Courseiva

CCNA Manage, Monitor and Operate Questions

59 questions · Manage, Monitor and Operate · All types, answers revealed

1
MCQhard

A security operations center (SOC) uses Panorama to monitor all firewalls. They notice that some log entries show a severity of 'critical' but the alerting system does not fire. The log forwarding profile on Panorama is configured to send syslog alerts for severity 'critical'. The syslog server receives other logs from Panorama but not these critical logs. The administrator checks the Panorama configuration and finds that the log forwarding profile is applied to the correct log types. What is the most likely issue?

A.The log forwarding profile on Panorama is not applied to the managed firewalls.
B.The critical logs are generated on the firewall and not forwarded to Panorama.
C.The Panorama's log collector is not processing the logs correctly.
D.The syslog server is filtering out the critical logs based on the source IP.
AnswerB

Panorama only forwards logs it receives from managed firewalls. If critical logs are generated locally on a firewall and never sent to Panorama, Panorama's log forwarding profile cannot forward them, explaining why the syslog server receives other logs but not these.

Why this answer

The most likely issue is that the critical logs are generated on the firewall but not forwarded to Panorama. Panorama can only forward logs it has received from its managed firewalls; if the firewall’s log forwarding or logging settings (e.g., log severity threshold, log buffering, or connectivity to the Log Collector) prevent those critical logs from reaching Panorama, then Panorama’s syslog forwarding profile will never see them. The fact that other logs arrive at the syslog server indicates Panorama’s forwarding works, so the gap must be upstream at the firewall-to-Panorama log collection stage.

Exam trap

The trap here is that candidates assume Panorama’s log forwarding profile is the only configuration needed, overlooking that logs must first be collected from the firewall via the Log Collector, and that the firewall’s own logging settings or connectivity can prevent critical logs from reaching Panorama.

How to eliminate wrong answers

Option A is wrong because the log forwarding profile on Panorama is applied to the correct log types and the syslog server receives other logs, proving the profile is active; the issue is not about the profile being applied to firewalls but about logs not reaching Panorama. Option C is wrong because if the Log Collector were not processing logs correctly, other logs would also be missing or corrupted, but the syslog server receives other logs from Panorama, indicating the collector is functioning. Option D is wrong because the syslog server receives other logs from Panorama, so it is not filtering based on source IP; the problem is that the critical logs never leave Panorama, not that they are dropped by the syslog server.

2
MCQhard

A company uses Panorama to manage multiple firewalls. An administrator pushes a template that includes a new Security Profiles group, but the firewalls do not receive the profile group. What is the most likely cause?

A.The profile group references a profile that does not exist in the template.
B.The push was performed to device groups instead of templates.
C.The firewalls are not assigned to the template that contains the profile group.
D.The commit was not selected to include the new profiles.
AnswerC

Template membership governs which firewalls receive pushed configuration objects. A Security Profiles group defined in a template only reaches firewalls explicitly assigned to that template; unassigned devices keep their existing configuration, so the group never appears on them.

Why this answer

Panorama pushes templates to firewalls based on template assignment. If a firewall is not assigned to the template that contains the Security Profiles group, the firewall will never receive that configuration, regardless of the push operation. Template assignment is a prerequisite for any template-based configuration to be applied to a managed firewall.

Exam trap

The trap here is that candidates often confuse the push operation for device groups with the push for templates, assuming that a single push covers all configuration, when in fact Panorama requires separate pushes for templates and device groups, and template assignment is a prerequisite for receiving any template-based configuration.

How to eliminate wrong answers

Option A is wrong because if a profile group references a profile that does not exist in the template, Panorama would generate a validation error during a commit or push, preventing the push from succeeding entirely — the firewalls would not partially receive the group without the missing profile. Option B is wrong because Panorama pushes templates and device groups separately; a push to device groups does not affect template content, and the administrator would need to push templates to deliver the profile group. Option D is wrong because the commit operation is not a per-object selection; when a commit is performed on Panorama, all pending changes in the selected template or device group are included — there is no option to selectively exclude new profiles from a commit.

3
MCQeasy

Refer to the exhibit. The firewall's disk usage is at 85% overall, and the /opt/panlogs partition is at 92%. The administrator wants to free up space without losing important log data. Which action should be taken first?

A.Configure log auto-deletion in the Log Settings to purge logs older than a specified period
B.Add an external storage device to the firewall
C.Delete configuration files from /opt/pancfg
D.Delete the /opt/panlogs directory and recreate it
AnswerA

Auto-deletion targets the /opt/panlogs partition directly, purging the oldest logs first to reclaim space while retaining recent entries. It satisfies the constraint of freeing space without losing important log data, and is non-destructive compared with manual deletion or reformatting.

Why this answer

Configuring log auto-deletion in the Log Settings allows the administrator to automatically purge older logs based on a specified retention period, freeing up disk space on the /opt/panlogs partition without manually deleting important log data. This is the safest and most controlled method, as it respects the firewall's log management policies and ensures compliance with data retention requirements.

Exam trap

Palo Alto Networks often tests the misconception that deleting configuration files or directories is a valid troubleshooting step, when in fact the correct approach is to use built-in log management features like auto-deletion to safely reclaim space without data loss.

How to eliminate wrong answers

Option B is wrong because adding an external storage device does not free up existing disk space; it only provides additional capacity, and the immediate issue of 92% usage on /opt/panlogs remains unresolved. Option C is wrong because deleting configuration files from /opt/pancfg would remove critical firewall configuration data, potentially causing operational failures or loss of policy settings, and it does not address the log partition issue. Option D is wrong because deleting the /opt/panlogs directory and recreating it would permanently remove all log data, which violates the requirement to not lose important log data, and may also disrupt logging services until the directory is properly recreated with correct permissions.

4
MCQeasy

Refer to the exhibit. What does the uptime indicate?

A.The firewall license is about to expire.
B.The firewall is in active-passive HA mode.
C.The firewall has high memory usage.
D.The firewall has been restarted approximately 3 hours ago.
AnswerD

The uptime counter resets to zero whenever the dataplane restarts, so a value near three hours indicates the firewall was rebooted roughly that long ago. It reflects process restart time, not total device age or configuration commit history.

Why this answer

The uptime displayed in the exhibit shows the firewall has been running for approximately 3 hours. This directly indicates that the firewall was restarted or rebooted about 3 hours ago, making option D correct. Uptime is a measure of time since the last system boot, not related to licensing, HA mode, or memory usage.

Exam trap

The trap here is that candidates may confuse uptime with license expiration or HA status, but uptime is solely a measure of system runtime since last boot and has no bearing on licensing, HA mode, or memory usage.

How to eliminate wrong answers

Option A is wrong because license expiration is shown under 'License' or 'Device > Licenses', not in the uptime field; uptime only reflects system runtime since last boot. Option B is wrong because active-passive HA mode is indicated by HA configuration and state (e.g., 'active-passive' in HA settings), not by uptime; uptime values are independent of HA role. Option C is wrong because high memory usage is monitored via 'Device > Resources' or CLI commands like 'show system resources', not by uptime; uptime does not correlate with memory consumption.

5
Multi-Selecthard

Which TWO configurations are required for User-ID to work using the Windows User-ID Agent (WUA) in a distributed environment?

Select 2 answers
A.The User-ID Agent must have permissions to query Active Directory domain controllers.
B.Firewalls must be configured to send User-ID data to the Agent via Server Monitoring.
C.An Application Override policy must be created for User-ID traffic.
D.The firewall must be able to reach the User-ID Agent's IP address on TCP port 5007.
E.The User-ID Agent must be in the same Layer 2 subnet as the users.
AnswersA, D

User-ID Agent queries DCs for user logon events.

Why this answer

The Windows User-ID Agent (WUA) must have permissions to query Active Directory (AD) domain controllers to retrieve user login events (e.g., security event ID 4624). Without these permissions, the agent cannot map IP addresses to usernames, which is the core function of User-ID in a distributed environment.

Exam trap

The trap here is that candidates often confuse the direction of data flow, thinking the firewall sends data to the agent (Option B), or assume the agent must be on the same subnet as users (Option E), when in fact the agent only needs network reachability and AD query permissions.

6
MCQhard

A GlobalProtect gateway is configured as shown. Remote users report that they can connect to the gateway but cannot authenticate. The users are using the GlobalProtect client with certificate authentication. What is the most likely cause?

A.The IPSec crypto profile is too strong for the clients.
B.The IP pool is exhausted.
C.The DNS server is misconfigured, causing authentication failure.
D.The gateway does not have a root CA certificate imported for validating client certificates.
AnswerD

Without a trusted root CA certificate, the gateway cannot build a chain to validate the client certificates presented during the TLS handshake. Certificate authentication therefore fails after the tunnel connects, matching the reported symptom of connecting but not authenticating. Importing the issuing root CA under Device > Certificate Management resolves this.

Why this answer

For certificate-based authentication, the GlobalProtect gateway must trust the certificate presented by the client. This requires the gateway to have the root CA certificate that issued the client certificate imported into its trusted CA list. Without this root CA, the gateway cannot validate the client's certificate chain, causing authentication to fail even though the initial connection (e.g., IPSec tunnel establishment) succeeds.

Exam trap

The trap here is that candidates assume the connection success (tunnel established) means authentication should work, but certificate authentication requires a separate trust validation step that fails if the root CA is not imported on the gateway.

How to eliminate wrong answers

Option A is wrong because an IPSec crypto profile that is 'too strong' would prevent the client and gateway from agreeing on security parameters, causing the tunnel to fail entirely—not just authentication. Option B is wrong because an exhausted IP pool would prevent the client from obtaining an IP address after authentication, but the user would still be able to authenticate successfully. Option C is wrong because a misconfigured DNS server would affect name resolution (e.g., for portal/gateway FQDN) but does not directly impact the certificate validation process during authentication.

7
MCQmedium

A firewall's traffic logs are being forwarded to a Panorama appliance for centralized retention. An administrator notices that logs from one specific firewall are missing from Panorama even though the same firewall's logs appear locally. The firewall is managed by Panorama and shows as connected. Which cause is most likely?

