Courseiva

PCNSE · topic practice

Core Concepts and Architecture practice questions

Core Concepts and Architecture covers the PAN-OS dataplane and control plane: security zones, virtual routers and virtual systems, interface types, session setup and teardown, and management-plane access. Questions are scenario-based exhibits showing session details, routing between virtual routers, or management interface reachability, requiring you to identify the specific PAN-OS component or setting responsible.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Core Concepts and Architecture

What the exam tests

What to know about Core Concepts and Architecture

Be able to read session details and map each end reason to its cause, trace traffic between virtual routers, and verify management interface services and profiles. The single most important thing: know that aged-out is a normal timeout, not a block.

Session end reasons such as aged-out, policy-deny, and tcp-fin in the session details view

Inter-virtual-router routing between VR1 and VR2 via shared interfaces or static routes

Management interface access requiring permitted services (HTTPS, SSH, ping) on the management profile

Security zone and interface configuration for Layer 2, Layer 3, virtual wire, and tunnel modes

Watch out for

Common Core Concepts and Architecture exam traps

  • ▸Assuming aged-out means the session was denied by policy; it actually means the session timed out after inactivity and is normal traffic behavior.
  • ▸Believing two virtual routers exchange routes automatically; traffic between VRs needs explicit routes or an inter-VR path, not just shared subnets.
  • ▸Forgetting that the management interface needs an allowed service in its management profile before HTTPS or SSH access works, even when ping succeeds.

Practice set

Core Concepts and Architecture questions

20 questions · select your answer, then reveal the explanation

An organization wants to simplify firewall rule management by grouping related rules into logical units and applying them to specific sets of users or devices. Which Palo Alto Networks feature supports this requirement?

Question 2hardmultiple choice
Review the full routing breakdown →

A Palo Alto Networks firewall is configured with two virtual routers: VR-A (trust) and VR-B (untrust). An interface is placed in VR-A. A static route to 10.0.0.0/8 via next-hop 192.168.1.1 exists in VR-A. The firewall receives a packet from the trust zone destined to 10.1.1.1. The route lookup succeeds in VR-A. Which statement is true about the forwarding decision?

Question 3mediummultiple choice
Review the full routing breakdown →

A firewall has the routing table shown. A packet arrives on ethernet1/2 with source IP 10.0.0.50 and destination IP 10.0.0.100. Which route will be used for forwarding?

Exhibit

Refer to the exhibit.

```
admin@PA-5050> show routing route

IPv4 Virtual Router: default

destination nexthop interface metric flags
0.0.0.0/0 10.0.0.1 ethernet1/1 10 A S
10.0.0.0/8 10.0.0.1 ethernet1/1 10 A S
10.0.0.0/24 10.0.0.2 ethernet1/2 10 A S
10.0.1.0/24 10.0.0.3 ethernet1/3 10 A S
172.16.0.0/12 10.0.0.4 ethernet1/4 10 A S
192.168.0.0/16 10.0.0.5 ethernet1/5 10 A S
```

An administrator runs the commands and sees the output. The session shows an SSL application from trust to untrust. However, the traffic is actually a custom application over TCP 44321 that the firewall incorrectly identifies as SSL. Which configuration step will most accurately identify the custom application?

Exhibit

Refer to the exhibit.

```
admin@PA-3020> show session info

session id 12345, application: ssl, vsys vsys1, zone trust->untrust
source 10.1.1.10:443 -> destination 192.168.1.1:44321
state: active, type: dynamic
session age: 120 sec, timeout: 3600 sec

admin@PA-3020> show system info | match uptime
Uptime: 30 days, 4 hours, 12 minutes
```

Which TWO are valid dataplane components in a Palo Alto Networks firewall? (Choose two.)

Which THREE factors are considered when a Palo Alto Networks firewall performs application identification (App-ID) on a session? (Choose three.)

A company runs a mixed environment of physical and virtual Palo Alto Networks firewalls (PA-5250, VM-300) managed by a single Panorama. The company recently deployed a new application that uses the QUIC protocol (UDP 443) for performance. After the deployment, the security team notices that the firewall is not accurately identifying the QUIC traffic, and some QUIC sessions are being dropped unexpectedly. The firewall logs show 'application: incomplete' for these sessions. The security team wants to ensure QUIC traffic is properly identified and allowed. The team has configured a security policy rule to allow 'ssl' application (thinking QUIC is similar to SSL) but the problem persists. The firewall is running PAN-OS 10.1. Which of the following is the best course of action?

Refer to the exhibit. A firewall administrator is investigating why traffic from a source IP 10.1.1.100 to destination 192.168.1.50 is not establishing sessions. The firewall has been up for 45 days. Based on the counters shown, what is the most likely cause?

