Deploy and Configure Core Components for Palo Alto Networks Certified Network Security Engineer (PCNSE)

This page covers the Deploy and Configure Core Components domain of the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Master Cybersecurity offers 48 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    A customer wants to set up a VLAN interface for a Layer 2 Ethernet port. Which two mandatory options are used to configure a VLAN interface? (Choose two.)
    1. A. Virtual router
    2. B. Security zone
    3. C. ARP entries
    4. D. Netflow Profile
    Explanation

    The correct answers are: A. Virtual router, B. Security zone.

    A VLAN interface is the routed gateway that lets traffic leave a Layer 2 segment, so the two settings it cannot do without are the ones that place it inside the firewall's forwarding and policy model. A virtual router gives the interface a routing table to participate in, and a security zone lets Security policy match traffic entering or leaving it; both appear on the Config tab of the VLAN interface alongside the VLAN object itself, and omitting either leaves an interface that either cannot route or cannot be referenced by any rule. ARP entries and a NetFlow profile are optional fields on the Advanced tab. Static ARP entries are needed only where dynamic resolution is undesirable, such as pinning a critical host against ARP spoofing, and a NetFlow profile merely exports flow records to an external collector for visibility. Neither has any bearing on whether the interface functions, which is why neither can be part of the mandatory pair.

  2. Question 2

    Which method will dynamically register tags on the Palo Alto Networks NGFW?
    1. A. Restful API or the VMware API on the firewall or on the User-ID agent or the ready-only domain controller (RODC)
    2. B. Restful API or the VMware API on the firewall or on the User-ID agent
    3. C. XML API or the VMware API on the firewall or on the User-ID agent or the CLI
    4. D. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent
    Explanation

    The correct answer is: D. XML API or the VM Monitoring agent on the NGFW or on the User-ID agent.

    Tags are registered dynamically either through the XML API or by the VM Monitoring agent, whether that agent runs on the firewall itself or on a Windows User-ID agent. The API path is what allows an orchestration system, a SIEM or a script to tag an address the moment something is observed, and the VM Monitoring path watches a virtualisation platform and tags workloads according to their attributes there, so a newly created virtual machine falls into the right dynamic address group without a configuration change. Both feed dynamic address groups, which is the mechanism that lets policy adapt without a commit. The options naming a RESTful API describe the wrong interface for this purpose, since dynamic tag registration uses the XML API. The option naming a read-only domain controller confuses User-ID collection with tag registration, as an RODC is a source of user information rather than of tags. The option adding the CLI is wrong because the command line is used to inspect registered tags rather than to register them dynamically.

  3. Question 3

    An administrator needs to implement an NGFW between their DMZ and Core network. EIGRP Routing between the two environments is required. Which interface type would support this business requirement?
    1. A. Virtual Wire interfaces to permit EIGRP routing to remain between the Core and DMZ
    2. B. Layer 3 or Aggregate Ethernet interfaces, but configuring EIGRP on subinterfaces only
    3. C. Tunnel interfaces to terminate EIGRP routing on an IPsec tunnel (with the GlobalProtect License to support LSVPN and EIGRP protocols)
    4. D. Layer 3 interfaces, but configuring EIGRP on the attached virtual router
    Explanation

    The correct answer is: A. Virtual Wire interfaces to permit EIGRP routing to remain between the Core and DMZ.

    PAN-OS does not implement EIGRP, so the only way to place a firewall between two environments that must continue exchanging EIGRP routes is to deploy it in virtual wire mode, where the firewall inspects traffic and passes it through without participating in routing. The routers on either side remain EIGRP neighbours and are unaware of the device between them, which is what satisfies the requirement. Layer 3 interfaces with EIGRP on the attached virtual router is not possible, because the virtual router supports static routing, RIP, OSPF and BGP but not EIGRP. Configuring EIGRP on subinterfaces fails for the same reason, since the protocol is absent from the platform regardless of where it is configured. The tunnel interface option compounds several errors, proposing to terminate EIGRP on an IPsec tunnel and attributing EIGRP support to a GlobalProtect license, and it is worth noting that a virtual wire also preserves any other protocol the two sides use, which is often the real reason the mode is chosen.

  4. Question 4

    A web server is hosted in the DMZ, and the server is configured to listen for incoming connections only on TCP port 8080. A Security policy rule allowing access from the Trust zone to the DMZ zone need to be configured to enable we browsing access to the server. Which application and service need to be configured to allow only cleartext web-browsing traffic to thins server on tcp/8080?
    1. A. application: web-browsing; service: application-default
    2. B. application: web-browsing; service: service-https
    3. C. application: ssl; service: any
    4. D. application: web-browsing; service: (custom with destination TCP port 8080)
    Explanation

    The correct answer is: D. application: web-browsing; service: (custom with destination TCP port 8080).

    The server listens on 8080 and only cleartext web traffic should be allowed to it, so the application must be web-browsing and the service must be a custom service object specifying TCP port 8080. The reason a custom service is required is that application-default for web-browsing means port 80, so pairing web-browsing with application-default would never match traffic on 8080. Naming the application as well as the port is what makes the rule tight, because it ensures only traffic App-ID identifies as web-browsing is permitted rather than anything that happens to use the port. Using application-default fails for the reason given. Using the HTTPS service names port 443, which is neither the port the server listens on nor consistent with cleartext traffic. Specifying the ssl application with any service inverts the requirement in two ways, permitting encrypted traffic instead of cleartext and leaving the port entirely unconstrained.

  5. Question 5

    An administrator needs to optimize traffic to prefer business-critical applications over non-critical applications. QoS natively integrates with which feature to provide service quality?
    1. A. Port Inspection
    2. B. Certificate revocation
    3. C. Content-ID
    4. D. App-ID
    Explanation

    The correct answer is: D. App-ID.

    QoS on PAN-OS is built on App-ID, which is what lets bandwidth decisions follow the application rather than the port. Because the firewall identifies the application regardless of the port it uses, a QoS policy can guarantee bandwidth to a business-critical application and throttle recreational traffic even when both travel over the same port, and the same policy can also match on user, so treatment can vary by who is generating the traffic. That is the integration the question asks about. Content-ID is the inspection engine covering threat prevention, URL filtering and file blocking, so it examines what is inside traffic rather than classifying it for bandwidth treatment. Certificate revocation is a validation function used during decryption and authentication and has no bearing on prioritisation. Port inspection is not a PAN-OS feature at all, and it describes precisely the port-equals-application assumption that App-ID exists to replace.

Other Palo Alto Networks Certified Network Security Engineer (PCNSE) domains

Practice all 48 Deploy and Configure Core Components questions · Browse Palo Alto Networks Certified Network Security Engineer (PCNSE)