Courseiva

PCNSE · domain

scenario questions

Practise Palo Alto Networks Certified Network Security Engineer PCNSE scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

319 questions100 easy123 medium96 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (319)

Click any question to see the full explanation, or start a practice session above.

1

A network security engineer is deploying a Palo Alto Networks firewall in a high-availability (HA) active/passive configuration. The engineer wants to ensure that the passive firewall takes over seamlessly if the active firewall fails. Which of the following is a requirement for HA active/passive configuration?

Hard
2

Which THREE of the following are key differences between the Palo Alto Networks Next-Generation Firewall and Cloud-Delivered Security Services (CDSS)?

Hard
3

A security engineer is troubleshooting why a web application is not being identified correctly. The firewall shows the session as 'ssl' instead of the specific application. The engineer has verified that the traffic is using TLS 1.3. What is the most likely reason for the misidentification?

Medium
4

A help desk ticket reports that a user cannot access the firewall's web management interface (HTTPS) from the management network. The management interface is on a dedicated MGMT network. Which setting must be enabled on the firewall to allow this access?

Easy
5

A security operations center (SOC) uses Panorama to monitor all firewalls. They notice that some log entries show a severity of 'critical' but the alerting system does not fire. The log forwarding profile on Panorama is configured to send syslog alerts for severity 'critical'. The syslog server receives other logs from Panorama but not these critical logs. The administrator checks the Panorama configuration and finds that the log forwarding profile is applied to the correct log types. What is the most likely issue?

Hard
6

An administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions that are active on the firewall. The administrator wants to see details such as source and destination IP addresses, application, and security policy applied. Which CLI command should the administrator use?

Easy
7

A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?

Medium
8

A company uses Panorama to manage multiple firewalls. An administrator pushes a template that includes a new Security Profiles group, but the firewalls do not receive the profile group. What is the most likely cause?

Hard
9

A security engineer is designing a Palo Alto Networks firewall deployment for a multi-tenant environment. The engineer needs to ensure that each tenant's traffic is isolated and that security policies can be applied per tenant. The engineer plans to use Virtual Systems (vsys) to achieve this. Which two statements about Virtual Systems (vsys) are true? (Choose two.)

Hard
10

A security administrator notices that traffic to a specific website is being denied. The traffic log shows that the application is 'ssl' and the action is 'deny' with the rule being 'Allow-SSL'. What is the most likely cause?

Easy
11

A network engineer notices that traffic from an internal user to a web application is being incorrectly identified as 'web-browsing' instead of the custom application 'my-app'. The engineer has already created a custom application 'my-app' with the correct signature. What is the most likely reason for the misidentification?

Easy
12

An organization uses User-ID with agent-based mapping on a Palo Alto Networks firewall. Users authenticate to a domain but some user-to-IP mappings are not showing up in the firewall's user cache. The firewall can reach the domain controllers. What is the most likely cause?

Hard
13

A company is experiencing intermittent connectivity issues between two branch offices connected via an IPSec tunnel. Users report that they can access resources for a few minutes, then lose connectivity, and after a short time it comes back. Which troubleshooting step should be taken first?

Medium
14

A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?

Medium
15

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?

Easy
16

An organization is implementing SSL Forward Proxy decryption to inspect outbound HTTPS traffic. They want to exclude traffic to specific internal applications that cannot handle decryption due to certificate pinning. The firewall is configured with a decryption policy that decrypts all traffic from the internal network to the internet. To exclude the pinned applications, which approach is best practice?

Hard
17

Refer to the exhibit. The firewall's disk usage is at 85% overall, and the /opt/panlogs partition is at 92%. The administrator wants to free up space without losing important log data. Which action should be taken first?

Easy
18

A security engineer is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for inspection. The firewall is deployed in a forward proxy mode. The engineer wants to ensure that the firewall can decrypt traffic without generating certificate errors on client browsers. Which configuration is required to achieve this?

Medium
19

An organization uses captive portal for guest Wi-Fi access with LDAP authentication against an on-premise Active Directory. Users complain that after successfully logging in, they are repeatedly prompted for credentials every few minutes. The captive portal page loads correctly and credentials are accepted initially. The authentication profile has a session timeout of 60 minutes. What is the most likely cause of the repeated prompts?

Medium
20

Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)

Hard
21

Refer to the exhibit. An administrator notices that HTTPS traffic to a specific website is being denied. What is the most likely cause?

Hard
22

A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?

Hard
23

A Palo Alto Networks firewall administrator is troubleshooting why a session was terminated with the flag 'tcp-rst-from-client'. The administrator wants to identify possible causes for this termination flag. Which two factors can cause a session to be terminated with 'tcp-rst-from-client'? (Choose two.)

Hard
24

During an audit, it is discovered that some traffic from a legacy application is being incorrectly identified as 'ssl' because the application uses a custom encryption scheme over TCP port 443. The engineer has created a custom application signature that matches the legacy application's handshake. What additional configuration is needed to ensure the legacy application is correctly identified?

Medium
25

When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?

Easy
26

Refer to the exhibit. A user at 10.1.1.10 is trying to connect to a web server at 203.0.113.5 on port 443. The session shows 'State: DROP' with reason 'policy-deny'. However, the administrator has a security policy rule that allows SSL traffic from the source zone to the destination zone. What is the most likely cause of the drop?

Medium
27

A network security engineer is deploying a PA-5220 firewall in a data center. The firewall must inspect traffic between two internal segments (trust and dmz) and also provide security for outbound internet access. The engineer wants to ensure that when a packet arrives, the firewall properly identifies the application and enforces security policies. Which component is responsible for identifying the application regardless of port, protocol, or encryption?

Medium
28

A security engineer is troubleshooting a traffic drop issue on a Palo Alto Networks firewall. The traffic is allowed by the security policy, but the session is being terminated. Which two features could cause this behavior? (Choose two.)

Medium
29

A security engineer is configuring a security policy to allow only the specific business application 'salesforce' while blocking all other applications that use HTTPS. The firewall is not performing SSL decryption. What will be the result of the security policy?

Medium
30

A network engineer is configuring a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party VPN peer. The engineer wants to ensure that the firewall can establish the tunnel even if the peer initiates the connection. Which configuration is required on the Palo Alto Networks firewall?

Hard
31

A security engineer wants to identify applications in SSL/TLS encrypted traffic without decrypting the payload. Which method can be used?

Medium
32

Which THREE factors should be considered when designing an authentication policy for a multi-zone environment with varied security requirements? (Choose THREE.)

Hard
33

An engineer is troubleshooting an inter-zone rule that should allow traffic from zone 'Trust' to zone 'Untrust'. The rule has a source address of 10.0.0.0/8 and destination address of any. The traffic is being denied. The engineer checks the log and sees the rule is not matched. What is the most likely reason?

Hard
34

Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?

Easy
35

Refer to the exhibit. What does the uptime indicate?