A.The firewall's local log quota is full and is overwriting entries before Panorama can retrieve them.
B.The firewall's management interface certificate has expired, so the Panorama connection silently drops log traffic.
C.Panorama is in Panorma mode instead of management-only mode, so it cannot receive logs.
D.The log forwarding configuration on the firewall is missing a Panorama server profile or the correct log forwarding profile attachment.
AnswerD

For logs to reach Panorama, the firewall needs a Panorama server profile referenced in the log forwarding configuration, and the relevant Log Forwarding profile must be attached to the policy rules generating the traffic. A missing or misconfigured profile means sessions are logged locally but never sent to Panorama, which matches the symptom precisely.

Why this answer

Centralized log collection requires the firewall to reference a Panorama server profile in its log forwarding configuration and to attach the appropriate Log Forwarding profile to the rules that generate the logs. When either piece is missing, traffic is still logged locally but never transmitted to Panorama, exactly matching a single firewall whose logs are absent centrally.

Exam trap

The trap here is assuming that a connected management relationship also means logs are being forwarded, when log forwarding requires its own server profile and profile attachment.

8
MCQmedium

A network security engineer is validating a newly deployed firewall. The security policy is configured to allow web traffic from the Trust zone to the Untrust zone. After a user reports that a website is unreachable, the engineer runs the CLI command 'show session all filter source 10.1.1.50' and sees no active sessions. Which CLI command should the engineer use next to determine why the session was not established?

A.show counter global filter delta yes
B.show running security-policy
C.test security-policy-match application ssl from Trust to Untrust source 10.1.1.50 destination 203.0.113.10 destination-port 443 protocol 6
D.show session info
AnswerC

This command simulates the policy lookup for a specific flow and returns the matching rule or the reason for denial, such as 'implicit deny' or 'no matching rule'. It is the correct next step because it directly tests the policy configuration without generating live traffic, helping the engineer pinpoint whether the security policy is the cause of the missing session.

Why this answer

The most direct way to determine why a session was not established is to simulate the policy lookup for the exact traffic flow. The 'test security-policy-match' command evaluates the five-tuple against the current ruleset and returns the matching rule or the reason for denial, such as implicit deny or no matching rule. This quickly identifies policy misconfigurations without generating live traffic, making it the correct choice for troubleshooting a missing session.

Exam trap

The trap here is assuming that viewing the security policy configuration is sufficient to diagnose why a session was not created, when in fact a policy simulation is needed to see the actual match result.

9
MCQeasy

A network administrator needs to verify that the firewall is receiving dynamic updates for applications and threats. Which command should they use from the CLI to check the current update status and schedule?

A.show jobs all
B.show system update-server
C.show system info
D.show system dynamic-updates
AnswerD

The command 'show system dynamic-updates' displays the current versions of the installed dynamic updates, including applications, threats, and antivirus, as well as the schedule for future updates. This is the correct command to verify update status and schedule from the CLI.

Why this answer

The CLI command 'show system dynamic-updates' provides a summary of the currently installed dynamic update versions and the configured update schedule. This allows administrators to quickly verify that the firewall is up to date with the latest applications and threats content.

Exam trap

The trap here is confusing commands that show general system information or job status with the specific command that displays dynamic update versions and schedule.

10
MCQmedium

A company wants to forward logs from a firewall to a SIEM system with high reliability. Which log forwarding method ensures that logs are not lost if the SIEM is temporarily unreachable?

A.Email (SMTP) for each log.
B.Syslog over TCP with buffering enabled in the log forwarding profile.
C.Syslog over UDP with a log forwarding profile.
D.Syslog over SSL without optional buffering.
AnswerB

TCP provides session-oriented delivery with acknowledgements and retransmission, so the firewall detects an unreachable SIEM and holds logs in its buffer rather than dropping them. This directly satisfies the reliability constraint, unlike UDP-based syslog, which is fire-and-forget with no delivery guarantee.

Why this answer

Syslog over TCP with buffering enabled in the log forwarding profile ensures reliable delivery because TCP provides acknowledgment and retransmission of lost segments, while the buffering mechanism stores logs locally on the firewall when the SIEM is unreachable and retransmits them once connectivity is restored. This combination prevents log loss during temporary network or SIEM outages.

Exam trap

The trap here is that candidates often assume Syslog over TCP alone guarantees delivery, but without buffering enabled in the log forwarding profile, the firewall will drop logs if the TCP connection fails, making buffering the key differentiator for reliability.

How to eliminate wrong answers

Option A is wrong because email (SMTP) is not designed for high-volume, real-time log forwarding and can easily fail or queue indefinitely without reliable retransmission guarantees. Option C is wrong because Syslog over UDP is connectionless and inherently unreliable; logs are silently dropped if the SIEM is unreachable, with no buffering or retransmission. Option D is wrong because Syslog over SSL without optional buffering provides encryption but no local storage or retransmission mechanism; if the SIEM is unreachable, the TCP connection fails and logs are lost without buffering.

11
MCQeasy

An administrator needs to generate a report showing all traffic denied by the firewall over the past week. Which type of report in the firewall web interface should be used?

A.Application Report
B.Threat Report
C.URL Filtering Report
D.Traffic Report
AnswerD

The Traffic Report logs sessions the firewall allowed and denied, with details such as source, destination, application and rule. Filtering it to denied actions over the past week produces exactly the required list, which other report types do not capture.

Why this answer

The Traffic Report is the correct choice because it provides detailed logs of all traffic passing through the firewall, including both allowed and denied sessions. By filtering the report to show only denied traffic over the past week, the administrator can generate the exact report needed. Other report types focus on specific categories like applications, threats, or URLs, not general traffic denials.

Exam trap

The trap here is that candidates confuse 'denied traffic' with specific security features like threat prevention or URL filtering, but the Traffic Report is the only one that captures all policy-based denials regardless of the application or threat involved.

How to eliminate wrong answers

Option A is wrong because the Application Report focuses on application usage and bandwidth consumption, not on traffic that was denied by security policies. Option B is wrong because the Threat Report logs only traffic that triggered threat prevention signatures (e.g., exploits, malware), not all denied traffic (e.g., policy denials without threats). Option C is wrong because the URL Filtering Report logs only web traffic that was allowed or blocked based on URL categories, not all denied traffic (e.g., non-web traffic or policy-based denials).

12
MCQmedium

A company has a firewall with multiple virtual systems (vsys). The administrator wants to delegate management of one vsys to a junior administrator, allowing them to configure security policies but not access system settings or other vsys. Which administrative role should be assigned?

A.Virtual System Admin
B.Superuser
C.Device Admin
D.Role-Based Admin
AnswerA

A Virtual System Admin role scopes permissions to a single vsys, granting full policy configuration within it while denying access to system settings and other vsys. This satisfies the delegation constraint of policy-only rights without broader device administration.

Why this answer

A Virtual System Admin role is specifically designed to delegate administrative access to a single virtual system (vsys) within a Palo Alto Networks firewall. This role allows the junior administrator to configure security policies and objects within their assigned vsys, while explicitly preventing access to system settings, device-level configurations, or other virtual systems. This matches the requirement exactly.

Exam trap

The trap here is that candidates often confuse 'Virtual System Admin' with 'Role-Based Admin', thinking they need to create a custom role, when the predefined Virtual System Admin role is the exact fit for delegating per-vsys management.

How to eliminate wrong answers

Option B (Superuser) is wrong because a Superuser has full read-write access to all virtual systems and all system settings, which would grant the junior administrator access to other vsys and device-level configurations, violating the requirement. Option C (Device Admin) is wrong because a Device Admin has full access to the device's system settings and all virtual systems, again providing broader access than intended. Option D (Role-Based Admin) is wrong because it is a generic category for custom roles, but the specific predefined role that matches the requirement is Virtual System Admin; assigning a custom Role-Based Admin would require manually creating a role with the exact permissions, which is less direct and not the standard answer for this scenario.

13
MCQmedium

An engineer is troubleshooting a security policy that is not matching traffic as expected. The traffic is from source IP 10.1.1.10 to destination 172.16.0.1 port 443. The policy has source zone 'Internal', destination zone 'DMZ', source address '10.1.1.0/24', destination address '172.16.0.0/24', application 'ssl'. The firewall shows the traffic hitting a different rule. What is the most likely cause?

A.The source zone is incorrectly assigned; traffic is coming from a different zone.
B.The destination address is not in the specified subnet due to NAT.
C.The application 'ssl' does not match because the traffic is actually using TLS 1.3.
D.The traffic is being matched by an earlier rule with broader criteria.
AnswerD

Rule order matters; a prior rule with broader source/destination/application may match before the intended rule.

Why this answer

The most likely cause is that an earlier rule in the security policy rulebase matches the traffic before the intended rule. Palo Alto Networks firewalls evaluate security rules in sequential order from top to bottom, and the first rule that matches all criteria (source/destination zone, source/destination address, application, etc.) is applied. If a rule with broader criteria (e.g., any/any or a less specific application) appears earlier, it will match the traffic, preventing the intended rule from being hit.

Exam trap

Palo Alto Networks often tests the misconception that application signatures are version-specific (e.g., TLS 1.3 vs. SSL), but Palo Alto Networks uses generic application signatures that match all versions of a protocol, so candidates incorrectly eliminate the correct answer due to a misunderstanding of application identification.

How to eliminate wrong answers

Option A is wrong because the traffic is from source IP 10.1.1.10, which is within the 10.1.1.0/24 subnet, and the policy specifies source zone 'Internal'; if the zone were incorrectly assigned, the traffic would not match any rule with that zone, but the firewall shows it hitting a different rule, not failing to match. Option B is wrong because NAT does not change the destination address in the security policy match; the firewall evaluates the pre-NAT destination address (172.16.0.1) against the destination address object (172.16.0.0/24), and 172.16.0.1 is within that subnet, so this is not a mismatch. Option C is wrong because the application 'ssl' in Palo Alto Networks is a generic signature that matches SSL/TLS traffic regardless of the TLS version (e.g., TLS 1.3), as the firewall identifies the application by protocol behavior and handshake patterns, not by the specific TLS version number.

14
MCQhard

Two firewalls in an active/passive HA configuration are not synchronizing sessions. The 'show high-availability state' command shows both peers as 'active' and 'passive' correctly, but session synchronization is not working. What is the most likely cause?

