shows both peers as 'active' and 'passive' correctly, but session synchronization is not working. What is the most likely cause?
Hard15A network security administrator is investigating a suspicious session on a PA-3220 firewall. The administrator needs to determine the exact security policy rule that permitted the session to be established. Which action should the administrator take to accomplish this goal?
Medium16A network engineer is troubleshooting high latency on the firewall. Which THREE commands from the CLI should be used to identify potential bottlenecks? (Choose three.)
Medium17A user complains that they cannot access internal resources via GlobalProtect. The firewall shows the user is connected with an IP address from the tunnel pool. Which log type should the administrator check first to determine if traffic is being allowed or denied?
Easy18Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)
Hard19Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)
Hard20A network administrator needs to monitor the firewall's interface status and receive alerts when an interface goes down. Which built-in feature should they configure?
Easy21An administrator manages a PA-5220 pair running PAN-OS 11.1. During a change window, the active firewall's management plane becomes unreachable and the device fails over to the passive peer. The administrator wants to review the events that occurred on the failed device before the failover. Which action should the administrator take to obtain this information?
Medium22An organization has a pair of PA-5250 firewalls in active/passive HA. During a maintenance window, the active firewall is rebooted. After the reboot, the firewall that was passive becomes active and passes traffic. However, the other firewall remains in a non-functional state and shows 'unknown' as HA state. The administrator checks the HA configuration and finds both firewalls have the same HA settings. What is the most likely issue?
Easy23An administrator is troubleshooting high CPU usage on a PA-5250 firewall. The CPU usage spikes every 5 minutes. Which CLI command should be used to identify the process causing the spike?
Medium24A team uses the Panorama API to generate custom reports. They need to retrieve a list of all rules that have logging at session end enabled. Which API endpoint should be used?
Medium25A firewall is dropping traffic that should be allowed. The security policy appears correct. An administrator checks the session table and notices the session state is 'CLOSE'. What is the most likely cause of the traffic being dropped?
Medium26An administrator is preparing a PA-3220 running PAN-OS 11.0 for a maintenance window and wants to capture the current operational state so it can be compared after the window. Which two actions should the administrator take to preserve this state for later comparison? (Choose two.)
Medium27A security administrator needs to ensure that the firewall sends an email notification to the security team whenever a critical threat is detected. The email server is reachable at 10.10.10.5, and the firewall's management interface is in the 10.10.10.0/24 subnet. Which configuration step is required to enable email notifications for critical threats?
Medium28Refer to the exhibit. Which SSL protocol version is blocked as per this decryption profile?
Medium29An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?
Medium30An administrator needs to ensure that the firewall sends an alert to an external server whenever a critical threat is detected, and also wants to receive a daily summary of blocked traffic. Which two log forwarding destinations should be configured to satisfy both requirements?
Easy31An administrator is preparing to upgrade a PA-5220 firewall from PAN-OS 10.2 to a later maintenance release. Before the upgrade, the administrator wants to minimize the chance of a failed upgrade and ensure a rollback path exists. Which two actions should the administrator take? (Choose two.)
Medium32What does the session state 'SYN_SENT' indicate about this traffic flow?
Medium33A company has configured User-ID with Active Directory polling. Some users cannot access resources even though their security policy rules appear correct. The administrator verifies that the User-ID agent is connected and polling. What additional step should the administrator take?
Medium34A security engineer is configuring a Palo Alto Networks firewall to send alerts to an external SNMP manager. The engineer wants to ensure that the firewall sends SNMP traps for specific events, such as a link state change and a configuration change. Which two actions must the engineer perform to achieve this? (Choose two.)
Medium35An administrator needs every administrator login, configuration commit, and firewall restart to be recorded in a central location for an upcoming audit. The auditor requires that the records be queryable by username and timestamp, and that they be retained independently of the firewall's own log storage. Which action should the administrator take to meet these requirements?
Medium36An administrator notices that the firewall's dataplane CPU is consistently high and wants to determine which application is generating the most traffic without waiting for scheduled reports. Which action provides the most immediate visibility into top applications by session and byte count?