Easy
36

A SOC analyst reports that a critical security policy rule denying traffic from the 'Untrust' zone to the 'DMZ' zone is not generating any traffic logs, even though the analyst sees a high volume of denied traffic in other tools. The administrator confirms that the rule is correctly configured to deny and that logging is enabled at the rule level. What is the most likely reason for the missing logs?

Easy
37

Which TWO configurations are required for User-ID to work using the Windows User-ID Agent (WUA) in a distributed environment?

Hard
38

A company wants to authenticate users who are accessing internal applications from the internet through a firewall. The users should be prompted once per session. Which authentication solution best meets this requirement?

Easy
39

A GlobalProtect gateway is configured as shown. Remote users report that they can connect to the gateway but cannot authenticate. The users are using the GlobalProtect client with certificate authentication. What is the most likely cause?

Hard
40

A network administrator is configuring a new Palo Alto Networks firewall in a high-availability active/passive setup. The firewall will be placed in Layer 3 mode. Which THREE steps are required to ensure proper operation? (Choose three.)

Hard
41

An organization has configured an active/passive high availability pair of Palo Alto Networks firewalls. During a maintenance window, the active firewall was rebooted. After the reboot, the passive firewall became active, but the session table on the original active firewall is incomplete. The administrator notices that session synchronization is not working properly. Which two configuration checks should the technician perform to resolve this issue?

Medium
42

A security administrator is reviewing traffic logs and notices that a known application is being identified as 'web-browsing' instead of its correct App-ID. The application uses HTTP and is not encrypted. The administrator confirms that the application is not a custom application. What is the most likely cause of this misidentification?

Easy
43

A medium-sized enterprise recently deployed a PA-5250 firewall in a data center as the primary internet gateway. The network team configured the security policies to allow all outbound web traffic (HTTP/HTTPS) from the internal trust zone to the untrust zone, with URL filtering and threat prevention enabled. After the deployment, users complain that some legitimate websites, such as banking and healthcare portals, are being blocked. The team checks the URL filtering logs and sees that these sites are categorized as 'web-hosting' or 'dynamic-dns', which are in the block list. The company's compliance requires that all web traffic be inspected. What should the network engineer do to resolve the issue without reducing security?

Easy
44

Which TWO statements about active/active HA mode are true compared to active/passive mode? (Choose two.)

Easy
45

A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?

Easy
46

A security administrator is investigating why a session was terminated with the flag 'tcp-rst-from-server' in the traffic logs. The administrator has confirmed that the server is reachable and responding to pings. Which of the following is the most likely cause for this session termination?

Hard
47

A medium-sized enterprise has two Palo Alto Networks PA-5250 firewalls configured in an active/passive HA pair with session synchronization and configuration synchronization enabled. The HA1 link is a direct copper cable, and the HA2 link is also a direct copper cable. The firewalls are connected to two upstream routers (R1 and R2) and two downstream switches (S1 and S2). The network uses OSPF for dynamic routing. The active firewall (FW-A) is connected to R1 and S1, while the passive firewall (FW-P) is connected to R2 and S2. The OSPF cost is set symmetrically on both sides. During a maintenance window, the network team shuts down the HA1 and HA2 links on both firewalls to test failover behavior. After the links are brought back up, the firewalls are in a state of 'non-functional' and 'suspended'. The team suspects the HA configuration is broken. What is the most likely cause and the best course of action to restore HA?

Hard
48

An administrator wants to ensure that all traffic from the 'Trust' zone to the 'Untrust' zone is inspected by WildFire. Which configuration is required?

Hard
49

A firewall's traffic logs are being forwarded to a Panorama appliance for centralized retention. An administrator notices that logs from one specific firewall are missing from Panorama even though the same firewall's logs appear locally. The firewall is managed by Panorama and shows as connected. Which cause is most likely?

Medium
50

An administrator is configuring GlobalProtect with certificate authentication. The portal is configured to use a certificate profile that validates client certificates against a trusted CA. Users report that authentication fails with the error 'Certificate validation failed'. The administrator has verified that the client certificates are issued by the correct CA and are not expired. What is the most likely cause of the failure?

Hard
51

A network security engineer is validating a newly deployed firewall. The security policy is configured to allow web traffic from the Trust zone to the Untrust zone. After a user reports that a website is unreachable, the engineer runs the CLI command 'show session all filter source 10.1.1.50' and sees no active sessions. Which CLI command should the engineer use next to determine why the session was not established?

Medium
52

An administrator needs to create a custom application for a proprietary database protocol that uses TCP port 7890. What is the first step in defining this application in App-ID?

Easy
53

Which of the following is required for SAML-based single sign-on to work with a Palo Alto Networks firewall acting as the service provider?

Medium
54

During a network incident, an engineer notices that after an HA failover, some sessions are not active on the new active firewall. The 'show session all' command shows the sessions with state 'half-closed'. What is the most likely cause?

Hard
55

A network engineer is troubleshooting an HA pair where both firewalls show as 'active' in the HA state. What is this condition called?

Easy
56

A network engineer is troubleshooting why a Palo Alto Networks firewall is not generating any traffic logs for sessions that match a security policy rule set to allow. The engineer confirms that the rule is hit and traffic passes successfully. Which of the following is the most likely reason for the absence of logs?

Medium
57

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates from the active firewall. The HA2 link is up, and the HA1 link is healthy. The engineer checks the HA configuration and sees that the HA2 interface is configured with an IP address, and session synchronization is enabled. What is the most likely cause of the synchronization failure?

Hard
58

Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?

Hard
59

A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?

Easy
60

A network administrator needs to verify that the firewall is receiving dynamic updates for applications and threats. Which command should they use from the CLI to check the current update status and schedule?

Easy
61

A security administrator is configuring a new Palo Alto Networks firewall and needs to enable App-ID to identify applications traversing the network. The administrator wants to ensure that App-ID can correctly identify applications even when they use non-standard ports or encryption. Which feature must be enabled to allow App-ID to inspect encrypted traffic?

Easy
62

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates. The engineer runs 'show high-availability state' on both firewalls and sees that the HA2 link is down. Which action should the engineer take first to resolve the issue?

Medium
63

A network engineer is configuring HA on a pair of PA-5220 firewalls. The HA1 link is configured over a dedicated interface, and HA1 backup is configured over the management interface. The engineer wants to ensure that HA1 control traffic is encrypted and authenticated. Which action should be taken?

Hard
64

A network security engineer is designing a multi-vsys Palo Alto Networks firewall deployment to provide both advanced security and virtual routing separation for three different departments. Each department requires its own routing table and separate security policy enforcement. The engineer must decide which component is responsible for enforcing security policies and providing threat inspection across all virtual systems. Which component of the Palo Alto Networks Next-Generation Firewall performs this function?

Medium
65

A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?

Easy
66

A network administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions in real-time to identify which application is consuming the most bandwidth. Which command should the administrator use?

Easy
67

An administrator is reviewing the firewall's session table and notices many sessions in a 'discard' state. What is the most likely cause of this session state?

Medium
68

A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?