A.The HA3 link is not configured or is misconfigured.
B.The HA2 link is down.
C.The passive firewall does not have management API access.
D.The logging settings on both firewalls are different.
AnswerB

Correct. The HA2 link is responsible for session synchronization in active/passive mode. If it is down, sessions will not sync.

Why this answer

In an active/passive HA configuration on PAN-OS, session synchronization occurs over the HA2 link (control link). If the HA2 link is down, session synchronization will not work even though the HA state shows 'active' and 'passive' correctly. The HA3 link is used for packet forwarding in active/active mode, not for session sync in active/passive mode.

Exam trap

The trap here is that candidates often confuse the HA2 link (control link) with the HA3 link (session sync link), assuming that if HA state is correct and HA2 is up, session synchronization must also be working.

How to eliminate wrong answers

Option B is wrong because the HA2 link is used for control traffic (keepalives, configuration sync) and not for session synchronization; a down HA2 link would cause HA state issues, not just session sync failure. Option C is wrong because management API access on the passive firewall is unrelated to session synchronization; it controls administrative access, not data-plane session replication. Option D is wrong because differing logging settings between firewalls do not impact session synchronization; logging is a separate function from session table replication.

15
MCQmedium

A network security administrator is investigating a suspicious session on a PA-3220 firewall. The administrator needs to determine the exact security policy rule that permitted the session to be established. Which action should the administrator take to accomplish this goal?

A.Use the 'show session all' CLI command and look for the policy name in the output.
B.Use the Session Browser in the web interface and view the 'Policy' column for the specific session.
C.Check the Traffic log and filter by the session's source and destination IP addresses.
D.Use the 'test security-policy-match' CLI command with the source and destination IP addresses and ports.
AnswerB

The Session Browser displays active sessions and includes a 'Policy' column that shows the name of the security policy rule that matched the session. By locating the specific session, the administrator can directly see which rule permitted the traffic, providing the exact policy name without needing to infer it.

Why this answer

To identify the exact security policy rule that allowed a specific session, the administrator can use the Session Browser in the web interface, which shows the policy name for each active session. This real-time view is more direct than checking logs or using simulation commands, especially if the session is ongoing or logging is incomplete.

Exam trap

The trap here is assuming that the Traffic log always contains the policy name for every session, but logging may be disabled or the session may still be active, so the log might not have the entry.

16
Multi-Selectmedium

A network engineer is troubleshooting high latency on the firewall. Which THREE commands from the CLI should be used to identify potential bottlenecks? (Choose three.)

Select 3 answers
A.show running resource-monitor
B.show session info
C.show log traffic
D.show system resources
E.show counter global
AnswersA, D, E

This command shows dataplane resource utilization, useful for identifying CPU/memory bottlenecks.

Why this answer

'show running resource-monitor' displays real-time CPU and memory utilization per dataplane or control plane process, which directly helps identify resource exhaustion causing latency. This command provides granular per-process metrics, unlike the aggregated 'show system resources', making it essential for pinpointing bottlenecks in high-latency scenarios.

Exam trap

The trap here is that candidates often choose 'show session info' thinking it reveals session table overload, but it only shows session details, not utilization percentages or drop counts, which are found in 'show counter global' and 'show running resource-monitor'.

17
MCQeasy

A user complains that they cannot access internal resources via GlobalProtect. The firewall shows the user is connected with an IP address from the tunnel pool. Which log type should the administrator check first to determine if traffic is being allowed or denied?

A.System logs.
B.Traffic logs.
C.Threat logs.
D.User-ID logs.
AnswerB

Traffic logs record the security policy action, source, destination and application for each session, showing whether GlobalProtect tunnel traffic to internal resources was allowed or denied. This directly answers whether policy is blocking the user's access.

Why this answer

The administrator should check Traffic logs first because they record every session attempt, showing whether traffic was allowed or denied based on security policies. Since the user is connected with a tunnel IP, the issue is likely policy-based, and Traffic logs provide the source, destination, and action (allow/deny) for each session, directly revealing if the traffic is being blocked.

Exam trap

The trap here is that candidates may think User-ID logs (Option D) are relevant because the user is connected, but User-ID logs only show authentication mappings, not traffic policy decisions.

How to eliminate wrong answers

Option A is wrong because System logs record system-level events (e.g., process restarts, configuration changes) and do not show per-session allow/deny decisions for user traffic. Option C is wrong because Threat logs capture only traffic that matches intrusion prevention or antivirus signatures, not general allow/deny decisions. Option D is wrong because User-ID logs map usernames to IP addresses but do not indicate whether traffic is permitted or denied by security policies.

18
Multi-Selecthard

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Select 3 answers
A.Large number of dynamic IP address group lookups.
B.Inefficient security policy rules causing excessive session processing.
C.Insufficient disk space on the log partition.
D.Excessive logging due to very frequent session matches.
E.BGP prefix flapping causing route recalculations.
AnswersA, B, D

Dynamic group lookups can be CPU intensive.

Why this answer

A large number of dynamic IP address group lookups can cause high CPU utilization because each lookup requires the firewall to evaluate the dynamic group membership in real time, often involving LDAP or other directory queries. This process is computationally expensive, especially when policies trigger frequent lookups for every new session, leading to sustained CPU spikes.

Exam trap

The trap here is that candidates often confuse disk space issues (Option C) with CPU utilization, but disk space problems affect storage and logging, not CPU directly, while BGP flapping (Option E) is a control-plane issue that is less commonly cited as a top cause of high CPU in Palo Alto Networks documentation.

19
Multi-Selecthard

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

Select 2 answers
A.Log forwarding must use TLS encryption
B.Log forwarding requires an external syslog server
C.Log forwarding supports sending logs to multiple destinations
D.Log forwarding can be configured per security policy rule
E.Log forwarding can only send logs to a single Panorama collector
AnswersC, D

Panorama log forwarding profiles let you define multiple server entries within a single profile, so each log type can be dispatched to several collectors or syslog receivers simultaneously. This satisfies the requirement for redundancy or parallel retention without duplicating profiles.

Why this answer

Option C is correct because Panorama log forwarding profiles allow you to define multiple server entries (up to four syslog servers, plus SNMP, email, or HTTP destinations) within a single log forwarding profile, so logs can be sent to several destinations simultaneously. Option D is correct because log forwarding profiles are attached directly to security policy rules (via the Actions tab's Log Forwarding setting), enabling per-rule control over where that rule's traffic and threat logs are sent. Option A is incorrect because TLS encryption is not mandatory for log forwarding; syslog forwarding can use UDP or plain TCP, and TLS is only one optional transport choice.

Option B is incorrect because an external syslog server is not required — logs can be forwarded to Panorama itself, to another managed firewall, or to email/SNMP/HTTP destinations. Option E is incorrect because log forwarding is not limited to a single Panorama collector; multiple destinations, including multiple Panorama or syslog targets, can be configured in one profile.

Exam trap

The trap here is that candidates assume Log Forwarding is limited to a single destination or requires a syslog server, but Panorama actually supports multiple destinations and various log types without mandating syslog or TLS.

20
MCQeasy

A network administrator needs to monitor the firewall's interface status and receive alerts when an interface goes down. Which built-in feature should they configure?

A.Syslog forwarding with severity level 'critical'
B.NetFlow export for interface statistics
C.SNMP traps for linkDown
D.Email alerts for system logs
AnswerC

SNMP traps can be configured to send alerts for linkDown events. The firewall supports SNMP traps for interface status changes, including linkDown and linkUp. By configuring an SNMP trap destination and enabling linkDown traps, the administrator can receive immediate notifications when an interface goes down, meeting the monitoring requirement.

Why this answer

SNMP traps are the standard method for receiving real-time alerts on interface status changes. Configuring SNMP traps for linkDown events allows the administrator to be notified immediately when an interface goes down. Other options like syslog, email alerts, or NetFlow do not provide the same immediate and specific alerting for interface status.

Exam trap

The trap here is assuming that any log forwarding method can provide real-time interface status alerts.

21
MCQmedium

An administrator manages a PA-5220 pair running PAN-OS 11.1. During a change window, the active firewall's management plane becomes unreachable and the device fails over to the passive peer. The administrator wants to review the events that occurred on the failed device before the failover. Which action should the administrator take to obtain this information?

A.Connect to the failed device console and review the HA and system logs stored locally in the management plane log files.
B.On the passive peer, run the show high-availability state command and export the output to a file for review.
C.Use the Panorama-managed Config Audit feature to compare the running configuration against the last committed version on the failed device.
D.On the active peer, run the show session all filter source command to identify sessions that terminated during the failover.
AnswerA

The management plane stores HA, system, and configuration logs locally on the device. Even when the management interface is unreachable over the network, console access allows the administrator to read these logs and reconstruct the events leading up to the failover, which is the intended way to investigate this scenario.

Why this answer

Management plane logs are retained locally on each firewall and record system, HA, and configuration events. When the management interface is unreachable but the device still powers on, console access lets the administrator read those logs directly. Panorama config audit, HA state output, and session tables all describe current or configuration state rather than the historical event sequence needed here.

Exam trap

The trap here is assuming that an unreachable management interface means the logs are lost, when local management plane logs remain accessible through the console.

22
MCQeasy

An organization has a pair of PA-5250 firewalls in active/passive HA. During a maintenance window, the active firewall is rebooted. After the reboot, the firewall that was passive becomes active and passes traffic. However, the other firewall remains in a non-functional state and shows 'unknown' as HA state. The administrator checks the HA configuration and finds both firewalls have the same HA settings. What is the most likely issue?

A.The backup firewall has a different software version.
B.The floating IP addresses are not configured.
C.The HA keepalive timer is too short.
D.The HA control link is down or misconfigured.
AnswerD

HA state synchronisation and election traffic traverse the dedicated HA control link. If that link is down or misconfigured, the rebooted peer cannot exchange hello and state messages, so it remains 'unknown' even though data-plane failover succeeded.

Why this answer

After a reboot, the previously active firewall fails to join the HA pair and shows 'unknown' state, which indicates it cannot communicate with its peer. Since both firewalls have identical HA settings, the most likely cause is that the HA control link (the dedicated link used for heartbeat and state synchronization) is down or misconfigured, preventing the rebooted firewall from establishing a valid HA session.

