Courseiva
← Back to Palo Alto Networks Certified Network Security Engineer PCNSE questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Palo Alto Networks Certified Network Security Engineer PCNSE practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
PCNSE
exam code
Palo Alto Networks
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related PCNSE topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. What does the 'Session End Reason: aged-out' indicate about the traffic?

Exhibit

# Timestamp: 2020-07-10 12:34:56
# Source IP: 10.0.0.1
# Destination IP: 203.0.113.2
# Application: ssl
# Action: allow
# Session End Reason: aged-out
# Bytes In: 5000
# Bytes Out: 12000
Question 2hardmultiple choice
Full question →

Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?

Exhibit

2025/03/15 10:30:45,drop,203.0.113.10,10.1.1.200,https,443,trust,untrust,deny-rule,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any
Question 3hardmultiple choice
Full question →

Refer to the exhibit. Based on the log, what triggered the failover?

Exhibit

Refer to the exhibit.

2019-03-15 10:30:15.123 high-availability: HA state change from active to passive (reason: path-monitor-group-down)
2019-03-15 10:30:15.124 high-availability: Path monitoring group 'ISP1' failed: 0 out of 1 destinations reachable
Question 4mediummultiple choice
Full question →

Refer to the exhibit. Which SSL protocol version is blocked as per this decryption profile?

Exhibit

decryption profile:
  name: 'Decrypt-All'
  ssl-decryption:
    minimum-protocol-version: tls1-0
    maximum-protocol-version: tls1-2
    allow-block tls1-0
    block tls1-1
    allow tls1-2
Question 5mediummultiple choice
Full question →

Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?

Exhibit

Refer to the exhibit.
```
> show ssl-decrypt statistics

SSL Decryption Statistics
Total sessions decrypted: 45032
Total sessions bypassed: 2341
Bypass reasons:
  unsupported cipher: 1200
  certificate validation failure: 800
  handshake failure: 341
Currently active sessions: 105
```
Question 6mediummultiple choice
Full question →

The security policy rule shown in the exhibit has log-start and log-end both set to 'no', but a log-forwarding profile is configured. Which statement best describes the logging behavior for sessions matching this rule?

Exhibit

Refer to the exhibit.
admin@PA-500> show running security-policy
rule 1: name "Allow-Outbound" from "Internal" to "External" source "10.0.0.0/8" destination "any" application "any" service "any" action "allow" log-start "no" log-end "no" log-forward "Log-to-Panorama"
Question 7easymultiple choice
Full question →

Refer to the exhibit. The firewall's disk usage is at 85% overall, and the /opt/panlogs partition is at 92%. The administrator wants to free up space without losing important log data. Which action should be taken first?

Exhibit

Refer to the exhibit.

admin@PA-5000> show system resources
CPU: 15% used
Memory: 45% used
Disk: /dev/sda1 85% used

admin@PA-5000> show logging-status
Disk space usage:
  /opt/pancfg: 70% used
  /opt/panlogs: 92% used
Question 8easymultiple choice
Full question →

Refer to the exhibit. A firewall system log contains a critical license expiration entry for URL Filtering. What will happen to URL Filtering functionality?

Exhibit

system log:
2019-03-15 14:23:45, severity: critical, module: license, description: License for URL Filtering has expired.
Question 9hardmultiple choice
Full question →

Refer to the exhibit. What happens when a user with an unknown identity (source-user unknown) tries to access resources in 192.168.1.0/24?

Exhibit

authentication-policy {
    rules {
        "require-auth" {
            match {
                source-user "unknown"
                destination-address "192.168.1.0/24"
            }
            action allow-authentication
            authentication-profile "SAML-Auth"
        }
    }
}
Question 10hardmultiple choice
Full question →

The firewall is in passive state. The network team reports that during a recent maintenance window, the active firewall lost its upstream link but the passive firewall did not take over. Based on the exhibit, what is the most likely reason?

Exhibit

Refer to the exhibit.
```
admin@PA-5050> show high-availability state

Local:
  mode: active-passive
  state: passive
  link monitoring: enabled
  path monitoring: disabled
  monitor fail-holdup: 0
  HA1 link status: up
  HA2 link status: down

Peer:
  mode: active-passive
  state: active
  link monitoring: enabled
  path monitoring: disabled
  monitor fail-holdup: 0

Group state: complete
```
Question 11easymultiple choice
Full question →

Refer to the exhibit. Which configuration is required in the authentication profile 'SAML-Auth'?

Exhibit

portal "Corporate-Portal" {
    authentication-profile "SAML-Auth"
    ...
}
Question 12hardmultiple choice
Full question →

Refer to the exhibit. An administrator notices that HTTPS traffic to a specific website is being denied. What is the most likely cause?

Exhibit

user@fw> show running security-policy
rule 1: name "Allow-Web" from trust to untrust source any destination any application web-browsing service application-default action allow
rule 2: name "Allow-SSL" from trust to untrust source any destination any application ssl service application-default action allow
rule 3: name "Block-Other" from trust to untrust source any destination any application any service any action deny log-start
rule 4: name "Allow-All" from trust to trust source any destination any application any service any action allow
Question 13mediummultiple choice
Full question →

Refer to the exhibit. An engineer configures HA with link monitoring and path monitoring. However, failover does not occur when ethernet1/2 goes down. What is the likely reason?

Exhibit

Refer to the exhibit.

config shared {
    high-availability {
        mode active-passive;
        group-id 10;
        state-synchronization enable;
        link-monitoring {
            interfaces [ ethernet1/1 ethernet1/2 ];
            failure-condition any;
        }
        path-monitoring {
            enable yes;
            groups {
                group1 {
                    source-ip 10.0.0.1;
                    destination-ip [ 10.0.0.254 ];
                    interval 5;
                    threshold 10;
                }
            }
        }
    }
}
Question 14mediummultiple choice
Full question →

Refer to the exhibit. A user at 10.1.1.10 is trying to connect to a web server at 203.0.113.5 on port 443. The session shows 'State: DROP' with reason 'policy-deny'. However, the administrator has a security policy rule that allows SSL traffic from the source zone to the destination zone. What is the most likely cause of the drop?

Exhibit

show session id 12345
Session 12345: 10.1.1.10:50000 -> 203.0.113.5:443 (10.1.1.10:50000 -> 203.0.113.5:443)
Application: ssl	State: DROP	Type: FLOW
Reason: policy-deny	Flags: 0x40000000
NAT: source 10.1.1.10:50000 (no NAT)
Question 15mediummultiple choice
Full question →

Refer to the exhibit. A user in the trust zone attempts to access HTTPS to an external server. Which rule will match?

Exhibit

admin@PA-500> show running security-policy
1.  rule1  (src: trust; dst: untrust; app: web-browsing; action: allow)
2.  rule2  (src: trust; dst: untrust; user: anyone; app: ssl; action: allow)
3.  rule3  (src: trust; dst: untrust; user: user1; app: any; action: deny)
4.  rule4  (src: trust; dst: untrust; user: anyone; app: any; action: deny)

These PCNSE practice questions are part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style PCNSE questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.