Easy
69

A company wants to forward logs from a firewall to a SIEM system with high reliability. Which log forwarding method ensures that logs are not lost if the SIEM is temporarily unreachable?

Medium
70

An administrator needs to generate a report showing all traffic denied by the firewall over the past week. Which type of report in the firewall web interface should be used?

Easy
71

A firewall administrator notices that traffic from a specific subnet is being unexpectedly dropped. The firewall log shows a 'flow_drop' reason of 'packet too long for interface MTU'. The interface MTU is set to 1500, and the packets are 1500 bytes. What is the most likely cause?

Hard
72

Arrange the steps to deploy a new Panorama template to a managed firewall.

Medium
73

A company wants to enforce multi-factor authentication (MFA) for all administrative access to the Palo Alto Networks firewall. They have a RADIUS server configured with MFA capability (e.g., RSA SecurID). The firewall is currently using local authentication for admin accounts. What must be configured to enforce MFA for admin access?

Easy
74

Refer to the exhibit. What is the primary cause of the 'non-functional' state?

Easy
75

Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.

Medium
76

A company needs to deploy a firewall in transparent inline mode to filter traffic between two switches without requiring any IP address changes on existing devices. Which interface type should be configured?

Easy
77

A firewall receives traffic with IP options enabled. How does the firewall handle this traffic by default?

Hard
78

A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?

Medium
79

Based on the exhibit, what is the impact of the current HA state on the network?

Medium
80

A company has a firewall with multiple virtual systems (vsys). The administrator wants to delegate management of one vsys to a junior administrator, allowing them to configure security policies but not access system settings or other vsys. Which administrative role should be assigned?

Medium
81

During an HA failover, the new active firewall's session table is empty, causing all existing connections to be dropped. Which configuration change would prevent this?

Medium
82

Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?

Medium
83

A company needs to authenticate remote users accessing internal web applications via GlobalProtect portal and wants to use SAML with Azure AD for MFA. Which component must be configured on the firewall?

Hard
84

An engineer is troubleshooting a security policy that is not matching traffic as expected. The traffic is from source IP 10.1.1.10 to destination 172.16.0.1 port 443. The policy has source zone 'Internal', destination zone 'DMZ', source address '10.1.1.0/24', destination address '172.16.0.0/24', application 'ssl'. The firewall shows the traffic hitting a different rule. What is the most likely cause?

Medium
85

Two firewalls in an active/passive HA configuration are not synchronizing sessions. The 'show high-availability state' command shows both peers as 'active' and 'passive' correctly, but session synchronization is not working. What is the most likely cause?

Hard
86

A firewall shows session logs with application 'incomplete' for many SSL connections. Which action should be taken to improve App-ID accuracy?

Easy
87

A network security administrator is investigating a suspicious session on a PA-3220 firewall. The administrator needs to determine the exact security policy rule that permitted the session to be established. Which action should the administrator take to accomplish this goal?

Medium
88

Which TWO are prerequisites for using Authentication Policy? (Choose two.)

Hard
89

A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?

Medium
90

During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?

Hard
91

A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?

Medium
92

A company has two Palo Alto Networks firewalls in an active/passive high availability pair. The firewalls are configured with a virtual IP (VIP) for the internal network. Recently, the passive firewall was upgraded to a new PAN-OS version. After the upgrade, the active firewall is still running the old version. The administrator wants to perform a failover to make the upgraded firewall active. However, when the administrator attempts to manually failover, the new passive firewall does not become active. The HA synchronization status shows 'synchronized' but the preemption is disabled. The administrator checks the HA configuration and finds that the peer's version is not compatible. What should the administrator do to successfully failover to the upgraded firewall?

Medium
93

A network engineer is troubleshooting high latency on the firewall. Which THREE commands from the CLI should be used to identify potential bottlenecks? (Choose three.)

Medium
94

A security administrator wants to block traffic from IP address 192.168.1.100 to the internet. The firewall has a security policy that allows all outbound traffic. Which action should be taken to most efficiently block this specific host?

Easy
95

A network engineer is troubleshooting why a Palo Alto Networks firewall is not decrypting SSH traffic even though an SSL Forward Proxy decryption policy is configured for the internal zone. The engineer confirms that the SSH traffic matches the decryption policy and that the forward trust and untrust certificates are installed and valid. What is the most likely reason the SSH traffic is not being decrypted?

Medium
96

A network administrator is setting up a new Palo Alto Networks firewall. The administrator needs to configure the firewall so that it can resolve domain names for its own management traffic, such as for updates and logging. Which type of interface should be configured with a default gateway to allow the firewall to reach external services?

Easy
97

A security administrator is configuring a Palo Alto Networks firewall to perform DNS sinkholing to detect and block malware callbacks. The firewall is deployed with a default route to the internet. The administrator wants to ensure that when an internal host attempts to resolve a known malicious domain, the firewall returns a sinkhole IP address (10.10.10.10) and logs the event. Which configuration is required to achieve this?

Hard
98

A network security engineer is troubleshooting a Palo Alto Networks firewall that is dropping traffic to a critical internal server. The engineer runs 'show session all filter destination 10.1.1.50' and sees sessions in the 'discard' state. The engineer wants to determine why these sessions are being discarded. Which action should the engineer take next?

Medium
99

Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?

Easy
100

A company wants to enforce multi-factor authentication (MFA) for employees accessing a specific internal application through the firewall. Which two configurations are required on the Palo Alto Networks firewall? (Choose two.)

Medium
101

An administrator adds a new security rule to allow outbound 'web-browsing' and 'ssl' traffic. After committing, users report that some HTTPS sites are still blocked. Traffic logs show that the traffic matches the new rule but is denied. What is the most likely cause?

Medium
102

A user complains that they cannot access internal resources via GlobalProtect. The firewall shows the user is connected with an IP address from the tunnel pool. Which log type should the administrator check first to determine if traffic is being allowed or denied?

Easy
103

A company has two Palo Alto Networks firewalls configured in an active/passive HA pair. Traffic fails over correctly, but after a failover, existing sessions from external users to internal servers are broken. The security team wants to prevent this disruption. Which feature must be enabled?

Medium
104

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Hard
105

When configuring High Availability on a Palo Alto Networks firewall, which of the following is a best practice for the HA1 control link?

Easy
106

An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?

Medium
107

A firewall is configured with multiple virtual systems (vsys). The administrator notices that one vsys is consuming excessive dataplane resources, affecting others. Which feature should be used to guarantee each vsys a minimum share of CPU and session capacity?

Hard
108

A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?

Easy
109

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

Hard
110

A security administrator is deploying a PA-5220 firewall with a single external zone and several internal zones. The requirement is to allow DNS queries to any external DNS server while ensuring that responses are permitted only when they match an existing session. Which security policy configuration meets this requirement?

Medium
111

A network administrator is troubleshooting an IPsec site-to-site VPN that fails to establish. IKE phase 1 completes successfully, but phase 2 fails with a 'no proposal chosen' message. Both sides have identical IKE and IPsec crypto profiles, and the pre-shared key is correct. What is the most likely cause of the failure?

