Courseiva

PCNSE · topic practice

Troubleshoot practice questions

The Troubleshoot domain (11%) covers diagnosing PAN-OS and Panorama issues: traffic flow failures, GlobalProtect connectivity, decryption problems, and commit or HA errors. The exam presents scenario-based questions asking you to identify the root cause from CLI output, logs, or GUI state, then select the correct diagnostic command or fix.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Troubleshoot

What the exam tests

What to know about Troubleshoot

Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.

Reading 'show session all filter' and 'test security-policy-match' output to trace dropped traffic

Using 'show system logdb-quota' and log forwarding to isolate logging pipeline failures

Diagnosing GlobalProtect tunnel failures via 'show global-protect-gateway statistics' and gateway logs

Interpreting HA state with 'show high-availability state' and resolving split-brain or suspended peers

Watch out for

Common Troubleshoot exam traps

  • ▸Assuming a commit succeeded without checking 'show jobs all' for partial or failed commits on managed firewalls
  • ▸Confusing flow ownership in active/active HA, so session lookups run on the wrong peer and show no data
  • ▸Blaming the firewall for app failures when the real cause is a decryption profile or SSL forward proxy exclusion

Practice set

Troubleshoot questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Review the full subnetting walkthrough →

An engineer is troubleshooting a case where users on a specific subnet cannot reach a web server behind a Palo Alto Networks firewall. The security policy allows the traffic, and the firewall sees the session hit the rule. However, the server does not receive the request. What is the most likely cause?

Question 2mediummultiple choice
Read the full Troubleshoot explanation →

A company deploys a new application that uses UDP on port 12345. The security policy is configured to allow UDP traffic from the internal network to the application server. However, users report that the application does not work. The firewall logs show that the traffic is allowed. What is the most likely cause?

Question 3hardmultiple choice
Read the full Troubleshoot explanation →

An engineer is troubleshooting an issue where GlobalProtect users are unable to connect to the portal. The portal is configured with a certificate signed by an internal CA. Users can reach the portal's IP address from the internet, but the connection fails. The firewall log shows 'TLS handshake failed'. What is the most likely cause?

Question 4mediummultiple choice
Read the full Troubleshoot explanation →

After upgrading a Palo Alto Networks firewall, the administrator notices that some URL filtering categories are not being blocked as configured. The URL filtering profile is applied to the security rule. What should the administrator verify first?

Question 5mediummulti select
Read the full Troubleshoot explanation →

Which TWO troubleshooting steps should be performed when a user cannot access an internal server through a Palo Alto Networks firewall, and the traffic log shows that the session was dropped by a security rule?

Question 6mediummultiple choice
Read the full Troubleshoot explanation →

Refer to the exhibit. A user at 10.1.1.100 is browsing the internet. The session is established. However, the user reports that the page is not loading completely. What could be the issue?

Exhibit

admin@PA-5000> show session id 12345
Session ID: 12345
Source IP: 10.1.1.100
Destination IP: 203.0.113.50
Application: web-browsing
State: ESTABLISHED
From Zone: trust
To Zone: untrust
Rule: allow-web
Question 7hardmultiple choice
Review the full subnetting walkthrough →

A large organization uses GlobalProtect for remote access. Users report that they can connect to the portal and download the client, but the client fails to establish a tunnel after connecting. The firewall's GlobalProtect gateway is configured with an authentication profile that uses LDAP. The gateway is configured to use an internal IP pool. The administrator checks the GlobalProtect logs and sees that the user authenticates successfully, but the gateway fails to assign an IP address. The IP pool is configured with a range of 10.10.10.100-10.10.10.200. The administrator verifies that there are no other devices using those IPs. The gateway is on a different subnet than the IP pool. What is the most likely cause?

Question 8mediummultiple choice
Review the full subnetting walkthrough →

A security administrator notices that traffic logs are not being generated for allowed traffic from a specific subnet. The security policy rule for that subnet has 'Log at Session End' enabled. What should the engineer check?

Question 9hardmultiple choice
Read the full Troubleshoot explanation →

In an active/passive HA pair, the passive firewall shows state 'non-functioning'. Both firewalls are running PAN-OS 10.1.5. What is the most likely cause?

Question 10mediummultiple choice
Read the full Troubleshoot explanation →

A company is using GlobalProtect for remote access. Users report that they can connect but cannot access internal resources. The firewall logs show successful GlobalProtect tunnel establishment. What is the most likely issue?

Question 11hardmultiple choice
Read the full Troubleshoot explanation →

A firewall is experiencing high CPU utilization. The engineer suspects a denial-of-service attack. Which command should be used to identify the source of the attack?

Question 12mediummultiple choice
Read the full Troubleshoot explanation →

A user reports that they cannot access a website. The firewall logs show the session was denied with 'No rule matched'. The security policy has a rule that should match the traffic. What is the most likely cause?

Question 13hardmultiple choice
Read the full Troubleshoot explanation →

A firewall has a security policy that includes a rule with a 'Schedule' object. During the scheduled time, traffic should be allowed, but it is being blocked. The schedule is configured correctly. What could be the issue?

Question 14mediummulti select
Read the full Troubleshoot explanation →

Which TWO are common causes of session drops after the initial handshake? (Choose two.)

Question 15mediummultiple choice
Read the full Troubleshoot explanation →

Refer to the exhibit. The session is in FIN_WAIT state. What does this indicate about the TCP connection?

Exhibit

Refer to the exhibit.

---
> show session id 12345
Session ID: 12345
Source IP: 10.1.1.100
Destination IP: 192.168.2.50
Source Port: 34567
Destination Port: 80
Protocol: TCP
State: FIN_WAIT
Application: ssl
NAT Source: 10.1.1.100
NAT Destination: 192.168.2.50
---
Question 16mediummultiple choice
Read the full Troubleshoot explanation →

A user reports that they cannot access a specific website. Traffic matches a security policy rule that allows the application 'web-browsing' but the session is being dropped. Which of the following is the most likely cause?

Question 17easymultiple choice
Read the full Troubleshoot explanation →

After upgrading Panorama to a newer version, a configuration push to a managed firewall fails with the error 'Commit failed: template validation error.' Which of the following should be checked first?

Question 18hardmultiple choice
Read the full Troubleshoot explanation →

An organization uses SSL Forward Proxy decryption for all web traffic. A user reports intermittent connectivity issues to a SaaS application. The firewall shows no drops or errors. Which of the following is the most likely cause?

Question 19mediummultiple choice
Read the full Troubleshoot explanation →

A security policy rule is configured to deny traffic, but no logs are generated when the traffic is denied. Which of the following is the most likely reason?

Question 20hardmultiple choice
Read the full Troubleshoot explanation →

A Panorama-managed firewall is not sending logs to Panorama. The firewall is operational and policies are being pushed successfully. Which of the following is the most likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Troubleshoot sessions

Start a Troubleshoot only practice session

Every question in these sessions is drawn from the Troubleshoot domain — nothing else.

Related practice questions

Related PCNSE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSE exam test about Troubleshoot?
Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Troubleshoot questions in a focused session?
Yes — the session launcher on this page draws every question from the Troubleshoot domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSE topics?
Use the topic links above to move to related areas, or go back to the PCNSE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSE exam covers. They are not copied from any real exam or dump site.