Sample questions
Palo Alto Networks Certified Network Security Engineer PCNSE practice questions
Order the steps to upgrade the PAN-OS software on a standalone firewall.
Which TWO statements are true about TLS version 1.3 support in Palo Alto Networks decryption?
Which TWO of the following are mandatory requirements for forming an active/passive HA pair between two Palo Alto Networks firewalls? (Choose exactly two.)
A security administrator wants to block traffic from IP address 192.168.1.100 to the internet. The firewall has a security policy that allows all outbound traffic. Which action sho…
A large enterprise with 10,000+ users is deploying GlobalProtect with SAML authentication. The IdP is Azure AD. Users report that authentication sometimes fails during peak hours w…
Securing Users and Applications with AuthenticationhardSee the answer and why each option is right or wrong →Which TWO factors should be considered when designing an authentication enforcement strategy? (Choose two.)
Securing Users and Applications with AuthenticationeasySee the answer and why each option is right or wrong →What is the most likely reason the traffic from 192.168.1.100 to 203.0.113.50 is being denied?
An administrator notices that traffic for a known application 'ms-update' is being blocked. The security policy has a rule allowing 'ms-update' from the internal network to the int…
Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?
A large enterprise uses a pair of PA-5250 firewalls in an active/passive high availability configuration to protect their data center. The firewalls are connected to two upstream s…
Managing Troubleshooting and High AvailabilityhardSee the answer and why each option is right or wrong →A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public web…
An administrator configures the management interface with IP 192.168.1.1/24 and can ping it from a host on the same subnet, but cannot access the web interface. What is the likely…
Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?
Which TWO configurations are required on a GlobalProtect portal to enable automatic tunnel configuration for macOS clients? (Choose two.)
A company uses a Palo Alto Networks firewall with Authentication Policy to enforce MFA for external users accessing a web application via GlobalProtect. The authentication sequence…
Securing Users and Applications with AuthenticationmediumSee the answer and why each option is right or wrong →Refer to the exhibit. A user at 10.1.1.10 attempts to access https://www.example.com (port 443). The firewall correctly identifies the application as 'ssl' and matches the rule 'Al…
A multinational corporation uses GlobalProtect with multiple gateways distributed globally for load balancing. The portal has 'Enable Location Awareness' enabled and region mapping…
An engineer checks the application counter and sees that my-custom-app has zero packets, but they expected traffic from 10.0.0.0/24 to 10.1.0.0/24 to be identified as my-custom-app…
A company has a pair of Palo Alto Networks firewalls in active/passive HA. The active firewall manages all traffic. Recently, the network team reconfigured the virtual router by ad…
A cloud-based application is accessed via URL filtering and uses SAML authentication. After a user changes their password in the identity provider (Okta), they are unable to authen…
Securing Users and Applications with AuthenticationmediumSee the answer and why each option is right or wrong →A company recently deployed a Palo Alto Networks PA-5250 firewall in a data center. The firewall is configured with multiple virtual routers and is connected to an MPLS WAN router…
An administrator is configuring SSL Forward Proxy decryption and wants to ensure that traffic to internal servers with self-signed certificates is decrypted, but traffic to externa…
A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)
An administrator wants to ensure that all traffic from the internal network to the internet uses a specific public IP address for source NAT. There are multiple public IP addresses…