Medium
112

A network administrator needs to monitor the firewall's interface status and receive alerts when an interface goes down. Which built-in feature should they configure?

Easy
113

An administrator manages a PA-5220 pair running PAN-OS 11.1. During a change window, the active firewall's management plane becomes unreachable and the device fails over to the passive peer. The administrator wants to review the events that occurred on the failed device before the failover. Which action should the administrator take to obtain this information?

Medium
114

An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?

Hard
115

An HA pair is configured with Active/Passive mode. The passive firewall fails to become active after the active firewall's management interface goes down. What is the most likely cause?

Easy
116

An organization has a pair of PA-5250 firewalls in active/passive HA. During a maintenance window, the active firewall is rebooted. After the reboot, the firewall that was passive becomes active and passes traffic. However, the other firewall remains in a non-functional state and shows 'unknown' as HA state. The administrator checks the HA configuration and finds both firewalls have the same HA settings. What is the most likely issue?

Easy
117

After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?

Hard
118

An engineer is deploying a new Palo Alto Networks firewall running PAN-OS 10.1 as a standalone device. The security team requires that the firewall forward syslog messages to an external server. After configuring the Syslog server profile and applying it to a Log Forwarding profile, the engineer notices that no logs are being received on the syslog server. The firewall's management interface can reach the syslog server on UDP port 514. Which action should the engineer take to resolve this issue?

Medium
119

An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?

Medium
120

A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?

Hard
121

A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?

Hard
122

An administrator has configured an authentication profile with LDAP and sets the authentication sequence to 'continue on failure'. A user enters an incorrect password first, then correct. Will the user be authenticated?

Easy
123

Two Palo Alto Networks firewalls are configured in an active/passive HA pair. During a scheduled maintenance, the network team reboots both firewalls simultaneously. After reboot, both firewalls appear as 'active' in the HA state. What is the most likely cause and the correct troubleshooting step?

Hard
124

A network security administrator is deploying a new PA-3220 firewall in a data center. The security team requires that all traffic traversing the firewall be inspected for threats, but they want to minimize latency for trusted internal traffic that is already known to be benign. The administrator decides to create a security policy rule that allows traffic from the 'Trust' zone to the 'DMZ' zone without any security profiles attached. Which statement accurately describes the behavior of this rule?

Easy
125

Order the steps to upgrade the PAN-OS software on a standalone firewall.

Medium
126

A network security engineer is configuring an authentication profile on a Palo Alto Networks firewall to allow administrators to log in using their Active Directory credentials. The engineer wants to ensure that only members of the 'NetOps' group can access the firewall. Which setting in the authentication profile should be configured to enforce this?

Medium
127

A company implements SSL Forward Proxy decryption. Users complain that accessing certain websites, such as video streaming and software updates, is slow. Which action should the administrator take to improve performance?

Medium
128

An organization has two different applications (AppA and AppB) that both use TCP port 8080. The firewall must apply different security policies to each application. What is the recommended approach?

Hard
129

An administrator wants to enforce authentication for SSL decrypted traffic so that only authenticated users can access decrypted content. Which firewall feature should be configured?

Easy
130

A security administrator is troubleshooting App-ID on a firewall that is deployed in a Layer 2 transparent mode. The administrator notices that some applications are not being identified correctly, even though the traffic is not encrypted. What is the most likely reason for this issue?

Hard
131

An administrator is troubleshooting high CPU usage on a PA-5250 firewall. The CPU usage spikes every 5 minutes. Which CLI command should be used to identify the process causing the spike?

Medium
132

Which THREE of the following are mandatory components for GlobalProtect client connectivity?

Hard
133

Refer to the exhibit. A firewall administrator is troubleshooting why some applications are not being correctly identified. The firewall is running App-ID version 8000-7120. What does the 'appid packet buffer: 1024 KB' indicate?

Medium
134

An administrator configures the management interface with IP 192.168.1.1/24 and can ping it from a host on the same subnet, but cannot access the web interface. What is the likely cause?

Easy
135

Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?

Hard
136

A team uses the Panorama API to generate custom reports. They need to retrieve a list of all rules that have logging at session end enabled. Which API endpoint should be used?

Medium
137

A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?

Medium
138

Which THREE are required for a successful firewall-to-firewall IPSec VPN tunnel? (Choose three.)

Hard
139

In an Active/Passive HA pair, the passive firewall reports 'non-functional' state. The 'show high-availability state' output on the passive shows 'state: non-functional' and 'reason: configuration mismatch'. The active firewall shows 'state: active' and 'reason: no reason'. Which action should be taken to resolve the issue without disrupting traffic?

Hard
140

A security administrator is configuring a security policy to allow the 'web-browsing' application but block the 'facebook' application. The administrator creates a rule that allows 'web-browsing' and a subsequent rule that denies 'facebook'. However, users report that they can still access Facebook. The administrator checks the traffic logs and sees that Facebook traffic is being identified as 'web-browsing'. Which action should the administrator take to correctly block Facebook?

Hard
141

A firewall is dropping traffic that should be allowed. The security policy appears correct. An administrator checks the session table and notices the session state is 'CLOSE'. What is the most likely cause of the traffic being dropped?

Medium
142

An administrator is preparing a PA-3220 running PAN-OS 11.0 for a maintenance window and wants to capture the current operational state so it can be compared after the window. Which two actions should the administrator take to preserve this state for later comparison? (Choose two.)

Medium
143

A security administrator needs to ensure that the firewall sends an email notification to the security team whenever a critical threat is detected. The email server is reachable at 10.10.10.5, and the firewall's management interface is in the 10.10.10.0/24 subnet. Which configuration step is required to enable email notifications for critical threats?

Medium
144

A security administrator is designing a zero trust architecture using Palo Alto Networks Next-Generation Firewalls. They need to ensure that all traffic between the internal network and the internet is inspected, and that users are identified regardless of location. Which two components are required to achieve user identification for both on-premises and remote users? (Choose two.)

Medium
145

During a security audit, it is discovered that some HTTP traffic is being incorrectly identified as 'web-browsing' instead of 'ssl' even though the traffic uses HTTPS. The firewall is positioned as a transparent bridge and no SSL decryption is configured. What is the most likely cause?

Hard
146

A network security engineer is troubleshooting why a user's session to a SaaS application is being decrypted by SSL Forward Proxy but then immediately reset. The engineer checks the session details and sees the session end reason as 'tcp-rst-from-server'. Packet capture on the firewall shows that the server is sending a TCP RST after the client sends a TLS Client Hello. The firewall's decryption profile is configured to block sessions with untrusted issuers. What is the most likely cause of the reset?

Hard
147

A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?

Easy
148

Arrange the steps to enable and configure GlobalProtect on a Palo Alto Networks firewall.

Medium
149

An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?