Exam trap

The trap here is that candidates often assume a software version mismatch or keepalive timer issue is the cause, but the 'unknown' state specifically points to a loss of control-plane connectivity, not a version or timer problem.

How to eliminate wrong answers

Option A is wrong because if the backup firewall had a different software version, the HA pair would typically show a version mismatch or fail to form, but the backup became active and passed traffic successfully, indicating compatible versions. Option B is wrong because floating IP addresses are used for service access and do not affect the HA state or the ability of a firewall to join the pair; the 'unknown' state is a control-plane issue, not a data-plane addressing issue. Option C is wrong because a keepalive timer that is too short would cause flapping or frequent state transitions, not a persistent 'unknown' state; the rebooted firewall would still attempt to re-establish the control link and report its state.

23
MCQmedium

An administrator is troubleshooting high CPU usage on a PA-5250 firewall. The CPU usage spikes every 5 minutes. Which CLI command should be used to identify the process causing the spike?

A.show session all
B.show dataplane
C.show running resource-monitor
D.show system resources
AnswerC

The resource-monitor command samples per-process CPU and memory usage at intervals, so it captures the five-minute spike and names the offending process. Plain 'show system resources' gives only a point-in-time snapshot, which would likely miss the periodic spike.

Why this answer

The 'show running resource-monitor' command displays real-time CPU and memory usage per process on Palo Alto Networks firewalls. Since the CPU spikes every 5 minutes, this command can identify which specific process (e.g., management-plane daemon, dataplane task) is consuming the most CPU during those intervals, enabling targeted troubleshooting.

Exam trap

The trap here is that candidates often confuse 'show system resources' (overall utilization) with 'show running resource-monitor' (per-process breakdown), assuming the former is sufficient for process-level diagnosis when it only shows aggregate CPU and memory percentages.

How to eliminate wrong answers

Option A is wrong because 'show session all' lists active sessions but does not provide per-process CPU usage data. Option B is wrong because 'show dataplane' shows dataplane statistics and packet processing info, not management-plane process CPU consumption. Option D is wrong because 'show system resources' gives overall system CPU and memory usage but lacks the granular per-process breakdown needed to pinpoint the specific process causing the spike.

24
MCQmedium

A team uses the Panorama API to generate custom reports. They need to retrieve a list of all rules that have logging at session end enabled. Which API endpoint should be used?

A.GET /api/?type=config&action=get&xpath=/config/devices/entry/vsys/entry/rulebase/security/rules
B.GET /api/?type=op&cmd=<show><log></log></show>
C.GET /api/?type=config&action=get&xpath=/config/shared/log-settings
D.GET /api/?type=report&reporttype=predefined
AnswerA

Retrieving the security rulebase via a config get returns each rule's definition, including its log-end setting, so the team can filter for rules with session-end logging enabled. This satisfies the requirement to enumerate all such rules, since logging configuration lives in the rulebase itself rather than operational logs.

Why this answer

Security rules and their log settings live in the rulebase under /config/devices/entry/vsys/entry/rulebase/security/rules, so a config-type GET against that XPath returns every security rule including the log-end attribute. Filtering the returned XML for log-end='yes' yields the list of rules with session-end logging enabled. This is the correct API path for reading rule configuration, not logs or reports.

Exam trap

The trap is confusing configuration retrieval with log retrieval — candidates see 'logging' in the question and pick the show log or report endpoint, but the question asks for rule configuration, which lives in the config tree.

How to eliminate wrong answers

Option B is wrong because type=op with a show log command retrieves actual log entries from the log database, not the rule configuration that defines which rules log at session end. Option C is wrong because /config/shared/log-settings holds global log forwarding and profile settings, not individual security rule definitions. Option D is wrong because type=report with a predefined reporttype returns generated report data, not raw rule configuration, and cannot be filtered by the log-end attribute.

25
MCQmedium

A firewall is dropping traffic that should be allowed. The security policy appears correct. An administrator checks the session table and notices the session state is 'CLOSE'. What is the most likely cause of the traffic being dropped?

A.The server is sending a FIN/RST prematurely due to application layer issues.
B.A deny all security policy is blocking the traffic.
C.Asymmetric routing is causing the session to be torn down.
D.Packet buffer exhaustion on the firewall is causing drops.
AnswerA

A session in CLOSE state means a FIN or RST was already exchanged, so the firewall treats the flow as terminating and drops subsequent packets. A premature FIN/RST from the server, caused by application-layer issues, produces this state despite a correct security policy.

Why this answer

When a firewall sees a session state of 'CLOSE', it indicates that the session has been terminated via a proper TCP FIN or RST exchange. If the server is sending a FIN or RST prematurely due to application-layer issues (e.g., a misconfigured application, a bug causing early connection closure, or a load balancer sending a reset), the firewall will close the session and drop subsequent packets that belong to that flow, even if the security policy allows the traffic. This is because the firewall's session table no longer has an active session for the traffic, so the packets are treated as unsolicited and dropped.

Exam trap

The trap here is that candidates often assume a 'CLOSE' state means the firewall is actively dropping traffic due to a policy or resource issue, but the correct interpretation is that the session was properly terminated and the firewall is simply enforcing that closure by dropping subsequent packets.

How to eliminate wrong answers

Option B is wrong because a 'deny all' security policy would cause the firewall to drop traffic at the policy lookup stage, not after a session is established and then closed; the session state would not show 'CLOSE' but rather the traffic would never create a session. Option C is wrong because asymmetric routing typically causes the firewall to see only one direction of traffic, leading to session setup failures or 'half-open' states, not a clean 'CLOSE' state; the firewall would drop packets due to no matching session, but the session state would not be 'CLOSE' unless a proper teardown occurred. Option D is wrong because packet buffer exhaustion causes random drops or session setup failures, not a specific 'CLOSE' state; the firewall would likely show session states like 'INIT' or 'ACTIVE' with drops, not a clean teardown.

26
Multi-Selectmedium

An administrator is preparing a PA-3220 running PAN-OS 11.0 for a maintenance window and wants to capture the current operational state so it can be compared after the window. Which two actions should the administrator take to preserve this state for later comparison? (Choose two.)

Select 2 answers
A.Delete the oldest log segments to free space so new logs are not lost during the window.
B.Generate a Tech Support File from the device to capture logs, configuration, and system state in one archive.
C.Export a named configuration snapshot so the current committed configuration can be restored or diffed later.
D.Change the management interface IP address so the device is reachable from a different subnet after the window.
E.Run the request system reboot command to flush volatile state so the snapshot is clean.
AnswersB, C

The Tech Support File bundles the running configuration, logs, and diagnostic output into a single archive. It is designed exactly for capturing a device's state at a point in time so it can be reviewed or compared later, which fits the goal of preserving the pre-maintenance state for post-window comparison.

Why this answer

Preserving state before maintenance involves capturing both configuration and diagnostics. A named configuration snapshot saves the committed configuration for later diff or rollback, while a Tech Support File archives configuration, logs, and system diagnostics in one artifact. Rebooting, deleting logs, and changing the management address all alter the device rather than preserve its state.

Exam trap

The trap here is treating a reboot or log cleanup as preparation, when both destroy the very state the administrator intends to preserve for comparison.

27
MCQmedium

A security administrator needs to ensure that the firewall sends an email notification to the security team whenever a critical threat is detected. The email server is reachable at 10.10.10.5, and the firewall's management interface is in the 10.10.10.0/24 subnet. Which configuration step is required to enable email notifications for critical threats?

A.Configure a Syslog server profile under Device > Server Profiles > Syslog and set the severity level to critical.
B.Configure an Email server profile under Device > Server Profiles > Email and then attach it to a Log Forwarding profile used in the security policy.
C.Configure a Log Forwarding profile under Objects > Log Forwarding and enable email notifications directly in the profile.
D.Configure an SNMP trap destination under Device > Server Profiles > SNMP and enable traps for critical threats.
AnswerB

To send email notifications for threats, you must create an Email server profile with the SMTP server details and then reference it in a Log Forwarding profile. The Log Forwarding profile is then applied to the security policy that matches the traffic. This is the standard method for email alerting on critical threats.

Why this answer

The correct approach is to create an Email server profile that defines the SMTP server, and then reference that profile within a Log Forwarding profile. The Log Forwarding profile is then attached to the security policy that logs the critical threats. This ensures that when a threat is detected, an email is sent.

Other options involve different server types that do not provide email functionality.

Exam trap

The trap here is assuming that Log Forwarding profiles can directly send email without an Email server profile.

28
MCQmedium

Refer to the exhibit. Which SSL protocol version is blocked as per this decryption profile?

A.TLS 1.1
B.TLS 1.0
C.TLS 1.3
D.TLS 1.2
AnswerA

The profile explicitly blocks TLS 1.1.

Why this answer

The decryption profile in the exhibit shows 'TLS 1.1' explicitly selected under 'Block SSL/TLS Versions,' meaning any session attempting to negotiate TLS 1.1 will be blocked. This is a direct configuration setting in Palo Alto Networks firewalls where you can selectively block specific SSL/TLS protocol versions to enforce stronger cryptographic standards.

Exam trap

Palo Alto Networks often tests the ability to read the exhibit carefully—candidates may assume that because TLS 1.1 is a deprecated protocol, the question is about which version is allowed, or they might confuse the 'Block' list with the 'Allow' list, leading them to pick TLS 1.0 or TLS 1.2 as the blocked version.

How to eliminate wrong answers

Option B is wrong because TLS 1.0 is not selected in the exhibit; only TLS 1.1 is checked, so TLS 1.0 remains allowed unless explicitly blocked. Option C is wrong because TLS 1.3 is not listed in the block options (the exhibit only shows TLS 1.0, 1.1, and 1.2), and it is not selected. Option D is wrong because TLS 1.2 is not checked in the exhibit; it is allowed by default unless explicitly blocked.

29
MCQmedium

An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?

A.Add an external disk to the firewall
B.Configure log export and auto-deletion in Log Settings
C.Disable logging for non-critical traffic
D.Manually delete logs from the CLI
AnswerB

Log Settings controls log storage behaviour, including export to external servers and automatic deletion of older logs once thresholds are reached. Enabling auto-deletion directly reduces disk consumption, satisfying the requirement to reclaim space without manual intervention.

