Deploy and Configure Features and Subscriptions for Palo Alto Networks Certified Network Security Engineer (PCNSE)

This page covers the Deploy and Configure Features and Subscriptions domain of the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Master Cybersecurity offers 88 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    An administrator has been asked to configure a Palo Alto Networks NGFW to provide protection against worms and trojans. Which Security Profile type will protect against worms and trojans?
    1. A. Anti-Spyware
    2. B. Instruction Prevention
    3. C. File Blocking
    4. D. Antivirus
    Explanation

    The correct answer is: D. Antivirus.

    Worms and trojans are malware delivered as files, and an Antivirus profile is the security profile that inspects files in transit against antivirus signatures and blocks them, so attaching one to the rules permitting the relevant traffic is the protection required. The profile allows a decision per protocol decoder, so HTTP, SMTP, FTP and the others can be treated differently, and it works alongside WildFire so that newly generated signatures for previously unknown samples are enforced through the same mechanism. An Anti-Spyware profile addresses the aftermath instead, detecting command and control traffic from a host that is already compromised. File Blocking controls which file types may cross the firewall at all, which is a valuable complementary control but blocks by type rather than by malicious content, so it would stop an executable regardless of whether it was malicious. Instruction Prevention is not a profile type; the name is a corruption of intrusion prevention, which in PAN-OS is delivered by Vulnerability Protection.

  2. Question 2

    When configuring a GlobalProtect Portal, what is the purpose of specifying an Authentication Profile?
    1. A. To enable Gateway authentication to the Portal
    2. B. To enable Portal authentication to the Gateway
    3. C. To enable user authentication to the Portal
    4. D. To enable client machine authentication to the Portal
    Explanation

    The correct answer is: C. To enable user authentication to the Portal.

    An authentication profile on a GlobalProtect portal establishes how users authenticate to the portal itself, which is the first step in the connection sequence: the app contacts the portal, the user authenticates, and the portal returns the configuration telling the app which gateways to use and how to behave. Additional selections allow different profiles for particular cases, one for a user reaching the portal from a browser to download the app and another for authenticating a satellite in a large-scale VPN deployment, which shows that the setting is about who is authenticating to the portal. The options describing gateway authentication to the portal and portal authentication to the gateway both invert the relationship, since these components identify each other with certificates rather than through an authentication profile. Client machine authentication to the portal describes what a certificate profile achieves, which is a separate setting used for pre-logon and for validating machine certificates.

  3. Question 3

    To connect the Palo Alto Networks firewall to AutoFocus, which setting must be enabled?
    1. A. Device>Setup>Services>AutoFocus
    2. B. Device> Setup>Management >AutoFocus
    3. C. AutoFocus is enabled by default on the Palo Alto Networks NGFW
    4. D. Device>Setup>WildFire>AutoFocus
    5. E. Device>Setup> Management> Logging and Reporting Settings
    Explanation

    The correct answer is: B. Device> Setup>Management >AutoFocus.

    The AutoFocus integration is enabled under the management section of the device setup, where an administrator turns it on and supplies the service URL, after which threat intelligence context becomes available directly from log entries and the ACC. Locating it under management rather than under services or WildFire reflects what it is: a management-plane integration that enriches what the administrator sees rather than a data-plane inspection feature. The services section holds the addresses the firewall uses for DNS, NTP and updates. The WildFire section configures the cloud the firewall submits samples to along with file size limits and the grayware reporting option, and while AutoFocus and WildFire are related services, they are configured separately. AutoFocus is not enabled by default, since it requires a subscription and an explicit service URL. The logging and reporting settings control log storage quotas and report generation rather than external intelligence integrations.

  4. Question 4

    Which User-ID method maps IP addresses to usernames for users connecting through an 802.1x-enabled wireless network device that has no native integration with PAN-OS software?
    1. A. XML API
    2. B. Port Mapping
    3. C. Client Probing
    4. D. Server Monitoring
    Explanation

    The correct answer is: A. XML API.

    A wireless controller enforcing 802.1x knows exactly which user authenticated on which address, but if it has no native integration with PAN-OS there is no built-in way for the firewall to learn that. The XML API bridges the gap: a script or middleware reads the controller's authentication events and posts the resulting mappings to the firewall, which then treats them like any other User-ID mapping. That flexibility is the reason the API exists, since it accommodates any source of identity that can be scripted. Port mapping is for terminal servers where many users share an address and a source port range identifies each session. Client probing queries endpoints directly with WMI or NetBIOS to discover the logged-on user, which is intrusive and unreliable for wireless clients. Server monitoring reads security event logs from domain controllers and Exchange servers, so it would learn about a domain login but not about an 802.1x authentication handled by a controller it cannot read.

  5. Question 5

    Decrypted packets from the website https://www.microsoft.com will appear as which application and service within the Traffic log?
    1. A. web-browsing and 443
    2. B. SSL and 80
    3. C. SSL and 443
    4. D. web-browsing and 80
    Explanation

    The correct answer is: A. web-browsing and 443.

    Once a session to an HTTPS site has been decrypted, App-ID can see the cleartext inside it and identifies the application as web-browsing, while the service remains the port the session actually uses, which is 443. That combination of web-browsing on 443 is the signature of successful decryption in the Traffic log, and it is the quickest way to confirm a decryption rule is working: before decryption the same session would appear as ssl on 443, so the change in application with the port unchanged is what the administrator is looking for. The option pairing ssl with 443 describes the undecrypted state. The options involving port 80 are wrong because decryption does not change the port a session uses; the firewall inspects the traffic and re-encrypts it toward the destination on the same port, so nothing about the transport is rewritten. Only the application identity changes, which is precisely why the pairing is diagnostic.

Other Palo Alto Networks Certified Network Security Engineer (PCNSE) domains

Practice all 88 Deploy and Configure Features and Subscriptions questions · Browse Palo Alto Networks Certified Network Security Engineer (PCNSE)