Correct answer & explanation
✓Next-Generation Firewall (NGFW): Network security and traffic inspection
The correct matches are: NGFW for network security, Panorama for central management, Cortex XDR for endpoint detection, and Prisma Cloud for cloud security. Common confusions include mistaking Panorama's management role for NGFW or assigning cloud security to Cortex XDR.
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
How Courseiva writes practice questions · Editorial policy
Same concept, more angles
1 more way this is tested on PCNSE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Match each Palo Alto Networks feature to its primary function.
medium- ✓ A.App-ID: Identifies applications regardless of port, protocol, or encryption.
- B.User-ID: Identifies applications regardless of port, protocol, or encryption.
- ✓ C.User-ID: Maps IP addresses to usernames or groups.
- D.Content-ID: Inspects encrypted traffic by decrypting it.
- ✓ E.Content-ID: Scans content for threats and data filtering.
- ✓ F.SSL Decryption: Inspects encrypted traffic by decrypting it.
Why A: The correct matches are: App-ID identifies applications; User-ID maps IPs to users; Content-ID scans content; SSL Decryption decrypts traffic. Common confusions include swapping App-ID and User-ID, or confusing Content-ID with SSL Decryption.