Medium
150

A network security engineer is configuring a route-based IPsec VPN between two Palo Alto Networks firewalls. The engineer needs to ensure that the tunnel interface is used for dynamic routing updates and that the VPN can fail over to a backup path if the primary path goes down. Which configuration is required to achieve this?

Medium
151

A company has an application signature for an internal ERP system that uses a proprietary protocol over TCP port 4444. The ERP traffic is sometimes misidentified as unknown-tcp. Which App-ID mechanism should be used to improve identification without affecting the default App-ID engine?

Medium
152

An engineer is troubleshooting an HA pair where the passive firewall is not synchronizing sessions. The HA1 link is up and the HA state is 'passive'. The engineer notices that the HA2 link is up, but session synchronization is still not working. Which action should the engineer take next?

Hard
153

A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?

Hard
154

Refer to the exhibit. Which SSL protocol version is blocked as per this decryption profile?

Medium
155

Refer to the exhibit. A network engineer sees multiple IKE SAs for the same peer. What does this indicate?

Easy
156

What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?

Easy
157

A security engineer is configuring HA on a pair of Palo Alto Networks firewalls. The engineer wants to ensure that the HA1 control link is highly available. Which configuration should the engineer use for the HA1 link?

Easy
158

A company needs to provide internet access to 500 internal users using a single public IP address. Which NAT method should be configured?

Easy
159

A network security administrator is configuring a new Palo Alto Networks firewall and wants to ensure that traffic between two internal subnets is inspected by the firewall. The subnets are on different interfaces. What must be configured to allow the firewall to inspect this traffic?

Easy
160

Which Panorama deployment mode allows centralized management of firewalls while storing logs locally on each firewall instead of sending them to the Panorama log collector?

Easy
161

An HA pair is deployed with Active/Active mode. During a traffic spike, session table utilization reaches 90% on both firewalls. The engineer notices asymmetric routing and drops. What should be configured to optimize session distribution?

Hard
162

A network engineer needs to verify that a specific security rule is being hit by traffic. Which firewall log should be examined?

Easy
163

An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?

Medium
164

Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?

Medium
165

Match each security profile type to its purpose.

Medium
166

A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?

Hard
167

Refer to the exhibit. What happens when a user with an unknown identity (source-user unknown) tries to access resources in 192.168.1.0/24?

Hard
168

An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?

Medium
169

Which TWO troubleshooting steps are most effective when an HA pair is not synchronizing sessions between peers? (Assume HA1 and HA2 are up.)

Hard
170

An administrator needs to ensure that the firewall sends an alert to an external server whenever a critical threat is detected, and also wants to receive a daily summary of blocked traffic. Which two log forwarding destinations should be configured to satisfy both requirements?

Easy
171

The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?

Hard
172

Which TWO settings must be configured in a security policy rule to ensure the rule only matches when a specific application is detected on its standard port?

Easy
173

Refer to the exhibit. A user in the 10.0.0.0/8 network is unable to access a web server at 172.16.1.10 which is in the DMZ zone. The firewall's security policy is shown: source zone trust, destination zone untrust, application web-browsing, action allow. What is the most likely reason for the failure?

Medium
174

A firewall administrator is troubleshooting a scenario where users cannot reach an internal web server. The security policy allows the traffic, and the server is reachable from other networks. What should the administrator check first?

Easy
175

Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)

Hard
176

A company has configured multi-factor authentication (MFA) via an authentication sequence using LDAP and RADIUS. Users authenticate successfully with LDAP but the MFA prompt from RADIUS does not appear. What is the most likely cause?

Easy
177

Which TWO authentication methods support single sign-on (SSO) capabilities in Palo Alto Networks firewalls?

Easy
178

The firewall is in passive state. The network team reports that during a recent maintenance window, the active firewall lost its upstream link but the passive firewall did not take over. Based on the exhibit, what is the most likely reason?

Hard
179

An organization has two sites connected via IPSec VPN. The tunnel is up, but ICMP traffic between sites fails. No other traffic works. The firewall policy allows any-any. What is the most likely issue?

Medium
180

An administrator is preparing to upgrade a PA-5220 firewall from PAN-OS 10.2 to a later maintenance release. Before the upgrade, the administrator wants to minimize the chance of a failed upgrade and ensure a rollback path exists. Which two actions should the administrator take? (Choose two.)

Medium
181

A security administrator configures a new network template in Panorama and assigns it to a template stack. The template stack is associated with a device group containing several firewalls. After committing the Panorama configuration and pushing to devices, some firewalls in the device group do not have the new template settings. What is the most likely cause?

Medium
182

What does the session state 'SYN_SENT' indicate about this traffic flow?

Medium
183

A network security engineer is troubleshooting why a Palo Alto Networks firewall is not enforcing a security policy that should block traffic from the untrust zone to the trust zone. The policy is configured correctly, and the firewall is receiving traffic. The engineer suspects that the traffic is being allowed by a different policy due to policy evaluation order. Which factor determines the order in which security policies are evaluated?

Hard
184

A company has configured User-ID with Active Directory polling. Some users cannot access resources even though their security policy rules appear correct. The administrator verifies that the User-ID agent is connected and polling. What additional step should the administrator take?

Medium
185

A security administrator is troubleshooting why a user cannot access an internal server at 192.168.1.50 from the trust zone. The firewall is a PA-5220 running PAN-OS 10.2. The administrator checks the traffic log and sees that the session is allowed by a security policy rule. However, the user still cannot connect. The administrator runs 'show session all filter source 10.1.1.10 destination 192.168.1.50' and sees the session state as 'ACTIVE' but with 'tcp-rst-from-server' flag. What is the most likely cause?

Hard
186

A company uses User-ID to map users to IPs. Some users report that their traffic is being blocked even though they are in the correct user group for access. The security policy uses user-based conditions. What is a likely cause?

Medium
187

A network engineer notices that traffic from a specific subnet is being dropped by the firewall. The traffic log shows 'drop' with reason 'policy deny'. The engineer checks the security policy and confirms there is an allow rule for that subnet. What should be checked next?

Easy
188

A firewall in an HA pair is being upgraded. The administrator wants to minimize traffic loss. What is the recommended procedure for upgrading the passive firewall in an active/passive pair?

Medium
189

Which THREE components should be verified when troubleshooting a site-to-site IPSec VPN that is not coming up?

Hard
190

Which TWO of the following are required when configuring a new virtual wire (vwire) on a Palo Alto Networks firewall?

Medium
191

An administrator is troubleshooting why a Security policy rule that allows traffic from the 'trust' zone to the 'untrust' zone is not matching for certain sessions. The administrator notices that the sessions are being denied by an interzone rule. What is the most likely cause?

Medium
192

Refer to the exhibit. Based on the log, what triggered the failover?

Hard
193

Which component of the PAN-OS architecture is responsible for processing security policies and performing packet inspection?

Easy
194

A network engineer wants to reduce the number of applications in security policies by combining several applications that are always used together. What is the best practice?

