Courseiva
← Back to Palo Alto Networks Certified Network Security Engineer PCNSE questions

Scenario-based practice

Hard Difficulty Questions

Practise Palo Alto Networks Certified Network Security Engineer PCNSE practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PCNSE
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PCNSE topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A large enterprise with 10,000+ users is deploying GlobalProtect with SAML authentication. The IdP is Azure AD. Users report that authentication sometimes fails during peak hours with error 'SAML response timeout'. Which design change would most effectively address this issue?

Question 2hardmultiple choice
Full question →

Refer to the exhibit. What does the 'Session End Reason: aged-out' indicate about the traffic?

Exhibit

# Timestamp: 2020-07-10 12:34:56
# Source IP: 10.0.0.1
# Destination IP: 203.0.113.2
# Application: ssl
# Action: allow
# Session End Reason: aged-out
# Bytes In: 5000
# Bytes Out: 12000
Question 3hardmulti select
Full question →

Which THREE of the following can cause App-ID to incorrectly identify traffic?

Question 4hardmultiple choice
Open the full VLAN trunking answer →

A large enterprise uses an active/passive HA pair of PA-5250 firewalls to secure their data center. The network team recently migrated from a flat network to a VXLAN-based overlay. After the migration, they notice that during failover tests, the new active firewall does not forward traffic for VXLAN-terminated VLANs, even though the physical interfaces are up and the HA state transitions correctly. The configuration uses subinterfaces on Ethernet1/1 for each VLAN, with VXLAN tunnel termination on the firewall. The passive firewall receives the configuration sync, but show vxlan tunnel shows no VXLAN tunnels on the new active firewall after failover. The sessions are synced via HA2. The ARP table is correct. Which course of action should the engineer take to resolve the issue?

Question 5hardmultiple choice
Full question →

A large enterprise uses a pair of PA-5250 firewalls in an active/passive high availability configuration to protect their data center. The firewalls are connected to two upstream switches via aggregate Ethernet (AE) interfaces. The network team recently replaced the upstream switches, and since then, the passive firewall has gone into a 'non-functional' state. The active firewall shows no issues. The HA1 link is a direct cable connection between the firewalls, and HA2 is an out-of-band dedicated link. The administrative status of both firewalls is 'active-active' in the HA monitoring, but only one firewall is actually forwarding traffic. The team needs to restore proper HA operation. Which action should the team take first?

Question 6hardmultiple choice
Full question →

A GlobalProtect user cannot connect to any resources after authenticating successfully. Portal and gateway configurations appear correct. What is the most likely issue?

Question 7hardmultiple choice
Full question →

A GlobalProtect user behind the tunnel is unable to browse HTTPS websites. What is the issue?

Exhibit

Refer to the exhibit.

Decryption policy rule:
{
  "name": "Skip Decrypt for VPN",
  "from": ["any"],
  "to": ["any"],
  "source": ["10.0.0.0/8"],
  "destination": ["any"],
  "service": ["application-default"],
  "category": ["any"],
  "action": "no-decrypt"
}

Additionally, the GlobalProtect gateway is configured with 'Tunnel Inspection' set to 'Required'.

A security administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The requirement is to send only threat logs and traffic logs, and to ensure that logs are sent in a reliable manner. Which configuration should the administrator use?

Question 9hardmultiple choice
Full question →

An administrator is configuring SSL Forward Proxy decryption and wants to ensure that traffic to internal servers with self-signed certificates is decrypted, but traffic to external banking sites is excluded from decryption. They have created a decryption policy with two rules: first rule with 'No Decrypt' for the external banking URLs, second rule with 'Decrypt' for all other traffic. However, the banking traffic is still being decrypted. What is the most likely issue?

Question 10hardmultiple choice
Full question →

Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?

Exhibit

2025/03/15 10:30:45,drop,203.0.113.10,10.1.1.200,https,443,trust,untrust,deny-rule,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any
Question 11hardmulti select
Full question →

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Question 12hardmultiple choice
Full question →

A network security engineer is configuring a Palo Alto Networks firewall to perform URL filtering. The company requires that all HTTP and HTTPS traffic from the trust zone to the untrust zone be inspected, and that access to known malware sites be blocked. The firewall is running PAN-OS 10.1. The engineer has already created a URL filtering profile with the appropriate categories set to block. Which additional configuration is required to ensure that HTTPS traffic is filtered based on the full URL?

