PCNSE · domain
Troubleshoot
The Troubleshoot domain (11%) covers diagnosing PAN-OS and Panorama issues: traffic flow failures, GlobalProtect connectivity, decryption problems, and commit or HA errors. The exam presents scenario-based questions asking you to identify the root cause from CLI output, logs, or GUI state, then select the correct diagnostic command or fix.
Focused practice
Practice Troubleshoot questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Troubleshoot
Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
Reading 'show session all filter' and 'test security-policy-match' output to trace dropped traffic
Using 'show system logdb-quota' and log forwarding to isolate logging pipeline failures
Diagnosing GlobalProtect tunnel failures via 'show global-protect-gateway statistics' and gateway logs
Interpreting HA state with 'show high-availability state' and resolving split-brain or suspended peers
Watch out for
Common Troubleshoot exam traps
- ▸Assuming a commit succeeded without checking 'show jobs all' for partial or failed commits on managed firewalls
- ▸Confusing flow ownership in active/active HA, so session lookups run on the wrong peer and show no data
- ▸Blaming the firewall for app failures when the real cause is a decryption profile or SSL forward proxy exclusion
Question index
All Troubleshoot questions (31)
Click any question to see the full explanation, or start a practice session above.
A company is experiencing intermittent connectivity issues between two branch offices connected via an IPSec tunnel. Users report that they can access resources for a few minutes, then lose connectivity, and after a short time it comes back. Which troubleshooting step should be taken first?
Medium2A Palo Alto Networks firewall administrator is troubleshooting why a session was terminated with the flag 'tcp-rst-from-client'. The administrator wants to identify possible causes for this termination flag. Which two factors can cause a session to be terminated with 'tcp-rst-from-client'? (Choose two.)
Hard3Refer to the exhibit. A user at 10.1.1.10 is trying to connect to a web server at 203.0.113.5 on port 443. The session shows 'State: DROP' with reason 'policy-deny'. However, the administrator has a security policy rule that allows SSL traffic from the source zone to the destination zone. What is the most likely cause of the drop?
Medium4A SOC analyst reports that a critical security policy rule denying traffic from the 'Untrust' zone to the 'DMZ' zone is not generating any traffic logs, even though the analyst sees a high volume of denied traffic in other tools. The administrator confirms that the rule is correctly configured to deny and that logging is enabled at the rule level. What is the most likely reason for the missing logs?
Easy5A security administrator is investigating why a session was terminated with the flag 'tcp-rst-from-server' in the traffic logs. The administrator has confirmed that the server is reachable and responding to pings. Which of the following is the most likely cause for this session termination?
Hard6A network engineer is troubleshooting why a Palo Alto Networks firewall is not generating any traffic logs for sessions that match a security policy rule set to allow. The engineer confirms that the rule is hit and traffic passes successfully. Which of the following is the most likely reason for the absence of logs?
Medium7A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?
Easy8A network administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions in real-time to identify which application is consuming the most bandwidth. Which command should the administrator use?
Easy9A company has two Palo Alto Networks firewalls in an active/passive high availability pair. The firewalls are configured with a virtual IP (VIP) for the internal network. Recently, the passive firewall was upgraded to a new PAN-OS version. After the upgrade, the active firewall is still running the old version. The administrator wants to perform a failover to make the upgraded firewall active. However, when the administrator attempts to manually failover, the new passive firewall does not become active. The HA synchronization status shows 'synchronized' but the preemption is disabled. The administrator checks the HA configuration and finds that the peer's version is not compatible. What should the administrator do to successfully failover to the upgraded firewall?
Medium10A network engineer is troubleshooting why a Palo Alto Networks firewall is not decrypting SSH traffic even though an SSL Forward Proxy decryption policy is configured for the internal zone. The engineer confirms that the SSH traffic matches the decryption policy and that the forward trust and untrust certificates are installed and valid. What is the most likely reason the SSH traffic is not being decrypted?
Medium11Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?
Hard12Which THREE are required for a successful firewall-to-firewall IPSec VPN tunnel? (Choose three.)