Medium
195

An administrator is configuring a Palo Alto Networks firewall to enforce security policies based on user identity. The environment uses Active Directory, and the administrator plans to deploy User-ID. Which TWO actions are required to enable User-ID to map IP addresses to usernames? (Choose two.)

Medium
196

A security engineer is configuring a Palo Alto Networks firewall to send alerts to an external SNMP manager. The engineer wants to ensure that the firewall sends SNMP traps for specific events, such as a link state change and a configuration change. Which two actions must the engineer perform to achieve this? (Choose two.)

Medium
197

Which THREE of the following are core components of the GlobalProtect solution? (Choose exactly three.)

Easy
198

During a failover test, the active firewall in an active/passive HA pair goes down, but the passive firewall remains in passive state and does not take over. The passive firewall shows HA state 'passive' and the HA1 link status is 'down'. What is the most likely cause?

Medium
199

A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?

Medium
200

An administrator needs every administrator login, configuration commit, and firewall restart to be recorded in a central location for an upcoming audit. The auditor requires that the records be queryable by username and timestamp, and that they be retained independently of the firewall's own log storage. Which action should the administrator take to meet these requirements?

Medium
201

A security administrator is configuring a Palo Alto Networks firewall and needs to ensure that traffic from the trust zone to the untrust zone is inspected for threats. The administrator wants to enable threat prevention profiles on the security policy. Which Palo Alto Networks feature is responsible for detecting and preventing threats such as viruses, spyware, and command-and-control traffic?

Easy
202

During a troubleshooting session, a user reports that they cannot access an internal web server through the firewall's public IP. The firewall is configured with destination NAT. The engineer checks the NAT policy and sees the rule is active. What should be the next step to verify the NAT is functioning correctly?

Medium
203

A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?

Hard
204

An administrator needs to allow FTP traffic from the internal network to an external server. The firewall is configured with a security policy that has the application 'ftp' and service 'service-http'. What is the most likely cause of the traffic being denied?

Easy
205

A network administrator is deploying a new Palo Alto Networks firewall and needs to configure the data-plane interfaces. The firewall will be placed between the internal network and the internet. The internal network uses private IP addresses and must be translated to a public IP address for outbound traffic. Which type of NAT should the administrator configure on the firewall?

Easy
206

Refer to the exhibit. An administrator has configured this decryption policy but users in the 10.1.1.0/24 subnet receive certificate warnings when accessing HTTPS sites. What is the most likely cause?

Hard
207

An administrator notices that the firewall's dataplane CPU is consistently high and wants to determine which application is generating the most traffic without waiting for scheduled reports. Which action provides the most immediate visibility into top applications by session and byte count?

Hard
208

A firewall is experiencing performance issues. The administrator wants to collect diagnostic data for TAC analysis. Which command generates a comprehensive support file?

Easy
209

A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?

Hard
210

In an Active/Passive HA pair, which statement is true regarding configuration synchronization?

Medium
211

An engineer notices that the HA pair is not synchronizing configuration changes. The 'show high-availability sync-status' output shows 'sync-failure'. What is the first step to troubleshoot?

Medium
212

To reduce the number of authentication prompts for users accessing multiple applications through the firewall, which configuration is recommended?

Easy
213

A network administrator wants to generate a report that shows the top applications used over the past week. The firewall is managed by Panorama. Which Panorama feature should the administrator use to create and schedule this report?

Easy
214

A network administrator is setting up a new Palo Alto Networks firewall in Layer 3 mode. The firewall has two interfaces: ethernet1/1 connected to the trust zone (internal network) and ethernet1/2 connected to the untrust zone (internet). The administrator wants to enable the firewall to perform DNS resolution for its own management traffic and for DNS proxy. Which type of interface configuration is required for the firewall to send DNS queries?

Easy
215

Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?

Medium
216

A network administrator is configuring a new Palo Alto Networks firewall and needs to ensure that management traffic is separated from data traffic. Which interface type should be used for out-of-band management?

Easy
217

A company has a Palo Alto Networks firewall with two virtual systems (vsys) configured. The administrator wants to ensure that traffic between vsys1 and vsys2 is inspected by the firewall. What must be configured to allow this inter-vsys traffic?

Medium
218

An engineer is troubleshooting an HA pair where the passive firewall is not receiving session updates. The HA1 link is up and the firewalls are in active/passive mode. The engineer runs 'show high-availability state' and sees 'State: passive' and 'Peer State: active'. Which additional command should the engineer run to verify that session synchronization is enabled and functioning?

Hard
219

A security team is implementing SSL Decryption. They want to ensure that traffic to health-related websites is not decrypted due to privacy concerns. Which method should they use to exclude this traffic?

Medium
220

In an HA active/passive setup, the engineer wants to ensure that during a failover, existing FTP data sessions are not interrupted. What additional configuration is required beyond default session synchronization?

Hard
221

Which TWO of the following are true regarding Panorama's templates and device groups?

Medium
222

A network administrator wants to verify if a specific internal IP address (10.1.1.100) is being translated to a public IP when accessing the internet. Which CLI command should be used?

Easy
223

An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?

Hard
224

A firewall administrator is troubleshooting why a user is unable to access a website. The administrator checks the traffic logs and sees that the session was allowed by the security policy, but the application is identified as 'ssl' instead of 'web-browsing'. The website uses HTTPS on port 443. What is the most likely reason for the application being identified as 'ssl'?

Easy
225

The security policy rule shown in the exhibit has log-start and log-end both set to 'no', but a log-forwarding profile is configured. Which statement best describes the logging behavior for sessions matching this rule?

Medium
226

A network security engineer is investigating why a firewall's dataplane CPU is consistently at 95%. After reviewing the session table, they notice a large number of sessions in a 'discard' state. Which action should the engineer take first to resolve the high CPU utilization?

Hard
227

A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?

Easy
228

A security administrator is configuring a Palo Alto Networks firewall to decrypt outbound SSL traffic for a specific user group. The administrator creates a decryption policy with source user group 'Finance', destination any, and action 'ssl-forward-proxy'. However, after committing, users in the Finance group report that they can still access HTTPS sites without any certificate warnings, and the firewall logs show no decryption. The administrator verifies that the decryption policy is placed correctly and that the forward trust certificate is installed and trusted by the clients. What is the most likely reason decryption is not occurring?

Medium
229

An engineer wants to block the use of file-sharing application BitTorrent, but allow file transfers over SFTP which also uses port 22. What is the most effective way to achieve this using App-ID?

Medium
230

A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?

Easy
231

An organization has deployed GlobalProtect with certificate authentication. Users on macOS report that after updating their client, they cannot connect and see error 'Certificate validation failed: The certificate hash does not match.' What is the most likely cause?

Hard
232

An administrator wants to view real-time CPU and memory usage on the firewall. Which CLI command should be used?

Easy
233

A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?

Easy
234

Refer to the exhibit. Based on the log entry, what action was taken on this traffic?

Hard
235

A security administrator needs to configure the firewall to send an email alert whenever a critical threat is detected. The administrator wants to ensure that the email includes the threat details and is sent immediately. Which configuration step is required to achieve this?

