Courseiva

PCNSE · topic practice

Manage, Monitor and Operate practice questions

The Manage, Monitor and Operate domain covers day-to-day firewall administration on PAN-OS: generating tech support files, configuring log forwarding, diagnosing resource problems, and making configuration changes like adding zones. Questions are scenario-based, asking you to pick the correct CLI command, required configuration steps, or ordered workflow rather than recite definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage, Monitor and Operate

What the exam tests

What to know about Manage, Monitor and Operate

You must be able to run the correct operational CLI commands, build and apply log forwarding profiles, and diagnose resource issues by cause. The single most important thing: know which command or configuration step actually produces the required outcome, not just its name.

Using the debug command to generate a tech support file for TAC analysis

Configuring log forwarding profiles and applying them to Security policy rules

Identifying causes of high CPU utilization such as logging, decryption, and threat inspection

Ordering zone configuration steps: create zone, assign interfaces, commit

Watch out for

Common Manage, Monitor and Operate exam traps

  • ▸Assuming log forwarding works after only creating a syslog server profile, forgetting to attach the profile to the Security policy rule
  • ▸Confusing the tech support file command with packet capture or session dump commands that do not bundle full diagnostics
  • ▸Blaming high CPU on hardware when management-plane tasks, logging, or content inspection are the actual drivers

Practice set

Manage, Monitor and Operate questions

20 questions · select your answer, then reveal the explanation

A security administrator notices that a specific user is generating excessive logs due to repeated authentication failures. The administrator wants to see only failed authentication events for that user in the monitor tab. Which filter string should be used in the log viewer?

A firewall is configured with two ISPs for redundancy. The administrator wants to ensure that traffic from internal users is load-balanced across both links based on source IP. Which configuration method should be used?

A firewall is deployed in an Active/Passive HA pair. The administrator notices that the passive firewall is not synchronizing configuration changes. The 'show high-availability state' command shows the passive firewall in a 'non-functional' state. What is the most likely cause?

Which TWO of the following are valid methods to upgrade the PAN-OS software on a firewall? (Choose two.)

Which THREE of the following are valid actions that can be taken on a dynamic block list entry? (Choose three.)

Refer to the exhibit. The firewall is experiencing high dataplane CPU usage (85%) with 45,000 active sessions out of a maximum of 100,000. Which of the following is the most likely cause of the high CPU?

Exhibit

Refer to the exhibit.

admin@PA-3020> show session info
Total active sessions: 45000
TCP sessions: 40000
UDP sessions: 5000

admin@PA-3020> show session stats
Max sessions: 100000
Current sessions: 45000

admin@PA-3020> show running resource-monitor
Dataplane CPU: 85%

Refer to the exhibit. The firewall is active in an HA pair, but the peer is non-functional. The HA2 link is down. What is the most likely cause of the peer being non-functional?

Exhibit

Refer to the exhibit.

admin@PA-5250> show high-availability state

HA State: active
HA Link Status:
  HA1: up
  HA2: down
  HA3: down

Peer State: non-functional
Question 8hardmultiple choice
Review the full routing breakdown →

A medium-sized enterprise has a PA-3220 firewall deployed in a data center with two ISPs (ISP-A and ISP-B) for redundancy. The firewall is configured with two virtual routers: VR-Trust for internal networks and VR-Untrust for external connections. Each ISP is connected to a separate physical interface (ethernet1/1 for ISP-A, ethernet1/2 for ISP-B) and both are placed in VR-Untrust with static default routes. The internal network uses 10.0.0.0/16. The firewall has a security policy that allows all outbound traffic from internal to external. Recently, users have reported that internet access is slow during peak hours. The administrator checks the dataplane CPU and sees it averaging 80-90%. The session count is 200,000 out of a maximum of 500,000. The administrator also notices that the firewall is using only ISP-A for all outbound traffic, even though both ISPs have equal bandwidth. The administrator wants to reduce CPU usage and utilize both ISP links. Which action should the administrator take?

A large organization has a PA-5250 firewall pair in active/passive HA mode. The firewalls are managed by Panorama. The security team recently created a new security policy rule to block a specific application (app-block-rule) and pushed the configuration from Panorama. After the push, the active firewall shows the new rule in the security policy list, but traffic matching the rule is not being blocked. The administrator checks the traffic logs and sees that the traffic is being allowed by a different rule with a higher priority. The administrator also notices that the 'app-block-rule' has an 'any' source and destination zone, but the allowed rule has specific zones. The administrator runs 'show session info' and sees that the sessions are being created before the policy push. The administrator wants to ensure that existing sessions are subject to the new policy. Which action should the administrator take?

Match each Palo Alto Networks feature to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Application identification and control

User and group mapping for policies

Threat prevention including IPS and antivirus

Cloud-based malware analysis

Remote access VPN and mobile security

Match each Palo Alto Networks product to its primary use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-generation firewall for enterprise

Virtual firewall for cloud environments

Container firewall for Kubernetes

Cloud-delivered security for remote users

Extended detection and response for endpoints

A network administrator notices that traffic logs are not being sent to the external Syslog server. The log forwarding profile is configured correctly. Which CLI command should be used to verify the Syslog server connectivity from the firewall?

During a Panorama upgrade from version 9.0 to 9.1, the administrator notices that the commit fails on one of the managed firewalls with the error: 'Mismatched content version'. What is the most likely cause?

An administrator needs to generate a tech support file for TAC. Which CLI command accomplishes this?

A firewall is experiencing slow performance. The administrator runs 'show counter global' and sees that the 'flow_aged_error_tcp_mss' counter is incrementing rapidly. What does this indicate?

Which TWO methods can be used to monitor traffic passing through a Palo Alto Networks firewall?

Which THREE steps should be performed when upgrading an active/passive HA pair to a new PAN-OS version?

A network engineer needs to configure SNMP traps on a PA-5250 running PAN-OS 10.2 to alert when CPU usage exceeds 80% for more than 10 minutes. Which CLI command should be used to set this threshold?

An administrator wants to see only the candidate configuration changes that have not yet been committed. Which CLI command should be used?

An engineer notices a decrease in network performance and wants to verify if a specific security policy is being triggered frequently. Which CLI command will show the hit count for a specific policy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage, Monitor and Operate sessions

Start a Manage, Monitor and Operate only practice session

Every question in these sessions is drawn from the Manage, Monitor and Operate domain — nothing else.

Related practice questions

Related PCNSE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSE exam test about Manage, Monitor and Operate?
You must be able to run the correct operational CLI commands, build and apply log forwarding profiles, and diagnose resource issues by cause. The single most important thing: know which command or configuration step actually produces the required outcome, not just its name.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage, Monitor and Operate questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage, Monitor and Operate domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSE topics?
Use the topic links above to move to related areas, or go back to the PCNSE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSE exam covers. They are not copied from any real exam or dump site.