Why this answer

The firewall's log settings allow administrators to configure automatic log export and auto-deletion policies. By enabling log export to an external server (e.g., syslog) and setting a retention period or disk usage threshold, the firewall will automatically purge older log files when disk usage reaches a specified limit, such as 85%. This directly addresses the need to reduce disk usage without manual intervention or disabling logging.

Exam trap

The trap here is that candidates may confuse 'adding external storage' (Option A) as a solution for disk usage, but the question specifically asks for automatic deletion of older logs, not just expanding capacity.

How to eliminate wrong answers

Option A is wrong because adding an external disk does not automatically delete older logs; it only provides additional storage, which may delay but not solve the underlying issue of log growth. Option C is wrong because disabling logging for non-critical traffic reduces visibility and is not a targeted method for managing disk usage; it also violates best practices for security monitoring. Option D is wrong because manually deleting logs from the CLI is a reactive, non-automated approach that requires ongoing administrative effort and does not provide a sustainable solution for automatic log rotation.

30
MCQeasy

An administrator needs to ensure that the firewall sends an alert to an external server whenever a critical threat is detected, and also wants to receive a daily summary of blocked traffic. Which two log forwarding destinations should be configured to satisfy both requirements?

A.Configure an SNMP trap server profile for the daily summary and an email profile for the critical threat alerts.
B.Configure a syslog server profile for the critical threat alerts and a scheduled report for the daily summary.
C.Configure a syslog server profile for the daily summary and an email profile for the critical threat alerts.
D.Configure an email profile for the critical threat alerts and a scheduled report for the daily summary.
AnswerD

Email profiles attached to a log forwarding profile can trigger notifications when matching threat logs are generated, satisfying the immediate alert requirement. Scheduled reports can be configured to run daily and include data such as blocked traffic, satisfying the summary requirement. Together they map directly to both needs.

Why this answer

Critical threat alerts are event-driven and are best delivered through an email profile referenced by a log forwarding profile, which fires when a matching log is generated. A recurring summary of blocked traffic is a scheduled reporting task, produced by a report configured to run daily. Syslog streams raw events and does not produce summaries, and SNMP traps target device-level events rather than log content.

Exam trap

The trap here is confusing raw log streaming over syslog with an alerting mechanism, when a targeted notification requires a log forwarding profile with an email action.

31
Multi-Selectmedium

An administrator is preparing to upgrade a PA-5220 firewall from PAN-OS 10.2 to a later maintenance release. Before the upgrade, the administrator wants to minimize the chance of a failed upgrade and ensure a rollback path exists. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Verify that the current configuration passes validation and resolve any commit warnings before starting.
B.Change the management interface to a different IP address so the upgrade does not conflict with the old configuration.
C.Delete the previous PAN-OS image from the firewall to free space for the new version.
D.Export a named configuration snapshot and a device state backup to an external server before upgrading.
E.Disable all Security policy rules temporarily so that traffic is not inspected during the upgrade.
AnswersA, D

Configuration errors or unresolved commit warnings can cause the post-upgrade commit to fail, leaving the firewall in an inconsistent state. Validating the configuration and clearing warnings beforehand ensures the new PAN-OS version can commit the existing configuration cleanly, which directly reduces the risk of a failed upgrade and preserves a predictable rollback point.

Why this answer

Validating the configuration and clearing commit warnings ensures the new PAN-OS version can commit the existing configuration, and exporting both a configuration snapshot and a device state backup creates an external restore point. Together these steps reduce upgrade risk and guarantee a usable rollback path if the new version misbehaves.

Exam trap

The trap here is treating free-space cleanup as more important than preserving the previous image, when the previous image is the primary rollback mechanism.

32
MCQmedium

What does the session state 'SYN_SENT' indicate about this traffic flow?

A.The session has been torn down by the server.
B.The firewall has sent a SYN packet and is waiting for a response.
C.The traffic is being dropped due to asymmetric routing.
D.The application has been identified as incomplete.
AnswerB

SYN_SENT means the firewall initiated the connection by transmitting a SYN packet and now awaits the returning SYN-ACK from the responder. This half-open state confirms the firewall is the active sender, not the receiver, of the initial handshake packet.

Why this answer

The SYN_SENT session state in a Palo Alto Networks firewall indicates that the firewall has sent a SYN packet to initiate a TCP three-way handshake and is awaiting a SYN-ACK response from the remote host. This state is part of the firewall's session setup process, where it tracks the TCP connection state machine to ensure proper traffic flow. It does not imply a teardown, asymmetric routing drop, or incomplete application identification.

Exam trap

The trap here is that candidates confuse SYN_SENT with a session teardown state or assume it indicates a problem like asymmetric routing, when in fact it is a normal transient state during TCP connection setup that only becomes problematic if it persists beyond the timeout.

How to eliminate wrong answers

Option A is wrong because a session torn down by the server would show states like FIN_WAIT, CLOSE_WAIT, or TIME_WAIT, not SYN_SENT, which is an initial handshake state. Option C is wrong because asymmetric routing typically causes sessions to be in a 'half-open' state or show as 'drop' due to security policy mismatch, not SYN_SENT; SYN_SENT is a normal transient state during connection establishment. Option D is wrong because application identification occurs after the TCP handshake completes and data is exchanged; SYN_SENT is too early in the flow for app-ID to be determined, and an 'incomplete' application would be flagged later, not at this stage.

33
MCQmedium

A company has configured User-ID with Active Directory polling. Some users cannot access resources even though their security policy rules appear correct. The administrator verifies that the User-ID agent is connected and polling. What additional step should the administrator take?

A.Restart the User-ID agent service.
B.Check the firewall's management plane CPU usage.
C.Ensure the firewall has a license for User-ID.
D.Verify that the user group mapping is correct.
AnswerD

Group mapping determines which users inherit policy based on their directory groups. With Active Directory polling, the agent retrieves group membership alongside user-to-IP mappings, so stale or incorrect group data leaves users unmatched by rules. Verifying mapping confirms the identity data feeding policy evaluation is accurate, resolving access failures despite correct rules.

Why this answer

Even if the User-ID agent is connected and polling, the firewall may not have the correct group-to-user mappings. Without accurate group mapping, security policies that reference user groups will fail to match, causing access issues for users who are members of those groups. The administrator should verify the group mapping configuration in the User-ID agent or on the firewall to ensure users are properly associated with their groups.

Exam trap

The trap here is that candidates assume a connected and polling User-ID agent guarantees correct policy enforcement, overlooking the critical step of verifying group mapping accuracy, which is a common misconfiguration in Active Directory environments.

How to eliminate wrong answers

Option A is wrong because restarting the User-ID agent service is a generic troubleshooting step that does not address the root cause of incorrect group mapping; the agent is already connected and polling, so a restart would not fix mapping errors. Option B is wrong because checking the firewall's management plane CPU usage is relevant for performance issues, not for user authentication or group mapping problems; high CPU would not prevent users from accessing resources if policies are correct. Option C is wrong because User-ID functionality does not require a separate license; it is included with the firewall's base subscription (e.g., Threat Prevention or URL Filtering), so a missing license is not the issue here.

34
Multi-Selectmedium

A security engineer is configuring a Palo Alto Networks firewall to send alerts to an external SNMP manager. The engineer wants to ensure that the firewall sends SNMP traps for specific events, such as a link state change and a configuration change. Which two actions must the engineer perform to achieve this? (Choose two.)

Select 2 answers
A.Configure an SNMP server profile with the manager's IP address and community string.
B.Configure a log forwarding profile to send SNMP traps.
C.Create a security policy rule to allow SNMP traffic from the firewall to the manager.
D.Enable SNMP traps for link state and configuration changes in the SNMP setup.
E.Enable SNMP on the dataplane interfaces to allow trap generation.
AnswersA, D

An SNMP server profile defines the SNMP manager's IP address, port, and community string (for SNMPv2c) or user credentials (for SNMPv3). Without this profile, the firewall does not know where to send traps. This is a mandatory step to enable SNMP trap forwarding. The engineer must create and apply this profile to the firewall's management interface or a specific interface.

Why this answer

To send SNMP traps for specific events, the engineer must first configure an SNMP server profile with the manager's details, and then enable the desired traps in the SNMP setup. These two steps ensure the firewall knows where to send traps and which events to report. Security policy rules and log forwarding profiles are not involved in system-level SNMP trap generation, and SNMP operates on the management plane, not the dataplane.

Exam trap

The trap here is assuming that security policy rules or log forwarding profiles are needed for SNMP traps, when in fact SNMP trap configuration is separate and managed entirely within the SNMP setup.

35
MCQmedium

An administrator needs every administrator login, configuration commit, and firewall restart to be recorded in a central location for an upcoming audit. The auditor requires that the records be queryable by username and timestamp, and that they be retained independently of the firewall's own log storage. Which action should the administrator take to meet these requirements?

A.Enable the Audit Log on the management plane and forward it to an external syslog server.
B.Configure a Log Forwarding profile on the management interface to send system logs to an external server.
C.Configure a Syslog server profile under Device > Server Profiles > Syslog and attach it to the Management interface's log settings.
D.Create a custom report under Monitor > Manage Custom Reports that includes the configuration log and schedule it to be emailed daily.
AnswerA

The audit log records administrative actions, including administrator logins, configuration commits, and system restarts, and each entry includes the username and a timestamp. Forwarding it to an external syslog server keeps the records independent of the firewall's local log storage, so the audit trail survives log rotation or device replacement and remains queryable for the auditor.

Why this answer

Administrative activity such as administrator logins, configuration commits, and reboots is recorded in the management-plane audit log, which includes the username and timestamp for each entry. To retain those records independently of the firewall's local storage, the audit log must be forwarded to an external syslog server, satisfying both the query and retention requirements.

Exam trap

The trap here is assuming that any syslog forwarding configuration captures administrator activity, when only the audit log records management-plane actions.

36
MCQhard

An administrator notices that the firewall's dataplane CPU is consistently high and wants to determine which application is generating the most traffic without waiting for scheduled reports. Which action provides the most immediate visibility into top applications by session and byte count?