Easy
236

A firewall administrator is configuring a new security zone for a DMZ. The requirement is that the DMZ zone should not be able to initiate connections to the internal trusted zone, but the trusted zone should be able to initiate connections to the DMZ. Which configuration achieves this with the least administrative effort?

Easy
237

Based on the exhibit, what is the most likely cause of the warnings?

Hard
238

By default, what is the action on traffic between two different zones without any security rule?

Easy
239

Refer to the exhibit. What does the serial number '0123456789' indicate?

Easy
240

A firewall administrator is troubleshooting an issue where a PA-3260 is experiencing high dataplane CPU utilization. The administrator runs 'show running resource-monitor' and sees that the CPU is consistently above 90%. Which command should the administrator use to identify the top applications contributing to the high CPU usage?

Hard
241

Which TWO components are part of the PAN-OS management plane?

Easy
242

A company is deploying GlobalProtect for remote users and wants to enforce that only users with valid certificates are allowed to connect. Which configuration is required on the GlobalProtect gateway?

Easy
243

An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?

Medium
244

A security administrator is troubleshooting why a custom application that uses SSL/TLS on TCP port 9443 is being identified as 'ssl' instead of the custom App-ID. The firewall has a security policy that allows 'ssl' and the custom application. The administrator has already confirmed that the traffic passes through the firewall and that SSL decryption is not enabled. Which action should the administrator take to allow App-ID to correctly identify the application?

Medium
245

A security team needs to capture traffic for forensic analysis of a specific application that uses non-standard ports. The administrator wants to capture packets on the firewall for that application only, without affecting performance. Which method should be used?

Hard
246

A user reports that they cannot access a specific website. The firewall security policy allows web traffic. The administrator checks the traffic log and sees that the session is being denied due to a 'URL Filtering' block. What should the administrator do to allow access?

Easy
247

A security administrator is designing a zero-trust architecture using Palo Alto Networks firewalls. They want to ensure that traffic between two internal zones is inspected and that access is granted based on user identity and device posture rather than IP address alone. Which two PAN-OS features must be implemented to meet these requirements? (Choose two.)

Hard
248

A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?

Hard
249

A network administrator is reviewing the firewall's logs and notices that many sessions are being denied by the security policy. The administrator wants to quickly identify the top source IP addresses that are being denied. Which feature in the PAN-OS web interface should the administrator use to accomplish this?

Easy
250

Arrange the steps to configure a new administrator account with role-based access.

Medium
251

An administrator is configuring HA on a pair of PA-5220 firewalls. They want to ensure that the HA1 link is redundant and can survive a single link failure. Which configuration should they use?

Medium
252

A security team uses Panorama to push policy to 40 managed firewalls. An administrator commits a policy change from Panorama, and the commit succeeds on Panorama but fails on 12 firewalls with a validation error. The administrator wants to identify which firewalls failed and the specific error each reported without opening each device individually. Which Panorama feature should the administrator use?

Hard
253

A network engineer is configuring HA on a pair of PA-5220 firewalls. The company requires that the HA1 control link be secured and that the firewalls authenticate each other. Which action should the engineer take?

Medium
254

Order the steps to configure a security policy allowing HTTP traffic from the inside to the outside zone.

Medium
255

An engineer is configuring HA on a pair of firewalls and wants to ensure that the HA1 link is secure and redundant. Which two actions should the engineer take? (Choose two.)

Hard
256

A security engineer needs to deploy a Palo Alto Networks firewall in a high-availability (HA) pair with active/passive mode. The firewall will inspect traffic for multiple tenants, each requiring separate routing and policy configuration. Which feature should be used to isolate tenant configurations while using a single pair of firewalls?

Medium
257

A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?

Easy
258

Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?

Easy
259

A network engineer is troubleshooting an HA pair where the passive firewall is showing a state of 'suspended'. The active firewall is functioning normally. What is the most likely reason for the suspended state?

Easy
260

A firewall has two virtual routers: VR1 (for internal networks) and VR2 (for DMZ). An internal server in VR1 needs to reach a DMZ server in VR2. Both virtual routers have routes to each other's subnets via a shared inter-connect. The firewall is receiving traffic but is dropping packets between the virtual routers. What configuration is missing?

Medium
261

An engineer is configuring App-ID for a network that uses both standard and custom applications. Which of the following are best practices for using App-ID effectively? (Choose three.)

Medium
262

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?

Medium
263

A company has deployed two PA-3220 firewalls in an active/passive high availability configuration. During normal operation, the active firewall (FW-A) handles all traffic. The network team notices that after a brief power outage, both firewalls report as active in the HA pair, causing network instability. The administrator needs to resolve this issue and prevent it from recurring. Which course of action should the administrator take?

Easy
264

A company has deployed two Palo Alto Networks firewalls in an active/passive HA configuration. During a failover test, the engineer notices that the passive firewall did not take over when the active firewall's data plane interface went down. The engineer reviews the HA configuration and sees that the HA1 link is up and the HA2 link is up. What is the most likely reason for the failover not occurring?

Medium
265

An administrator is configuring a Palo Alto Networks firewall to perform SSL decryption for outbound traffic. The administrator wants to ensure that traffic to certain categories, such as financial services, is not decrypted due to privacy concerns. What should the administrator configure?

Hard
266

Two firewalls in an active/passive HA pair are not synchronizing. The administrator checks 'show high-availability state' and sees 'active' on both firewalls. What is the most likely cause?

Hard
267

A network security engineer is troubleshooting an application that is inconsistently identified as 'unknown-tcp' in the traffic logs. The application uses TCP port 8080 and initiates with a proprietary binary handshake. The engineer confirms that no custom App-ID has been created. Which action should the engineer take to ensure the firewall reliably identifies this application?

Medium
268

Order the steps to configure a static route on a Palo Alto Networks firewall.

Medium
269

An organization has a firewall in HA active-passive mode. After a failover, the new active firewall does not have the latest session table. What should be configured to ensure session synchronization?

Hard
270

Refer to the exhibit. A user at IP 10.10.1.11 is unable to access internal resources that require authentication. The firewall logs show 'no user mapping' for traffic from this IP. Which step should the administrator take first?

Hard
271

A small business uses a single PA-220 firewall with PAN-OS 10.2. The administrator notices that the firewall is no longer receiving automatic threat updates. The License page shows the Threat Prevention license is active with 200 days remaining. The administrator can manually download updates from the Palo Alto Networks update server. What is the most likely cause?

Easy
272

A network security engineer is troubleshooting why a newly installed Palo Alto Networks firewall is not inspecting traffic between two internal subnets. The engineer confirms that the traffic is routed through the firewall, security policies are configured to allow and inspect the traffic, and no drop counters are incrementing. However, the firewall's session table shows sessions in an 'ACTIVE' state but with no application identified. Which component of the Palo Alto Networks Next-Generation Firewall is responsible for identifying the application in this scenario?

