Courseiva
Back to Palo Alto Networks Certified Network Security Engineer PCNSE questions

Scenario-based practice

Hard Difficulty Questions

Practise Palo Alto Networks Certified Network Security Engineer PCNSE practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PCNSE
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PCNSE topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which TWO statements are true about TLS version 1.3 support in Palo Alto Networks decryption?

Question 2hardmultiple choice
Full question →

A large enterprise with 10,000+ users is deploying GlobalProtect with SAML authentication. The IdP is Azure AD. Users report that authentication sometimes fails during peak hours with error 'SAML response timeout'. Which design change would most effectively address this issue?

Question 3hardmultiple choice
Full question →

A large enterprise uses a pair of PA-5250 firewalls in an active/passive high availability configuration to protect their data center. The firewalls are connected to two upstream switches via aggregate Ethernet (AE) interfaces. The network team recently replaced the upstream switches, and since then, the passive firewall has gone into a 'non-functional' state. The active firewall shows no issues. The HA1 link is a direct cable connection between the firewalls, and HA2 is an out-of-band dedicated link. The administrative status of both firewalls is 'active-active' in the HA monitoring, but only one firewall is actually forwarding traffic. The team needs to restore proper HA operation. Which action should the team take first?

Question 4hardmulti select
Full question →

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Question 5hardmultiple choice
Full question →

Refer to the exhibit. A user at 10.1.1.10 attempts to access https://www.example.com (port 443). The firewall correctly identifies the application as 'ssl' and matches the rule 'Allow-SSL'. However, the session is still being denied. What is the most likely reason?

Exhibit

config shared
security-rulebase
 security-rules
  rule "Allow-SSL"
   from [ "Trust-L3" ]
   to [ "Untrust-L3" ]
   source [ "10.0.0.0/8" ]
   destination [ "any" ]
   application [ "ssl" ]
   service [ "application-default" ]
   action allow
   log-start no
   log-end yes
   log-setting "Profile1"
 end-rule
  rule "Block-HTTP"
   from [ "Trust-L3" ]
   to [ "Untrust-L3" ]
   source [ "10.0.0.0/8" ]
   destination [ "any" ]
   application [ "web-browsing" ]
   service [ "application-default" ]
   action deny
   log-start no
   log-end yes
 end-rule
end
config shared
 application-group "Web-Apps"
  members [ "ssl" "web-browsing" ]
 end-application-group
end
Question 6hardmultiple choice
Full question →

An administrator is configuring SSL Forward Proxy decryption and wants to ensure that traffic to internal servers with self-signed certificates is decrypted, but traffic to external banking sites is excluded from decryption. They have created a decryption policy with two rules: first rule with 'No Decrypt' for the external banking URLs, second rule with 'Decrypt' for all other traffic. However, the banking traffic is still being decrypted. What is the most likely issue?

Question 7hardmulti select
Full question →

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Question 8hardmulti select
Full question →

An administrator is troubleshooting low throughput for a business-critical application that is identified as web-browsing instead of the custom app. The firewall is in inline mode. Which THREE potential causes should be investigated?

Question 9hardmulti select
Full question →

Based on the exhibit, which THREE conclusions can be drawn?

Exhibit

Refer to the exhibit.
```
admin@PA-5250> show session id 12345
Session ID: 12345
  Source IP: 10.10.1.100
  Destination IP: 203.0.113.50
  Source port: 34567
  Destination port: 443
  Ingress interface: ethernet1/2
  Egress interface: ethernet1/3
  NAT source IP: 192.0.2.100
  NAT destination IP: 203.0.113.50
  Protocol: TCP
  State: ACTIVE
  Type: FLOW
  Policy ID: 4
  Application: ssl
  Rule: allow-ssl
  User: unknown
```
Question 10hardmultiple choice
Full question →

A financial institution operates a pair of PA-5260 firewalls in active/active HA using Virtual Wire mode. They are experiencing intermittent asymmetric traffic flows causing session setup failures. The firewall logs show sessions being created with a one-sided flow. Which configuration change is most likely to resolve this issue?

Question 11hardmulti select
Full question →

Which THREE factors are considered when a Palo Alto Networks firewall performs application identification (App-ID) on a session? (Choose three.)

Question 12hardmulti select
Full question →

A security engineer is investigating a potential data exfiltration incident. The firewall logs show that a host in the DMZ made outbound connections to multiple external IPs on port 443, but the traffic was allowed. The engineer wants to review detailed session information including the amount of data transferred and the application used. Which three log types or tools should the engineer use? (Choose three.)

Question 13hardmultiple choice
Full question →

A firewall is configured with multiple virtual systems (vsys). The administrator notices that one vsys is consuming excessive dataplane resources, affecting others. Which feature should be used to guarantee each vsys a minimum share of CPU and session capacity?

Question 14hardmulti select
Full question →

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

Question 15hardmultiple choice
Review the full subnetting walkthrough →

A firewall administrator notices that traffic from a specific subnet is being unexpectedly dropped. The firewall log shows a 'flow_drop' reason of 'packet too long for interface MTU'. The interface MTU is set to 1500, and the packets are 1500 bytes. What is the most likely cause?

Question 16hardmultiple choice
Full question →

Two Palo Alto Networks firewalls are configured in an active/passive HA pair. During a scheduled maintenance, the network team reboots both firewalls simultaneously. After reboot, both firewalls appear as 'active' in the HA state. What is the most likely cause and the correct troubleshooting step?

Question 17hardmultiple choice
Full question →

A security architect needs to enforce authentication for all application-based policies using an external authentication source with MFA. Which combination of features best achieves this?

Question 18hardmultiple choice
Full question →

After configuring SAML authentication for GlobalProtect, users report they are repeatedly prompted for credentials even though they already authenticated via the IdP. The firewall logs show 'saml-auth-success' but the portal log shows 'user-login-failure: invalid saml assertion'. What is the most likely cause?

Question 19hardmultiple choice
Read the full VPN explanation →

Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?

Exhibit

Refer to the exhibit.

show vpn gateway

Name: Corp-GW
Peer IP: 203.0.113.1
Local IP: 198.51.100.1
IKE version: IKEv2
Pre-shared key: ****
IKE crypto profile: default
DPD: enabled

show vpn tunnel

Name: Corp-Tun
Tunnel interface: tunnel.1
Type: IPSec
IKE gateway: Corp-GW
IPSec crypto profile: default
Proxy IDs: local 10.0.0.0/16, remote 172.16.0.0/16

show routing route

Destination: 172.16.0.0/16
Next hop: tunnel.1
Metric: 10

show interface tunnel.1

Interface: tunnel.1
Zone: VPN-Zone
Virtual router: default
Question 20hardmultiple choice
Full question →

A large enterprise has deployed two Palo Alto Networks PA-5250 firewalls in active/passive HA mode with Panorama for centralized management. The network contains over 10,000 users across multiple sites. Recently, the security team deployed a new security policy rule to block a set of high-risk applications. After the commit, the firewall's CPU utilization spiked to 95% and sessions started to drop intermittently. The firewall logs show a high number of session setup failures and timeouts. The existing security policy contains over 5,000 rules. The new rule uses application-based filtering and is placed near the top of the rulebase. What is the most effective course of action to reduce CPU load while maintaining security?

These PCNSE practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSE questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.