A.Enable packet capture on the untrust zone and inspect the captured packets to identify the dominant application.
B.Use the Application Command Center (ACC) on the dashboard, which aggregates traffic by application, source, and destination.
C.Configure a new scheduled report for application usage and wait for the next daily run to review the results.
D.Run the show session all command and manually sort the output by byte count to identify the busiest applications.
AnswerB

The ACC aggregates recent traffic and presents top applications, sources, destinations, and threats in a dashboard view without waiting for a scheduled report. It is designed for immediate operational visibility and updates as new logs arrive, making it the fastest way to see which application is driving traffic and load.

Why this answer

The Application Command Center aggregates log data into dashboard widgets that show top applications, users, and threats, updating as logs are generated. It provides immediate operational visibility without waiting for a scheduled report and summarizes far more usefully than raw session or packet data. Scheduled reports and packet captures are slower or more manual and do not deliver the ranked application view required.

Exam trap

The trap here is reaching for raw session or packet data when a purpose-built aggregated dashboard already answers the question faster.

37
MCQeasy

A firewall is experiencing performance issues. The administrator wants to collect diagnostic data for TAC analysis. Which command generates a comprehensive support file?

A.debug system dump
B.show system resources
C.show log system
D.generate tech-support file
AnswerD

The `generate tech-support file` command bundles comprehensive diagnostics — configuration, logs, and system state — into a single archive for TAC analysis. It satisfies the stem's requirement for a comprehensive support file, unlike narrower commands that capture only specific subsystems or packet-level data.

Why this answer

The 'generate tech-support file' command collects a comprehensive archive of system logs, configuration, resource utilization, and diagnostic data into a single file, which is the standard method for providing TAC with the necessary information to analyze performance issues. This command is specifically designed for troubleshooting and support scenarios, unlike other commands that only capture partial or real-time data.

Exam trap

Palo Alto Networks often tests the distinction between commands that provide real-time snapshots (like 'show system resources') versus commands that generate a comprehensive diagnostic archive (like 'generate tech-support file'), leading candidates to mistakenly choose a command that only shows current state rather than the full dataset needed for TAC analysis.

How to eliminate wrong answers

Option A is wrong because 'debug system dump' is not a valid command on Palo Alto Networks firewalls; the correct command for generating a core dump or debug data is 'debug system core-dump', and it does not produce a comprehensive support file. Option B is wrong because 'show system resources' only displays current CPU, memory, and disk usage in real-time, which is insufficient for TAC analysis as it lacks historical logs, configuration, and other diagnostic data. Option C is wrong because 'show log system' only displays system logs from the log buffer or disk, but it does not include configuration, resource snapshots, or other critical diagnostic information needed for a full TAC investigation.

38
MCQeasy

A network administrator wants to generate a report that shows the top applications used over the past week. The firewall is managed by Panorama. Which Panorama feature should the administrator use to create and schedule this report?

A.Use the Manage Custom Reports feature under Monitor > Manage Custom Reports to create a report and schedule it.
B.Use the PDF Report feature under Monitor > PDF Reports to create a report.
C.Use the Log Forwarding profile to send logs to an external syslog server and then generate reports on that server.
D.Use the Application Command Center (ACC) to view top applications and export the data.
AnswerA

Panorama's Manage Custom Reports feature allows you to create reports based on various data sources, including traffic logs, and schedule them for generation and distribution. This is the correct tool to create a scheduled report of top applications.

Why this answer

Panorama's Manage Custom Reports feature is designed for creating, scheduling, and distributing reports. It allows selecting data sources such as traffic logs and defining the report content, including top applications. The report can be scheduled to run at intervals and emailed to recipients.

Other options involve real-time monitoring or external systems, which do not provide the scheduled reporting capability within Panorama.

Exam trap

The trap here is confusing Panorama's reporting feature with the firewall's PDF Reports or real-time monitoring tools.

39
MCQmedium

A security team is implementing SSL Decryption. They want to ensure that traffic to health-related websites is not decrypted due to privacy concerns. Which method should they use to exclude this traffic?

A.Use a source IP address exclusion list in the decryption policy.
B.Disable decryption for all sites that use certificate pinning.
C.Add the domain names to a custom URL category and create a no-decryption rule matching that category.
D.Configure a decryption profile to exclude traffic based on App-ID.
AnswerC

Adding health-related domains to a custom URL category lets a no-decryption rule match them by category rather than by individual address, satisfying the requirement to exclude that traffic from SSL Decryption. The firewall then bypasses decryption for those sessions while still applying other security policy, preserving privacy without disabling inspection globally.

Why this answer

Palo Alto Networks firewalls allow you to create custom URL categories containing specific domain names (e.g., health-related sites) and then reference that category in a decryption policy rule set to 'no-decrypt'. This ensures traffic matching those domains is excluded from SSL decryption, addressing privacy concerns without affecting other traffic.

Exam trap

The trap here is that candidates often confuse App-ID with URL filtering, thinking App-ID can selectively exclude traffic based on domain names, but App-ID operates at the application layer and cannot parse individual URLs within encrypted sessions without decryption.

How to eliminate wrong answers

Option A is wrong because source IP address exclusion lists in decryption policy only exclude traffic based on IP addresses, not domain names; health-related websites often use CDNs or load balancers with dynamic IPs, making IP-based exclusion impractical and incomplete. Option B is wrong because disabling decryption for all sites that use certificate pinning is a broad, security-weakening approach that would exclude many non-health sites and is not a precise method for excluding specific health-related domains. Option D is wrong because App-ID identifies applications (e.g., web-browsing, SSL) but cannot distinguish between specific domain names within an encrypted session; it cannot selectively exclude traffic to health-related websites based on URL or domain.

40
MCQmedium

The security policy rule shown in the exhibit has log-start and log-end both set to 'no', but a log-forwarding profile is configured. Which statement best describes the logging behavior for sessions matching this rule?

A.Sessions are logged only if the session duration exceeds a threshold.
B.Sessions are logged to Panorama immediately when the session starts.
C.Sessions are not logged because logging is disabled.
D.Sessions are logged to Panorama only when the session ends.
AnswerC

Log forwarding only sends traffic, threat and URL logs generated by the session; it cannot create logs that the security policy rule itself does not produce. With log-start and log-end both disabled, no session logs are generated for forwarding.

Why this answer

When both log-start and log-end are set to 'no' in a security policy rule, session logging is disabled regardless of any log-forwarding profile attached. The log-forwarding profile only specifies where logs are sent if logging is enabled; it does not override the explicit logging disable. Therefore, no session logs are generated for this rule.

Exam trap

The trap here is that candidates assume a log-forwarding profile overrides the log-start/log-end settings, but in PAN-OS, the profile only forwards logs that are already enabled by those flags.

How to eliminate wrong answers

Option A is wrong because there is no threshold-based logging behavior in PAN-OS; logging is either enabled or disabled per rule. Option B is wrong because log-start being set to 'no' means no logs are generated at session start, and the log-forwarding profile cannot enable logging on its own. Option D is wrong because log-end being set to 'no' prevents end-of-session logging, and the log-forwarding profile does not activate logging when logging is disabled.

41
MCQhard

A network security engineer is investigating why a firewall's dataplane CPU is consistently at 95%. After reviewing the session table, they notice a large number of sessions in a 'discard' state. Which action should the engineer take first to resolve the high CPU utilization?

A.Reduce the TCP handshake timeout value.
B.Check the security policy for a rule that denies traffic without sending a response.
C.Increase the session timeout for TCP sessions.
D.Enable hardware offload for session setup.
AnswerB

Sessions in a discard state often result from a security policy rule with an action of 'deny' and no notification to the client, such as a 'drop' action. When the firewall silently drops packets, sessions may linger until they time out, consuming resources. Reviewing the security policy to identify such rules and adjusting them to send a reset or ICMP unreachable can clear sessions faster and reduce CPU load.

Why this answer

Sessions in a discard state are often caused by a security policy rule that silently drops traffic without sending a response. This can lead to a large number of sessions lingering in the session table, consuming dataplane CPU. Reviewing and adjusting the security policy to send resets or ICMP unreachable messages can help clear these sessions more quickly and reduce CPU utilization.

Exam trap

The trap here is assuming that session timeouts or hardware offload are the primary causes of high CPU due to discard sessions.

42
MCQeasy

An administrator wants to view real-time CPU and memory usage on the firewall. Which CLI command should be used?

A.show system info
B.show routing route
C.show log system
D.show system resources
AnswerD

show system resources displays real-time CPU utilisation, memory usage and load averages for the firewall's dataplane and management plane. It satisfies the administrator's requirement to view live CPU and memory consumption directly from the CLI.

Why this answer

The 'show system resources' command displays real-time CPU and memory utilization on a Palo Alto Networks firewall, including load averages, memory usage, and process-level details. This is the correct command for monitoring live resource consumption, as opposed to static system information or logs.

Exam trap

The trap here is that candidates confuse 'show system info' (static system details) with 'show system resources' (dynamic resource usage), as both commands start with 'show system' and seem related to system health.

How to eliminate wrong answers

Option A is wrong because 'show system info' displays static system information such as model, serial number, software version, and uptime, not real-time CPU or memory usage. Option B is wrong because 'show routing route' displays the routing table entries, which is unrelated to system resource monitoring. Option C is wrong because 'show log system' displays system event logs (e.g., configuration changes, alarms), not real-time CPU or memory metrics.

43
MCQhard

Refer to the exhibit. Based on the log entry, what action was taken on this traffic?

A.The traffic was allowed with a reset.
B.The action could not be determined.
C.The traffic was dropped.
D.The traffic was allowed and logged.
AnswerC

The log records a drop action, meaning the firewall's security policy denied the session and no packet was forwarded to its destination. This satisfies the stem's requirement to identify the action taken on the exhibited traffic.

Why this answer

The log entry shows the action field as 'drop', which indicates the firewall denied the traffic. In Palo Alto Networks firewalls, a 'drop' action means the packet was silently discarded without sending a TCP reset or ICMP unreachable message. Therefore, option C is correct.

Exam trap

Palo Alto Networks often tests the distinction between 'drop' and 'reset' actions, where candidates may mistakenly assume a dropped packet generates a TCP reset, but in Palo Alto firewalls, 'drop' is silent and 'reset' explicitly sends RST packets.

How to eliminate wrong answers

Option A is wrong because 'reset' would appear in the action field as 'reset-both', 'reset-client', or 'reset-server', not 'drop'. Option B is wrong because the action is explicitly logged as 'drop', so it can be determined. Option D is wrong because 'allow' would appear as 'allow' in the action field, and the traffic was dropped, not allowed.

