PCNSE Deploy and Configure Firewalls Practice Question
Which TWO actions should be taken when deploying a Palo Alto Networks firewall in a branch office to ensure secure and efficient operation? (Choose two.)
⚠ Common exam trap
Many exam-takers think default NAT policies are acceptable for branch offices or that manual updates are more reliable, but the PCNSE exam emphasizes automation and security best practices, making options D and E incorrect due to their lack of scalability and security posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Threat Prevention profiles to block known malware
Enabling Threat Prevention profiles (A) is correct because it applies IPS signatures to block known malware, exploits, and vulnerabilities inline, which is essential for branch office security without requiring constant manual intervention. Configuring logging for all traffic (B) is correct because it provides visibility for monitoring, troubleshooting, and compliance, and is necessary for effective use of features like ACC and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Threat Prevention profiles to block known malware
Why this is correct
Branch traffic traverses the firewall to reach the internet, so attaching Threat Prevention profiles to the relevant security rules inspects that traffic and drops known malware and vulnerability exploits. This satisfies the requirement to secure the branch against external threats at the enforcement point.
- ✓
Configure logging for all traffic to enable monitoring and troubleshooting
Why this is correct
Forwarding all session logs to a log collector or Panorama gives visibility into permitted and denied traffic, enabling monitoring and retrospective troubleshooting of branch incidents. This satisfies the efficient-operation requirement by providing the audit trail needed to diagnose connectivity and policy issues.
- ✗
Leave the default admin password until the next audit
Why it's wrong here
Leaving the default admin password exposes the firewall to trivial compromise, violating secure deployment. It is tempting because it defers configuration effort, and would be correct only if the password were changed immediately during initial setup before connecting the device to any network.
- ✗
Use the default NAT policies provided by the initial configuration
Why it's wrong here
Default NAT policies exist only to translate the untrust zone to the internet for management traffic; they do not provide the outbound source NAT or inbound destination NAT rules a branch requires. They are tempting because they ship pre-configured and work for basic internet access, which is the correct choice only for a lab firewall with no internal servers.
- ✗
Manually download dynamic updates daily to ensure latest signatures
Why it's wrong here
Dynamic updates are retrieved automatically from Palo Alto Networks update servers; manual daily downloads add effort without benefit. It is tempting because staying current on signatures matters, and would be correct in air-gapped environments where automatic updates are impossible and offline packages must be imported.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.