Hard13A network security engineer is troubleshooting why a user's session to a SaaS application is being decrypted by SSL Forward Proxy but then immediately reset. The engineer checks the session details and sees the session end reason as 'tcp-rst-from-server'. Packet capture on the firewall shows that the server is sending a TCP RST after the client sends a TLS Client Hello. The firewall's decryption profile is configured to block sessions with untrusted issuers. What is the most likely cause of the reset?
Hard14A network engineer needs to verify that a specific security rule is being hit by traffic. Which firewall log should be examined?
Easy15A firewall administrator is troubleshooting a scenario where users cannot reach an internal web server. The security policy allows the traffic, and the server is reachable from other networks. What should the administrator check first?
Easy16A security administrator is troubleshooting why a user cannot access an internal server at 192.168.1.50 from the trust zone. The firewall is a PA-5220 running PAN-OS 10.2. The administrator checks the traffic log and sees that the session is allowed by a security policy rule. However, the user still cannot connect. The administrator runs 'show session all filter source 10.1.1.10 destination 192.168.1.50' and sees the session state as 'ACTIVE' but with 'tcp-rst-from-server' flag. What is the most likely cause?
Hard17A network engineer notices that traffic from a specific subnet is being dropped by the firewall. The traffic log shows 'drop' with reason 'policy deny'. The engineer checks the security policy and confirms there is an allow rule for that subnet. What should be checked next?
Easy18Which THREE components should be verified when troubleshooting a site-to-site IPSec VPN that is not coming up?
Hard19During a troubleshooting session, a user reports that they cannot access an internal web server through the firewall's public IP. The firewall is configured with destination NAT. The engineer checks the NAT policy and sees the rule is active. What should be the next step to verify the NAT is functioning correctly?
Medium20A network administrator wants to verify if a specific internal IP address (10.1.1.100) is being translated to a public IP when accessing the internet. Which CLI command should be used?
Easy21An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?
Hard22A firewall administrator is troubleshooting why a user is unable to access a website. The administrator checks the traffic logs and sees that the session was allowed by the security policy, but the application is identified as 'ssl' instead of 'web-browsing'. The website uses HTTPS on port 443. What is the most likely reason for the application being identified as 'ssl'?
Easy23A firewall administrator is troubleshooting an issue where a PA-3260 is experiencing high dataplane CPU utilization. The administrator runs 'show running resource-monitor' and sees that the CPU is consistently above 90%. Which command should the administrator use to identify the top applications contributing to the high CPU usage?
Hard24A user reports that they cannot access a specific website. The firewall security policy allows web traffic. The administrator checks the traffic log and sees that the session is being denied due to a 'URL Filtering' block. What should the administrator do to allow access?
Easy25Which TWO are valid methods to troubleshoot a firewall not passing traffic? (Choose two.)
Easy26Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?
Easy27Refer to the exhibit. A firewall system log contains a critical license expiration entry for URL Filtering. What will happen to URL Filtering functionality?
Easy28An administrator is troubleshooting VPN tunnel flapping. The logs show multiple Phase 2 rekeys. The tunnel uses IKEv2 with pre-shared key. What is the most likely cause?
Hard29A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?
Easy30A firewall administrator is troubleshooting a connectivity issue where users cannot reach a web server. The administrator checks the traffic log and sees that the session is being denied by a security policy rule. The administrator verifies that the rule is correctly configured to deny the traffic. However, the administrator wants to see which rule is blocking the traffic. Which action should the administrator take?
Easy31A firewall administrator is troubleshooting an issue where users behind a PA-3220 cannot access a public web server. The security policy allows the traffic. The administrator runs 'show session all filter source 10.1.1.50 destination 203.0.113.10' and sees a session with application 'incomplete' and no packets received from the server. Which tool should the administrator use to determine why the firewall is not receiving a response from the server?
MediumOther domains
All PCNSE exam domains
Frequently asked questions
- What does the Troubleshoot domain cover on the PCNSE exam?
- Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
- How many questions are in this domain?
- This page lists all 31 Troubleshoot questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Troubleshoot questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.