Medium
273

An administrator wants to be notified whenever any administrator account is locked out after repeated failed login attempts. The notification must be sent by email to the security team. Which configuration accomplishes this?

Easy
274

A network engineer is troubleshooting an authentication issue where users in a specific group are not being prompted for credentials, even though the authentication policy matches their traffic. The firewall logs show that the traffic is allowed by the security policy. What is the most likely cause?

Hard
275

Which TWO statements correctly describe the role of the data plane in PAN-OS architecture?

Medium
276

An administrator needs to verify the health of HA links. Which CLI command displays the current status of HA1, HA2, and HA3 links?

Easy
277

An administrator reviews a traffic log entry: 'Source: 10.0.0.10, Destination: 8.8.8.8, Application: web-browsing, Action: allow, Bytes Sent: 500, Bytes Received: 1200'. What does this log entry indicate about the traffic?

Medium
278

Which TWO factors can cause traffic to be classified as 'incomplete' by App-ID? (Choose two.)

Medium
279

Which TWO are valid methods to troubleshoot a firewall not passing traffic? (Choose two.)

Easy
280

Which TWO are best practices when configuring App-ID for a production environment? (Choose two.)

Easy
281

Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?

Easy
282

Refer to the exhibit. What does the 'Session End Reason: aged-out' indicate about the traffic?

Hard
283

Users are unable to authenticate via Captive Portal. The firewall receives authentication requests but they time out. What should be checked first?

Medium
284

Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?

Hard
285

An administrator is analyzing traffic logs on a Palo Alto Networks firewall and notices that a particular session shows an application of 'incomplete' and no bytes received. The session was allowed by the security policy. What is the most likely cause?

Medium
286

A network administrator wants to allow only specific applications such as 'facebook-base' and 'youtube' while blocking all other applications. Which type of security rule should be used to achieve this?

Easy
287

Arrange the steps to configure a new zone on a Palo Alto Networks firewall in the correct order.

Medium
288

Which TWO factors can cause a firewall to not show any User-ID mapping for a user who is actively logged in?

Medium
289

Which THREE of the following are capabilities of GlobalProtect Host Information Profile (HIP)?

Hard
290

Arrange the steps to perform a factory reset on a Palo Alto Networks firewall.

Medium
291

A security engineer needs to allow inbound HTTPS traffic from the internet to a web server in the DMZ. The source zone is 'Untrust', destination zone is 'DMZ', and the destination address is the web server's IP. Which security policy action should be used?

Easy
292

An administrator wants to receive SNMP traps from the firewall for critical events such as failed login attempts and high CPU usage. Which configuration step is required?

Easy
293

A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)

Hard
294

Refer to the exhibit. A firewall system log contains a critical license expiration entry for URL Filtering. What will happen to URL Filtering functionality?

Easy
295

A network engineer is configuring a new firewall to replace an existing one. The existing firewall has a policy that allows traffic from the 10.0.0.0/8 subnet to the internet. The new firewall must use the same policy but also log the traffic. The engineer creates a security rule with source zone 'Trust', destination zone 'Untrust', source address 10.0.0.0/8, and action 'allow'. Logging is set at rule end. However, traffic from 10.1.0.0/16 is not being logged. What is the reason?

Hard
296

An administrator is troubleshooting VPN tunnel flapping. The logs show multiple Phase 2 rekeys. The tunnel uses IKEv2 with pre-shared key. What is the most likely cause?

Hard
297

An enterprise requires separate administrative domains within a single firewall chassis for different business units. Each domain must have its own virtual router, security policies, and interface configuration. What is the appropriate PAN-OS feature?

Hard
298

Which THREE components are part of the GlobalProtect infrastructure? (Choose three.)

Medium
299

During a traffic spike, the firewall CPU utilization remains below 30% but the dataplane packet buffer usage is consistently above 90%. What is the most likely impact on firewall performance?

Medium
300

An administrator wants to generate a report that shows the top applications by bandwidth usage over the last week. Which report type should be used to accomplish this?

Easy
301

During a security audit, it is discovered that a custom application signature matches too broadly, causing benign traffic to be classified as the custom app. What change should be made to narrow the signature?

Hard
302

Based on the exhibit, what caused the last failover?

Medium
303

A security administrator is configuring a firewall to inspect traffic between two internal zones. The administrator wants to ensure that the firewall performs application identification and content inspection on all allowed traffic. Which configuration is required to achieve this?

Hard
304

A firewall is configured with a destination NAT rule to translate public IP 203.0.113.10 to internal server 10.0.0.5 on port 443. Internal users from 10.0.0.0/24 can access the server using its private IP, but cannot access using the public IP. What should be configured to allow internal users to reach the server using the public IP?

Medium
305

The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?

Medium
306

Which THREE of the following can cause App-ID to incorrectly identify traffic?

Hard
307

A network engineer is configuring App-ID for a custom application that uses a proprietary protocol over TCP port 12345. The application's traffic is not being identified as expected. Which configuration change should the engineer make to ensure the firewall correctly identifies this application?

Medium
308

An organization uses a SaaS application that runs on a dynamic set of IP addresses. The application traffic is currently identified as ssl and not as the specific application. How can the administrator improve application identification for this SaaS application?

Medium
309

Refer to the exhibit. An engineer configures HA with link monitoring and path monitoring. However, failover does not occur when ethernet1/2 goes down. What is the likely reason?

Medium
310

A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?

Hard
311

A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?

Easy
312

A firewall administrator is troubleshooting a connectivity issue where users cannot reach a web server. The administrator checks the traffic log and sees that the session is being denied by a security policy rule. The administrator verifies that the rule is correctly configured to deny the traffic. However, the administrator wants to see which rule is blocking the traffic. Which action should the administrator take?

Easy
313

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Hard
314

An engineer checks the application counter and sees that my-custom-app has zero packets, but they expected traffic from 10.0.0.0/24 to 10.1.0.0/24 to be identified as my-custom-app. What is the most likely reason?

Medium
315

A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)

Easy
316

A firewall administrator is troubleshooting an issue where users behind a PA-3220 cannot access a public web server. The security policy allows the traffic. The administrator runs 'show session all filter source 10.1.1.50 destination 203.0.113.10' and sees a session with application 'incomplete' and no packets received from the server. Which tool should the administrator use to determine why the firewall is not receiving a response from the server?

Medium
317

Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)

Easy
318

A company uses a Palo Alto Networks firewall with App-ID enabled. They have a custom application that communicates over TCP port 5001. The administrator has created a custom App-ID signature and a security rule that allows this application from the internal zone (trust) to the external zone (untrust). Users report that the custom application traffic is being blocked. The administrator checks the traffic logs and sees that the sessions are being matched to a different security rule that denies any traffic from trust to untrust. The deny rule appears before the custom allow rule in the policy list. The custom App-ID signature is properly defined and tested. What should the administrator do to resolve this issue?

Easy
319

Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?

Easy

Frequently asked questions

What does the scenario questions domain cover on the PCNSE exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 319 scenario questions questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.