44
MCQeasy

A security administrator needs to configure the firewall to send an email alert whenever a critical threat is detected. The administrator wants to ensure that the email includes the threat details and is sent immediately. Which configuration step is required to achieve this?

A.Enable SNMP traps on the firewall and configure the management server to receive them.
B.Configure a Syslog server profile and assign it to the security policy to receive threat logs.
C.Configure an Email profile in Device > Server Profiles > Email and assign it to the security policy that detects the threat.
D.Create a Log Forwarding profile that includes an email server profile and attach it to the security policy that detects the threat.
AnswerD

A Log Forwarding profile specifies where to send logs, including email. By attaching it to the security policy, the firewall will forward threat logs via email as soon as they are generated. This ensures immediate notification with threat details included in the email body.

Why this answer

To send email alerts for critical threats, the administrator must configure a Log Forwarding profile that includes an Email server profile and apply it to the security policy. This ensures that when a threat is detected, the corresponding threat log is forwarded via email immediately, including all relevant details.

Exam trap

The trap here is confusing the Email server profile with the Log Forwarding profile; the Email server profile alone does not trigger alerts without being referenced in a Log Forwarding profile attached to a policy.

45
MCQhard

A security team needs to capture traffic for forensic analysis of a specific application that uses non-standard ports. The administrator wants to capture packets on the firewall for that application only, without affecting performance. Which method should be used?

A.Set up a port mirror on the upstream switch
B.Create an application override policy
C.Configure a PCAP filter in the firewall's packet capture feature
D.Use tcpdump on the management interface
AnswerC

A PCAP filter narrows capture to traffic matching the application's specific ports and addresses, so only relevant packets are recorded. This satisfies the requirement to target the non-standard-port application without the performance overhead of capturing all traffic.

Why this answer

The firewall's built-in packet capture feature with a PCAP filter allows the administrator to capture only traffic matching specific criteria (e.g., application, source/destination IP, port) directly on the data plane, without impacting overall performance. This is the correct method because it isolates the target application's traffic for forensic analysis without requiring external devices or altering traffic flow.

Exam trap

The trap here is that candidates confuse a management-plane tool (tcpdump on the management interface) with a data-plane capture, or they assume port mirroring is the only way to capture traffic, overlooking the firewall's native, performance-friendly PCAP filter feature.

How to eliminate wrong answers

Option A is wrong because port mirroring on an upstream switch copies all traffic from the monitored port, not just the specific application, and it introduces additional load on the switch and firewall, potentially affecting performance. Option B is wrong because an application override policy changes how the firewall identifies and handles the application (e.g., by specifying a custom port), but it does not capture or log packet-level data for forensic analysis. Option D is wrong because tcpdump on the management interface only captures traffic destined to or originating from the management plane, not the data-plane traffic flowing through the firewall's forwarding path.

46
MCQeasy

A network administrator is reviewing the firewall's logs and notices that many sessions are being denied by the security policy. The administrator wants to quickly identify the top source IP addresses that are being denied. Which feature in the PAN-OS web interface should the administrator use to accomplish this?

A.The Application Command Center (ACC) with a filter for denied traffic.
B.The Traffic log with a filter for denied sessions and then sorting by source IP.
C.The Threat log with a filter for denied traffic.
D.The Session Browser with a filter for denied sessions.
AnswerB

The Traffic log displays all session details. By filtering for denied sessions (e.g., action eq deny) and then sorting or using the log viewer's aggregation feature to group by source IP, the administrator can quickly see the top source IP addresses. This is the most direct and efficient method to identify top denied sources from the log data.

Why this answer

The Traffic log records all sessions, including those denied by security policy. By applying a filter for denied actions and then using the log viewer's aggregation or sorting capabilities, the administrator can quickly identify the top source IP addresses. This is a standard operational task in PAN-OS.

Other logs or tools do not provide the same direct access to denied session data.

Exam trap

The trap here is confusing the Threat log with the Traffic log; denied sessions by policy are not threats and are only in the Traffic log.

47
Drag & Dropmedium

Arrange the steps to configure a new administrator account with role-based access.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To configure a new administrator with role-based access on a Palo Alto firewall, you must first create the administrator account by navigating to Device > Administrators and clicking Add. Then enter the username and password. Next, assign a role (e.g., Superuser, Read‑Only, or a custom role) to define the access level.

Finally, commit the changes to apply the configuration. This sequence ensures the account is fully defined before committing.

48
MCQhard

A security team uses Panorama to push policy to 40 managed firewalls. An administrator commits a policy change from Panorama, and the commit succeeds on Panorama but fails on 12 firewalls with a validation error. The administrator wants to identify which firewalls failed and the specific error each reported without opening each device individually. Which Panorama feature should the administrator use?

A.The Config Audit under the Panorama tab, which compares the candidate configuration to the running configuration on each device.
B.The Log Collector group configuration, which aggregates commit-related system logs from all managed firewalls into one searchable view.
C.The Managed Devices summary under the Panorama tab, which shows the connection status and software version of each firewall.
D.The Task Manager under the Panorama tab, which lists commit job results and per-device error details for the pushed changes.
AnswerD

Panorama's Task Manager records each commit job, its scope, and the outcome for every managed device. When a pushed commit fails validation on individual firewalls, the job details list the affected devices and the specific error returned by each, allowing centralized troubleshooting without logging into every firewall individually. This is the intended workflow for this scenario.

Why this answer

Panorama pushes configuration to managed devices as commit jobs, and the Task Manager retains the result of each job, including which devices succeeded and which failed along with the error each returned. Reviewing the job detail centrally avoids logging into each firewall. Config Audit, Managed Devices status, and Log Collector aggregation serve different purposes and do not present per-device commit validation failures.

Exam trap

The trap here is assuming that a successful commit on Panorama means the policy applied everywhere, when per-device validation can still fail and is only visible in the commit job results.

49
MCQeasy

A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?

A.Network > Virtual Routers
B.Policy Optimizer > Test Policy Match
C.Monitor > Logs > Traffic
D.Device > Setup > Management
AnswerB

Policy Optimizer's Test Policy Match simulates a flow against the current ruleset, returning the exact security policy that would apply for specified source, destination, application and port. This directly satisfies the stem's requirement to identify which policy matches 10.0.1.0/24 traffic, exposing any missing or shadowed rule causing the outage.

Why this answer

The 'Test Policy Match' tool under Policy Optimizer allows an administrator to simulate a specific traffic flow (source/destination IP, port, protocol) and see which security policy rule it matches. This directly addresses the need to verify whether a missing or misconfigured policy is blocking internet access for the 10.0.1.0/24 subnet.

Exam trap

The trap here is that candidates often confuse the 'Test Policy Match' tool with traffic logs (Option C), thinking logs can predict future policy matches, but logs only show past events and cannot simulate a flow that hasn't occurred yet.

How to eliminate wrong answers

Option A is wrong because Virtual Routers manage routing tables and next-hop decisions, not security policy matching; it cannot test which security rule applies to a traffic flow. Option C is wrong because Monitor > Logs > Traffic shows historical logs of already-processed traffic, not a proactive test of policy matching for a hypothetical flow. Option D is wrong because Device > Setup > Management configures administrative settings (e.g., management interfaces, authentication) and has no capability to simulate or test security policy matching.

50
MCQhard

Two firewalls in an active/passive HA pair are not synchronizing. The administrator checks 'show high-availability state' and sees 'active' on both firewalls. What is the most likely cause?

A.The HA3 control link is misconfigured or down.
B.Session owner is set to 'primary' on both firewalls.
C.Preemptive mode is enabled on both firewalls.
D.Both firewalls have different PAN-OS versions.
AnswerA

Without heartbeat, each firewall assumes the other is down and becomes active.

Why this answer

When both firewalls show 'active' in the HA state, it indicates a split-brain scenario where each firewall believes it is the active unit. The HA3 control link is responsible for heartbeat and state synchronization; if it is misconfigured or down, the firewalls cannot detect each other's presence, causing both to assume active status. This is the most common cause of dual-active HA failures.

Exam trap

The trap here is that candidates often assume both firewalls showing 'active' is caused by a configuration mismatch like PAN-OS versions or preemptive settings, but the core issue is the loss of the HA3 control link, which prevents heartbeat detection and triggers a split-brain condition.

How to eliminate wrong answers

Option B is wrong because 'session owner' is a session distribution setting for active/active HA, not active/passive, and setting it to 'primary' on both does not cause both to show active; it affects session ownership, not HA state. Option C is wrong because preemptive mode controls whether a previously active firewall reclaims active status after a failure recovery; it does not cause both to become active simultaneously. Option D is wrong because different PAN-OS versions prevent HA formation entirely (the pair will not synchronize or form a HA group), but the state would show 'non-functional' or 'not synchronized', not 'active' on both.

51
MCQeasy

A small business uses a single PA-220 firewall with PAN-OS 10.2. The administrator notices that the firewall is no longer receiving automatic threat updates. The License page shows the Threat Prevention license is active with 200 days remaining. The administrator can manually download updates from the Palo Alto Networks update server. What is the most likely cause?

A.The firewall is behind a proxy that blocks the update service.
B.The update schedule is disabled.
C.The firewall's system clock is incorrect.
D.The DNS settings are misconfigured.
AnswerB

Dynamic updates require a configured schedule to poll the update server automatically. With the licence active and manual downloads working, connectivity and entitlement are fine, so a disabled update schedule is the only remaining cause of missed automatic threat updates.

Why this answer

The most likely cause is that the update schedule is disabled. Even though the Threat Prevention license is active and manual downloads work, the firewall will not automatically check for or download updates if the scheduled update feature is turned off. In PAN-OS 10.2, the administrator must configure a recurring schedule under Device > Dynamic Updates for automatic updates to occur; otherwise, only manual downloads are possible.

Exam trap

The trap here is that candidates assume a valid license guarantees automatic updates, overlooking that the update schedule is a separate configuration setting that must be explicitly enabled.

