Courseiva
Back to Palo Alto Networks Certified Network Security Engineer PCNSE questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Palo Alto Networks Certified Network Security Engineer PCNSE practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
PCNSE
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related PCNSE topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which TWO statements are true about TLS version 1.3 support in Palo Alto Networks decryption?

Question 2mediummulti select
Full question →

Which TWO of the following are mandatory requirements for forming an active/passive HA pair between two Palo Alto Networks firewalls? (Choose exactly two.)

Question 3easymulti select
Full question →

Which TWO factors should be considered when designing an authentication enforcement strategy? (Choose two.)

Question 4easymulti select
Full question →

Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?

Question 5hardmulti select
Full question →

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

Question 6easymulti select
Full question →

Which TWO configurations are required on a GlobalProtect portal to enable automatic tunnel configuration for macOS clients? (Choose two.)

A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)

Question 8mediummulti select
Full question →

Which TWO of the following are prerequisites for configuring high availability on Palo Alto Networks firewalls? (Choose two.)

Question 9hardmulti select
Full question →

Which THREE are common causes of high CPU utilization on a Palo Alto Networks firewall? (Choose three.)

Question 10hardmulti select
Full question →

An administrator is troubleshooting low throughput for a business-critical application that is identified as web-browsing instead of the custom app. The firewall is in inline mode. Which THREE potential causes should be investigated?

Question 11hardmulti select
Full question →

Based on the exhibit, which THREE conclusions can be drawn?

Exhibit

Refer to the exhibit.
```
admin@PA-5250> show session id 12345
Session ID: 12345
  Source IP: 10.10.1.100
  Destination IP: 203.0.113.50
  Source port: 34567
  Destination port: 443
  Ingress interface: ethernet1/2
  Egress interface: ethernet1/3
  NAT source IP: 192.0.2.100
  NAT destination IP: 203.0.113.50
  Protocol: TCP
  State: ACTIVE
  Type: FLOW
  Policy ID: 4
  Application: ssl
  Rule: allow-ssl
  User: unknown
```
Question 12easymulti select
Read the full VPN explanation →

Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?

Question 13easymulti select
Full question →

Which TWO methods can be used to export logs from Panorama to an external system? (Choose two.)

Question 14hardmulti select
Full question →

Which THREE factors are considered when a Palo Alto Networks firewall performs application identification (App-ID) on a session? (Choose three.)

Question 15hardmulti select
Full question →

A security engineer is investigating a potential data exfiltration incident. The firewall logs show that a host in the DMZ made outbound connections to multiple external IPs on port 443, but the traffic was allowed. The engineer wants to review detailed session information including the amount of data transferred and the application used. Which three log types or tools should the engineer use? (Choose three.)

Question 16hardmulti select
Full question →

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

Question 17mediummulti select
Full question →

Which TWO actions can help App-ID correctly identify a custom application that communicates over TCP port 8443 using SSL/TLS with a known internal hostname?

Question 18hardmulti select
Full question →

Which two are prerequisites for deploying a Palo Alto Networks firewall in a high-availability active/passive pair? (Choose two.)

Question 19mediummulti select
Full question →

Which TWO of the following are minimum required configurations to enable User-ID on a Palo Alto Networks firewall? (Choose exactly two.)

Question 20easymulti select
Full question →

A security administrator needs to block an application that uses multiple ports, including dynamic ports. Which of the following methods can be used to block this application using App-ID? (Choose two.)

These PCNSE practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSE questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.