Palo Alto Networks PCNSE Palo Alto Networks Certified Network Security Engineer Exam Online Training
Palo Alto Networks PCNSE Online Training
The questions for PCNSE were last updated at Apr 22,2025.
- Exam Code: PCNSE
- Exam Name: Palo Alto Networks Certified Network Security Engineer Exam
- Certification Provider: Palo Alto Networks
- Latest update: Apr 22,2025
Which statement regarding HA timer settings is true?
- A . Use the Recommended profile for typical failover timer settings
- B . Use the Moderate profile for typical failover timer settings
- C . Use the Aggressive profile for slower failover timer settings.
- D . Use the Critical profile for faster failover timer settings.
A company has configured a URL Filtering profile with override action on their firewall.
Which two profiles are needed to complete the configuration? (Choose two)
- A . SSL/TLS Service
- B . HTTP Server
- C . Decryption
- D . Interface Management
A company has recently migrated their branch office’s PA-220S to a centralized Panorama. This Panorama manages a number of PA-7000 Series and PA-5200 Series devices All device group and template configuration is managed solely within Panorama.
They notice that commit times have drastically increased for the PA-220S after the migration.
What can they do to reduce commit times?
- A . Disable "Share Unused Address and Service Objects with Devices" in Panorama Settings.
- B . Update the apps and threat version using device-deployment
- C . Perform a device group push using the "merge with device candidate config" option
- D . Use "export or push device config bundle" to ensure that the firewall is integrated with the Panorama config.
Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server.
Given the rule below, what change should be made to make sure the NAT works as expected?
- A . Change destination NAT zone to Trust_L3.
- B . Change destination translation to Dynamic IP (with session distribution) using firewall eth1/2 address.
- C . Change Source NAT zone to Untrust_L3.
- D . Add source Translation to translate original source IP to the firewall eth1/2 interface translation.
Why would a traffic log list an application as "not-applicable”?
- A . The firewall denied the traffic before the application match could be performed.
- B . The TCP connection terminated without identifying any application data
- C . There was not enough application data after the TCP connection was established
- D . The application is not a known Palo Alto Networks App-ID.
Which three external authentication services can the firewall use to authenticate admins into the Palo Alto Networks NGFW without creating administrator account on the firewall? (Choose three.)
- A . RADIUS
- B . TACACS+
- C . Kerberos
- D . LDAP
- E . SAML
Where can a service route be configured for a specific destination IP?
- A . Use Network > Virtual Routers, select the Virtual Router > Static Routes > IPv4
- B . Use Device > Setup > Services > Services
- C . Use Device > Setup > Services > Service Route Configuration > Customize > Destination
- D . Use Device > Setup > Services > Service Route Configuration > Customize > IPv4
A network security administrator has been tasked with deploying User-ID in their organization.
What are three valid methods of collecting User-ID information in a network? (Choose three.)
- A . Windows User-ID agent
- B . GlobalProtect
- C . XMLAPI
- D . External dynamic list
- E . Dynamic user groups
Which two policy components are required to block traffic in real time using a dynamic user group (DUG)? (Choose two.)
- A . A Deny policy for the tagged traffic
- B . An Allow policy for the initial traffic
- C . A Decryption policy to decrypt the traffic and see the tag
- D . A Deny policy with the "tag" App-ID to block the tagged traffic
Refer to the exhibit.
Which will be the egress interface if the traffic’s ingress interface is ethernet1/7 sourcing from 192.168.111.3 and to the destination 10.46.41.113?
- A . ethernet1/6
- B . ethernet1/3
- C . ethernet1/7
- D . ethernet1/5