Exhibit

Refer to the exhibit.

admin@PA-5050> show system info | match uptime
Uptime: 45 days 3 hours 22 mins

admin@PA-5050> show session all filter source 10.1.1.100 destination 192.168.1.50
Session filter returned 0 sessions

admin@PA-5050> show counter global | match flow_tcp_non_syn
flow_tcp_non_syn: 15

admin@PA-5050> show counter global | match flow_tcp_handshake_fail
flow_tcp_handshake_fail: 8
Question 9mediummultiple choice
Read the full MPLS explanation →

A company recently deployed a Palo Alto Networks PA-5250 firewall in a data center. The firewall is configured with multiple virtual routers and is connected to an MPLS WAN router and an internet router. The network team reports that users can access internet resources but cannot reach a critical application hosted in a remote branch office over the MPLS link. The application uses TCP port 443 and is accessed via a fully qualified domain name (FQDN). The security policy includes a rule that allows traffic from the internal zone to the MPLS zone with the application 'ssl' and the destination address set to the FQDN of the application server. The internal DNS server resolves the FQDN correctly to the private IP address 10.20.30.40. The firewall has DNS proxy enabled, but the DNS server is configured as the internal DNS server. The administrator runs a packet capture and sees that the firewall is sending DNS queries for the FQDN to the internal DNS server but the response is not being used to update the dynamic address group (DAG) that is referenced in the security policy. The DAG is configured with a 'FQDN' match criteria. What is the most likely cause?

A security administrator is troubleshooting a traffic drop between two internal zones. The firewall shows that the session is being terminated with a 'tcp-fin' reason. The administrator verifies that the application is set to 'web-browsing' and the service is 'application-default'. What is the most likely cause of the session termination?

An organization is deploying a pair of PA-5250 firewalls in active/passive high availability. The network team notices that the passive firewall is not receiving synchronization updates. Both devices have the same software version and licenses. The HA1 control link is connected and shows 'up' in 'show high-availability state'. What is the most likely reason for the synchronization failure?

A network engineer is configuring a new PA-220 firewall. They need to allow HTTP traffic from the 'trust' zone to the 'untrust' zone. However, the traffic is being dropped. A packet capture shows that the SYN packet is received but no SYN-ACK is sent. What is the most likely cause?

Match each log type to its content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Records session start, end, and bytes transferred

Logs blocked malware, exploits, or spyware

Logs web requests and category matches

Tracks files sent for cloud analysis

Records administrative actions and system events

An administrator notices that traffic from zone A to zone B is being dropped silently. Security rules are in place. Troubleshooting shows that the session does not appear in the session table. What is the most likely cause?

An organization wants to map user identity from Active Directory for traffic coming from internal LAN users without installing any agent on domain controllers. Which User-ID mapping method should be used?

A firewall's dataplane CPU is consistently at 95% utilization even though session count is normal. Analysis shows that a large number of small packets are being processed. Which feature could be causing excessive dataplane processing?

Question 17mediummultiple choice
Review the full routing breakdown →

In an active/passive high-availability pair, the firewall fails over unexpectedly. Investigation shows that the active unit lost connectivity to the upstream router but the link is still up. Which monitoring feature should be configured to prevent false failovers due to temporary router unreachability?

Which THREE are valid methods for User-ID mapping in PAN-OS?

Refer to the exhibit. A packet from 10.0.0.5 to 8.8.8.8 on TCP port 443 (HTTPS) arrives. Source zone is trust, destination zone is untrust. The packet is dropped. What is the most likely reason?

Exhibit

admin@firewall> show running rulebase security
entry @name "Allow-Internal" {
    from "trust";
    to "untrust";
    source 10.0.0.0/24;
    destination any;
    application "web-browsing";
    service application-default;
    action allow;
    log-start yes;
}

Refer to the exhibit. An administrator sees this log entry. What does it indicate?

Exhibit

2019/10/15 14:23:45, drop, 192.168.1.10, 10.0.0.1, any, 0, (no rule), drop, session end reason: no-match

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Core Concepts and Architecture sessions

Start a Core Concepts and Architecture only practice session

Every question in these sessions is drawn from the Core Concepts and Architecture domain — nothing else.

Related practice questions

Related PCNSE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSE exam test about Core Concepts and Architecture?
Be able to read session details and map each end reason to its cause, trace traffic between virtual routers, and verify management interface services and profiles. The single most important thing: know that aged-out is a normal timeout, not a block.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Core Concepts and Architecture questions in a focused session?
Yes — the session launcher on this page draws every question from the Core Concepts and Architecture domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSE topics?
Use the topic links above to move to related areas, or go back to the PCNSE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSE exam covers. They are not copied from any real exam or dump site.