Question 13hardmultiple choice
Full question →

An administrator has applied the above configuration on a firewall. What will happen to traffic destined to TCP port 2525?

Exhibit

Refer to the exhibit.

config
{
    "deviceconfig": {
        "system": {
            "application-override": [
                {
                    "@name": "override-smtp",
                    "port": 2525,
                    "application": "smtp",
                    "protocol": "tcp"
                }
            ]
        }
    }
}
Question 14hardmultiple choice
Full question →

A firewall is configured with User-ID using the 'Server Monitoring' method via LDAP. The administrator notices that user-to-IP mappings are only being updated every 60 minutes instead of the configured 15-minute polling interval. The LDAP server is reachable and responds quickly. What configuration parameter is most likely causing the delayed update?

Question 15hardmulti select
Full question →

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Question 16hardmultiple choice
Read the full NAT/PAT explanation →

The source NAT rule 'SNAT-Outside' is configured to translate traffic from 10.0.0.0/8 to the interface address of ethernet1/1. However, traffic from 10.1.1.1 to the internet is not being translated. What is the most likely reason?

Exhibit

Refer to the exhibit.
admin@PA-500# show running config | match nat
...
nat {
    source-nat {
        rule "SNAT-Outside" {
            source [ 10.0.0.0/8 ];
            destination [ any ];
            service [ any ];
            to-interface ethernet1/1;
            source-translation {
                interface-address;
            }
        }
    }
}
Question 17hardmultiple choice
Full question →

Refer to the exhibit. A packet from 10.0.0.5 to 8.8.8.8 on TCP port 443 (HTTPS) arrives. Source zone is trust, destination zone is untrust. The packet is dropped. What is the most likely reason?

Exhibit

admin@firewall> show running rulebase security
entry @name "Allow-Internal" {
    from "trust";
    to "untrust";
    source 10.0.0.0/24;
    destination any;
    application "web-browsing";
    service application-default;
    action allow;
    log-start yes;
}
Question 18hardmultiple choice
Review the full OSPF breakdown →

A security engineer is deploying a new PA-5220 firewall to replace an existing legacy firewall. The environment has complex routing with OSPF and BGP. The engineer configures the firewall with multiple virtual routers: one for the internal network, one for the DMZ, and one for the external connection to two ISPs. The firewall is placed in Layer 3 mode. After the cutover, users report that they can access the internet but internal traffic between two different subnets that are both in the internal virtual router fails to route properly. The engineer checks the routing table on the internal virtual router and sees correct OSPF learned routes. The security policies allow all traffic between those subnets. What is the most likely cause of the routing failure?

Question 19hardmultiple choice
Review the full routing breakdown →

A medium-sized enterprise has a PA-3220 firewall deployed in a data center with two ISPs (ISP-A and ISP-B) for redundancy. The firewall is configured with two virtual routers: VR-Trust for internal networks and VR-Untrust for external connections. Each ISP is connected to a separate physical interface (ethernet1/1 for ISP-A, ethernet1/2 for ISP-B) and both are placed in VR-Untrust with static default routes. The internal network uses 10.0.0.0/16. The firewall has a security policy that allows all outbound traffic from internal to external. Recently, users have reported that internet access is slow during peak hours. The administrator checks the dataplane CPU and sees it averaging 80-90%. The session count is 200,000 out of a maximum of 500,000. The administrator also notices that the firewall is using only ISP-A for all outbound traffic, even though both ISPs have equal bandwidth. The administrator wants to reduce CPU usage and utilize both ISP links. Which action should the administrator take?

Question 20hardmultiple choice
Full question →

An organization uses GlobalProtect for remote access. Users report that they can connect but cannot access internal resources. The firewall logs show that the traffic from the GlobalProtect IP pool to internal servers is allowed. What is the most likely cause?

These PCNSE practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSE questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.