Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Palo Alto Networks > Palo Alto Networks Certifications > PCNSE > PCNSE Online Practice Questions and Answers

PCNSE Online Practice Questions and Answers

Questions 4

In a Panorama template which three types of objects are configurable? (Choose three)

A. HIP objects

B. QoS profiles

C. interface management profiles

D. certificate profiles

E. security profiles

Buy Now

Correct Answer: BCD

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/use-case-configure-firewalls-using-panorama/set-up-your-centralized-configuration-and-policies/use-templates-to-administer-a-base-configuration

Questions 5

Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?

A. check

B. find

C. test

D. sim

Buy Now

Correct Answer: C

Reference: http://www.shanekillen.com/2014/02/palo-alto-useful-cli-commands.html

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClQSCA0

Questions 6

Which two interface types can be used when configuring GlobalProtect Portal? (Choose two)

A. Virtual Wire

B. Loopback

C. Layer 3

D. Tunnel

Buy Now

Correct Answer: BC

Questions 7

Which operation will impact performance of the management plane?

A. DoS protection

B. WildFire submissions

C. generating a SaaS Application report

D. decrypting SSL sessions

Buy Now

Correct Answer: C

Questions 8

Which Panorama feature allows for logs generated by Panorama to be forwarded to an external Security Information and Event Management(SIEM) system?

A. Panorama Log Settings

B. Panorama Log Templates

C. Panorama Device Group Log Forwarding

D. Collector Log Forwarding for Collector Groups

Buy Now

Correct Answer: A

https://www.paloaltonetworks.com/documentation/61/panorama/panorama_adminguide/ma nage-log-collection/enable-log-forwarding-from-panorama-to-external-destinations

Questions 9

The same route appears in the routing table three times using three different protocols. Which mechanism determines how the firewall chooses which route to use?

A. Administrative distance

B. Round Robin load balancing

C. Order in the routing table

D. Metric

Buy Now

Correct Answer: A

Administrative distance is the measure of trustworthiness of a routing protocol. It is used to determine the best path when multiple routes to the same destination exist. The route with the lowest administrative distance is chosen as the best route.

Questions 10

An internal audit team has requested additional information to be included inside traffic logs forwarded from Palo Alto Networks firewalls to an internal syslog server. Where can the firewall engineer define the data to be added into each forwarded log?

A. Custom Log Format within Device > Server Profiles > Syslog

B. Built-in Actions within Objects > Log Forwarding Profile

C. Logging and Reporting Settings within Device > Setup > Management

D. Data Patterns within Objects > Custom Objects

Buy Now

Correct Answer: A

To facilitate the integration with external log parsing systems, the firewall allows you to customize the log format; it also allows you to add custom Key: Value attribute pairs. Custom message formats can be configured under DeviceServer ProfilesSyslogSyslog Server ProfileCustom Log Format. https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/custom-logevent-format

Questions 11

After switching to a different WAN connection, users have reported that various websites will not load, and timeouts are occurring. The web servers work fine from other locations.

The firewall engineer discovers that some return traffic from these web servers is not reaching the users behind the firewall. The engineer later concludes that the maximum transmission unit (MTU) on an upstream router interface is set to

1400 bytes.

The engineer reviews the following CLI output for ethernet1/1.

Which setting should be modified on ethernet1/1 to remedy this problem?

A. Change the subnet mask from /23 to /24.

B. Lower the interface MTU value below 1500.

C. Adjust the TCP maximum segment size (MSS) value.

D. Enable the Ignore IPv4 Don't Fragment (DF) setting.

Buy Now

Correct Answer: C

Please note that even though adjusting the MSS value on the PA firewall solves the issue, the issue is not caused by the Firewall. The issue is caused by other hosts in the path that have lower MTU setting.

Questions 12

Review the screenshots and consider the following information:

1.

FW-1 is assigned to the FW-1_DG device group and FW-2 is assigned to OFFICE_FW_DG

2.

There are no objects configured in REGIONAL_DG and OFFICE_FW_DG device groups Which IP address will be pushed to the firewalls inside Address Object Server-1?

A. Server-1 on FW-1 will have IP 2.2.2.2 Server-1 will not be pushed to FW-2

B. Server-1 on FW-1 will have IP 3.3.3.3 Server-1 will not be pushed to FW-2

C. Server-1 on FW-1 will have IP 1.1.1.1 Server-1 will not be pushed to FW-2

D. Server-1 on FW-1 will have IP 4.4.4.4 Server-1 on FW-2 will have IP 1.1.1.1

Buy Now

Correct Answer: D

Questions 13

An administrator is assisting a security engineering team with a decryption rollout for inbound and forward proxy traffic. Incorrect firewall sizing is preventing the team from decrypting all of the traffic they want to decrypt.

Which three items should be prioritized for decryption? (Choose three.)

A. Financial, health, and government traffic categories

B. Less-trusted internal IP subnets

C. Known malicious IP space

D. High-risk traffic categories

E. Public-facing servers

Buy Now

Correct Answer: BDE

Exam Code: PCNSE
Exam Name: Palo Alto Networks Certified Network Security Engineer - PAN-OS 11.x (PCNSE)
Last Update: Mar 27, 2026
Questions: 860

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2026 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.