How to eliminate wrong answers

Option A is wrong because if a proxy were blocking the update service, manual downloads would also fail, as they use the same outbound HTTPS connection to the Palo Alto Networks update server. Option C is wrong because an incorrect system clock would cause SSL certificate validation failures and prevent both automatic and manual updates, but the administrator can manually download updates successfully. Option D is wrong because misconfigured DNS would prevent resolution of the update server's FQDN, breaking both automatic and manual updates, yet manual downloads work.

52
MCQeasy

An administrator wants to be notified whenever any administrator account is locked out after repeated failed login attempts. The notification must be sent by email to the security team. Which configuration accomplishes this?

A.Configure an Email server profile and a Log Forwarding profile that matches auth log entries, then apply it to the management interface.
B.Configure an Email server profile and enable email notifications for the authentication log under Device > Log Settings.
C.Create a custom report that filters authentication log entries and schedule it to be emailed every five minutes.
D.Enable SNMP traps on the management interface and configure the SNMP manager to interpret authentication failure traps.
AnswerB

The management-plane log settings under Device > Log Settings allow an administrator to specify an Email server profile and choose which system or authentication events generate email alerts. Enabling email notification for authentication log events causes a message to be sent when an administrator account is locked out, which is exactly the required behavior.

Why this answer

Email notification for management-plane events is configured under Device > Log Settings, where an Email server profile is selected and specific log types such as the authentication log are flagged for email alerts. This delivers an immediate message to the security team when an administrator account is locked out, meeting the notification requirement.

Exam trap

The trap here is confusing Log Forwarding profiles, which apply to Security policy session logs, with the management-plane log settings that control event-driven email alerts.

53
MCQmedium

An administrator reviews a traffic log entry: 'Source: 10.0.0.10, Destination: 8.8.8.8, Application: web-browsing, Action: allow, Bytes Sent: 500, Bytes Received: 1200'. What does this log entry indicate about the traffic?

A.The traffic was blocked by a security policy.
B.The traffic was only one-way; only received bytes were logged.
C.The traffic was allowed and identified as web-browsing.
D.The application was incorrectly identified.
AnswerC

The log records Action: allow, confirming the firewall permitted the session, and Application: web-browsing, showing App-ID positively identified the traffic as HTTP/HTTPS browsing rather than merely inferring it from port 80 or 443. Bytes Sent and Received simply quantify client-to-server and server-to-client payload volumes for that allowed session.

Why this answer

The log entry shows 'Action: allow', which explicitly indicates the firewall permitted the traffic. The 'Application: web-browsing' field confirms that the Palo Alto Networks firewall correctly identified the traffic as HTTP/HTTPS (web-browsing) using App-ID, not just by port. The presence of both 'Bytes Sent' and 'Bytes Received' with non-zero values confirms bidirectional communication, so the traffic was allowed and properly classified.

Exam trap

The trap here is that candidates may assume traffic to 8.8.8.8 is always DNS and thus think the application was misidentified, but the log explicitly shows 'web-browsing' which is valid for HTTP/HTTPS traffic to any IP, and the 'allow' action confirms the firewall permitted it.

How to eliminate wrong answers

Option A is wrong because the 'Action: allow' field directly contradicts blocking; a blocked session would show 'Action: deny' or 'drop'. Option B is wrong because both 'Bytes Sent: 500' and 'Bytes Received: 1200' are non-zero, proving bidirectional traffic, not one-way. Option D is wrong because the application 'web-browsing' is a standard App-ID for HTTP/HTTPS traffic to a public DNS server (8.8.8.8), and there is no evidence of misidentification; App-ID uses deep packet inspection to verify the application regardless of port.

54
MCQmedium

An administrator is analyzing traffic logs on a Palo Alto Networks firewall and notices that a particular session shows an application of 'incomplete' and no bytes received. The session was allowed by the security policy. What is the most likely cause?

A.The application is using a non-standard port and was not detected.
B.The security policy is blocking the application, causing incomplete identification.
C.The application was identified but the session timed out before data was exchanged.
D.The firewall did not receive enough packets to identify the application.
AnswerD

The 'incomplete' application status means the firewall could not identify the application because it did not see enough packets or data. This often happens when the session is terminated early or if the traffic is asymmetric. Without sufficient data, the firewall cannot match the application signature, resulting in 'incomplete'.

Why this answer

An 'incomplete' application status in traffic logs indicates that the firewall could not identify the application because it did not receive enough packets or data to match a signature. This can occur with short-lived sessions, asymmetric routing, or when the session is terminated before the application is fully identified. The security policy allowed the session, but application identification failed.

Exam trap

The trap here is assuming that an allowed session should always have a fully identified application, but application identification requires sufficient data and can be incomplete.

55
Drag & Dropmedium

Arrange the steps to configure a new zone on a Palo Alto Networks firewall in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a new zone on a Palo Alto Networks firewall is: first, navigate to Network > Zones; second, click Add to create a new zone object; third, enter the zone name and select the zone type (e.g., Layer3); finally, click OK to save the configuration. This order ensures that the zone is properly created and configured before committing changes.

56
MCQeasy

An administrator wants to receive SNMP traps from the firewall for critical events such as failed login attempts and high CPU usage. Which configuration step is required?

A.Enable SNMP monitoring on the interface.
B.Set up a log forwarding profile with SNMP action.
C.Create an SNMP read-only community string.
D.Configure an SNMP trap destination under Device > Setup > SNMP Trap.
AnswerD

SNMP traps are outbound notifications, so the firewall needs a defined trap destination to know where to send them. Configuring this under Device > Setup > SNMP Trap enables critical events such as failed logins and high CPU usage to reach the monitoring server.

Why this answer

To receive SNMP traps from a Palo Alto Networks firewall, you must configure the trap destination under Device > Setup > SNMP Trap. This step defines where the firewall sends SNMP notifications (traps) for events like failed login attempts and high CPU usage. Without a configured trap destination, the firewall will not transmit any SNMP traps, even if other SNMP settings are enabled.

Exam trap

The trap here is that candidates often confuse SNMP polling (which requires read-only community strings and interface monitoring) with SNMP trap generation (which requires a separate trap destination configuration), leading them to select options A or C instead of D.

How to eliminate wrong answers

Option A is wrong because enabling SNMP monitoring on an interface allows the firewall to be polled via SNMP (e.g., for MIB data), but it does not configure the firewall to send unsolicited traps. Option B is wrong because log forwarding profiles are used to forward logs to external services (e.g., syslog, email), not to send SNMP traps; SNMP trap configuration is separate and does not use log forwarding profiles. Option C is wrong because creating an SNMP read-only community string is required for SNMP polling (read access to MIB objects), but it is not necessary for sending traps; traps use a separate community string (often the same, but the trap destination configuration is the critical step).

57
Multi-Selecthard

A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)

Select 2 answers
A.Enable Multi-Factor Authentication for all admins.
B.Configure role-based access on Panorama.
C.Create an admin role with commit scope limited to specific device groups.
D.Use template stacks to restrict commit permissions.
E.Set the firewall to require approval for commits.
AnswersB, C

Role-based access control on Panorama assigns administrative roles defining which device groups, templates and actions each administrator may use. This satisfies the requirement that only specific administrators can commit changes to devices, because commit rights derive from the assigned role's permissions.

Why this answer

Option B is correct because Panorama's role-based access control (RBAC) is the mechanism that defines what each administrator account is allowed to do, including whether they can push commits to managed devices; without configuring roles on Panorama, no granular restriction of commit rights is possible. Option C is correct because an admin role can be scoped with a commit scope limited to specific device groups (and templates), so administrators assigned that role can only commit changes to those device groups rather than to all managed firewalls. Option A is not required because MFA strengthens authentication but does not restrict which devices an admin can commit to.

Option D is incorrect because template stacks are configuration containers for pushing settings to firewalls, not a permission-control feature. Option E is incorrect because firewalls in a Panorama-managed environment do not have a per-device 'require approval for commits' setting that governs administrator commit permissions.

Exam trap

The trap is confusing authentication (MFA) with authorization (RBAC); MFA does not restrict what an admin can do after login, only how they log in.

58
MCQeasy

An administrator wants to generate a report that shows the top applications by bandwidth usage over the last week. Which report type should be used to accomplish this?

A.URL Filtering Report
B.Application Report
C.Traffic Report
D.Threat Report
AnswerB

The Application Report aggregates traffic by application, exposing bandwidth consumption per application over a chosen period. Selecting a one-week timeframe directly satisfies the requirement to rank top applications by bandwidth usage, which other report types do not provide.

Why this answer

The Application Report is designed to provide visibility into application usage, including bandwidth consumption, top applications, and application-level trends over a specified time period. This report type leverages the App-ID engine to classify traffic by application, regardless of port or protocol, making it the correct choice for identifying top applications by bandwidth usage.

Exam trap

The trap here is that candidates often confuse the Traffic Report (which shows raw byte counts) with application-level reporting, failing to realize that only the Application Report uses App-ID to break down bandwidth by application identity rather than by IP or port.

How to eliminate wrong answers

Option A is wrong because the URL Filtering Report focuses on web browsing activity based on URL categories and does not provide application-level bandwidth breakdowns. Option C is wrong because the Traffic Report shows raw traffic volume (bytes, packets, sessions) by source/destination or zone, but it does not natively aggregate or rank by application identity. Option D is wrong because the Threat Report is dedicated to security threats such as intrusions, malware, and vulnerabilities, not application bandwidth usage.

59
Multi-Selecteasy

A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Create a syslog server profile under Device > Server Profiles > Syslog.
B.Create an SNMP trap profile under Device > Server Profiles > SNMP Trap.
C.Directly apply the syslog server profile to each Security policy rule.
D.Enable log forwarding under the firewall's Device > Setup > Logging and Reporting settings.
E.Create a Log Forwarding profile that references the syslog server profile and apply it to Security policy rules.
AnswersA, E

A syslog server profile is required to define the destination syslog server.

Why this answer

A syslog server profile must first be created under Device > Server Profiles > Syslog to define the external syslog server's IP address, port (default 514), and transport protocol (UDP/TCP). This profile is a prerequisite for any log forwarding to an external syslog server.

Exam trap

The trap here is that candidates mistakenly think a syslog server profile can be applied directly to a Security policy rule, but the PCNSE exam requires understanding that a Log Forwarding profile is the mandatory intermediary object.

Ready to test yourself?

Try a timed practice session using only Manage, Monitor and Operate questions.