Palo-alto-networks

PCNSE practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 578-question bank.

Provider
Palo-alto-networks
Question bank
578
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for PCNSE, a certification listed under Palo-alto-networks. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Palo-alto-networks. The certification credential is issued by Palo-alto-networks, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?

    Choose one answer.

    • check
    • find
    • test
    • sim
  2. Question 2 · 1

    If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is pushed?

    Choose one answer.

    • The settings assigned to the template that is on top of the stack.
    • The administrator will be promoted to choose the settings for that chosen firewall.
    • All the settings configured in all templates.
    • Depending on the firewall location, Panorama decides with settings to send.
  3. Question 3 · 1

    View the GlobalProtect configuration screen capture. What is the purpose of this configuration?

    Choose one answer.

    Question illustration 1
    • It configures the tunnel address of all internal clients to an IP address range starting at 192.168.10.1.
    • It forces an internal client to connect to an internal gateway at IP address 192.168.10.1.
    • It enables a client to perform a reverse DNS lookup on 192.168.10.1 to detect that it is an internal client.
    • It forces the firewall to perform a dynamic DNS update, which adds the internal gateway's hostname and IP address to the DNS server.
  4. Question 4 · 1

    Which three user authentication services can be modified to provide the Palo Alto Networks NGFW with both usernames and role names? (Choose three.)

    Choose all answers that apply.

    • TACACS+
    • Kerberos
    • PAP
    • LDAP
    • SAML
    • RADIUS
  5. Question 5 · 1

    What is exchanged through the HA2 link?

    Choose one answer.

    • hello heartbeats
    • User-ID information
    • session synchronization
    • HA state information
  6. Question 6 · 1

    Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?

    Choose one answer.

    • Both SSH keys and SSL certificates must be generated.
    • No prerequisites are required.
    • SSH keys must be manually generated.
    • SSL certificates must be generated.
  7. Question 7 · 1

    A customer wants to combine multiple Ethernet interfaces into a single virtual interface using link aggregation. Which two formats are correct for naming aggregate interfaces? (Choose two.)

    Choose all answers that apply.

    • ae.8
    • aggregate.1
    • ae.1
    • aggregate.8
  8. Question 8 · 1

    Which three authentication factors does PAN-OSֲ® software support for MFA? (Choose three.)

    Choose all answers that apply.

    • Push
    • Pull
    • Okta Adaptive
    • Voice
    • SMS
  9. Question 9 · 1

    VPN traffic intended for an administrator's firewall is being maliciously intercepted and retransmitted by the interceptor. When creating a VPN tunnel, which protection profile can be enabled to prevent this malicious behavior?

    Choose one answer.

    • Zone Protection
    • Replay
    • Web Application
    • DoS Protection
  10. Question 10 · 1

    An administrator has configured a QoS policy rule and a QoS Profile that limits the maximum allowable bandwidth for the YouTube application. However, YouTube is consuming more than the maximum bandwidth allotment configured. Which configuration step needs to be configured to enable QoS?

    Choose one answer.

    • Enable QoS interface
    • Enable QoS in the Interface Management Profile
    • Enable QoS Data Filtering Profile
    • Enable QoS monitor
  11. Question 11 · 1

    Which log file can be used to identify SSL decryption failures?

    Choose one answer.

    • Traffic
    • ACC
    • Configuration
    • Threats
  12. Question 12 · 1

    Which method will dynamically register tags on the Palo Alto Networks NGFW?

    Choose one answer.

    • Restful API or the VMware API on the firewall or on the User-ID agent or the ready-only domain controller (RODC)
    • Restful API or the VMware API on the firewall or on the User-ID agent
    • XML API or the VMware API on the firewall or on the User-ID agent or the CLI
    • XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
  13. Question 13 · 1

    A customer wants to set up a site-to-site VPN using tunnel interfaces. Which two formats are correct for naming tunnel interfaces? (Choose two.)

    Choose all answers that apply.

    • tunnel.1
    • vpn-tunnel.1
    • tunnel.1025
    • vpn-tunnel.1024
  14. Question 14 · 1

    Based on the following image, what is the correct path of root, intermediate, and end-user certificate?

    Choose one answer.

    Question illustration 1
    • Palo Alto Networks > Symantec > VeriSign
    • VeriSign > Symantec > Palo Alto Networks
    • Symantec > VeriSign > Palo Alto Networks
    • VeriSign > Palo Alto Networks > Symantec
  15. Question 15 · 1

    An administrator wants a new Palo Alto Networks NGFW to obtain automatic application updates daily, so it is configured to use a scheduler for the application database. Unfortunately, they required the management network to be isolated so that it cannot reach the Internet. Which configuration will enable the firewall to download and install application updates automatically?

    Choose one answer.

    • Download and install application updates cannot be done automatically if the MGT port cannot reach the Internet.
    • Configure a service route for Palo Alto Networks Services that uses a dataplane interface that can route traffic to the Internet, and create a Security policy rule to allow the traffic from that interface to the update servers if necessary.
    • Configure a Policy Based Forwarding policy rule for the update server IP address so that traffic sourced from the management interfaced destined for the update servers goes out of the interface acting as your Internet connection.
    • Configure a Security policy rule to allow all traffic to and from the update servers.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free