Hard37A firewall is experiencing performance issues. The administrator wants to collect diagnostic data for TAC analysis. Which command generates a comprehensive support file?
Easy38A network administrator wants to generate a report that shows the top applications used over the past week. The firewall is managed by Panorama. Which Panorama feature should the administrator use to create and schedule this report?
Easy39A security team is implementing SSL Decryption. They want to ensure that traffic to health-related websites is not decrypted due to privacy concerns. Which method should they use to exclude this traffic?
Medium40The security policy rule shown in the exhibit has log-start and log-end both set to 'no', but a log-forwarding profile is configured. Which statement best describes the logging behavior for sessions matching this rule?
Medium41A network security engineer is investigating why a firewall's dataplane CPU is consistently at 95%. After reviewing the session table, they notice a large number of sessions in a 'discard' state. Which action should the engineer take first to resolve the high CPU utilization?
Hard42An administrator wants to view real-time CPU and memory usage on the firewall. Which CLI command should be used?
Easy43Refer to the exhibit. Based on the log entry, what action was taken on this traffic?
Hard44A security administrator needs to configure the firewall to send an email alert whenever a critical threat is detected. The administrator wants to ensure that the email includes the threat details and is sent immediately. Which configuration step is required to achieve this?
Easy45A security team needs to capture traffic for forensic analysis of a specific application that uses non-standard ports. The administrator wants to capture packets on the firewall for that application only, without affecting performance. Which method should be used?
Hard46A network administrator is reviewing the firewall's logs and notices that many sessions are being denied by the security policy. The administrator wants to quickly identify the top source IP addresses that are being denied. Which feature in the PAN-OS web interface should the administrator use to accomplish this?
Easy47Arrange the steps to configure a new administrator account with role-based access.
Medium48A security team uses Panorama to push policy to 40 managed firewalls. An administrator commits a policy change from Panorama, and the commit succeeds on Panorama but fails on 12 firewalls with a validation error. The administrator wants to identify which firewalls failed and the specific error each reported without opening each device individually. Which Panorama feature should the administrator use?
Hard49A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?
Easy50Two firewalls in an active/passive HA pair are not synchronizing. The administrator checks 'show high-availability state' and sees 'active' on both firewalls. What is the most likely cause?
Hard51A small business uses a single PA-220 firewall with PAN-OS 10.2. The administrator notices that the firewall is no longer receiving automatic threat updates. The License page shows the Threat Prevention license is active with 200 days remaining. The administrator can manually download updates from the Palo Alto Networks update server. What is the most likely cause?
Easy52An administrator wants to be notified whenever any administrator account is locked out after repeated failed login attempts. The notification must be sent by email to the security team. Which configuration accomplishes this?
Easy53An administrator reviews a traffic log entry: 'Source: 10.0.0.10, Destination: 8.8.8.8, Application: web-browsing, Action: allow, Bytes Sent: 500, Bytes Received: 1200'. What does this log entry indicate about the traffic?
Medium54An administrator is analyzing traffic logs on a Palo Alto Networks firewall and notices that a particular session shows an application of 'incomplete' and no bytes received. The session was allowed by the security policy. What is the most likely cause?
Medium55Arrange the steps to configure a new zone on a Palo Alto Networks firewall in the correct order.
Medium56An administrator wants to receive SNMP traps from the firewall for critical events such as failed login attempts and high CPU usage. Which configuration step is required?
Easy57A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)
Hard58An administrator wants to generate a report that shows the top applications by bandwidth usage over the last week. Which report type should be used to accomplish this?
Easy59A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)
EasyOther domains
All PCNSE exam domains
Frequently asked questions
- What does the Manage, Monitor and Operate domain cover on the PCNSE exam?
- You must be able to run the correct operational CLI commands, build and apply log forwarding profiles, and diagnose resource issues by cause. The single most important thing: know which command or configuration step actually produces the required outcome, not just its name.
- How many questions are in this domain?
- This page lists all 59 Manage, Monitor and Operate questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Manage, Monitor and Operate questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.