Deploy and Configure Firewalls Using Panorama for Palo Alto Networks Certified Network Security Engineer (PCNSE)

This page covers the Deploy and Configure Firewalls Using Panorama domain of the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Master Cybersecurity offers 39 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    A company needs to preconfigure firewalls to be sent to remote sites with the least amount of preconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers. Which VPN configuration would adapt to changes when deployed to the future site?
    1. A. Preconfigured GlobalProtect satellite
    2. B. Preconfigured GlobalProtect client
    3. C. Preconfigured IPsec tunnels
    4. D. Preconfigured PPTP Tunnels
    Explanation

    The correct answer is: A. Preconfigured GlobalProtect satellite.

    A preconfigured GlobalProtect satellite is the configuration that adapts to change after deployment. The satellite is given only the portal address and the certificate it needs to authenticate, and it then learns from the portal which gateways to build tunnels to, so adding a regional data centre later means updating the portal once rather than revisiting every remote site. That combination of minimal preconfiguration now and automatic discovery later is precisely what the requirement describes. A preconfigured GlobalProtect client is endpoint software for user remote access rather than a means of building site-to-site connectivity between firewalls. Preconfigured IPsec tunnels would carry the traffic but must be defined explicitly at both ends, so every new data centre requires touching every branch, which is the maintenance burden being avoided. PPTP is obsolete, is not offered by PAN-OS, and would be unacceptable on security grounds in any case.

  2. Question 2

    An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair. Which NGFW receives the configuration from Panorama?
    1. A. The passive firewall, which then synchronizes to the active firewall
    2. B. The active firewall, which then synchronizes to the passive firewall
    3. C. Both the active and passive firewalls, which then synchronize with each other
    4. D. Both the active and passive firewalls independently, with no synchronization afterward
    Explanation

    The correct answer is: D. Both the active and passive firewalls independently, with no synchronization afterward.

    Panorama pushes configuration to each member of a high availability pair independently, and the peers do not synchronise the pushed configuration with each other afterwards. Each firewall receives and commits the configuration on its own, which is why both members must be selected in the push and why an administrator watching only one device can be misled into thinking the operation is complete. The option in which Panorama pushes to the passive member and it synchronises to the active reverses the direction and invents a synchronisation step that does not occur for Panorama-pushed configuration. The option in which Panorama pushes to the active member and it synchronises down to the passive describes what happens for local commits with configuration synchronisation enabled, not for a Panorama push. The option in which both receive the push and then synchronise with each other adds a reconciliation step that is unnecessary, since both already hold the same configuration by virtue of receiving the same push.

  3. Question 3

    If a template stack is assigned to a device and the stack includes three templates with overlapping settings, which settings are published to the device when the template stack is pushed?
    1. A. The settings assigned to the template that is on top of the stack.
    2. B. The administrator will be promoted to choose the settings for that chosen firewall.
    3. C. All the settings configured in all templates.
    4. D. Depending on the firewall location, Panorama decides with settings to send.
    Explanation

    The correct answer is: A. The settings assigned to the template that is on top of the stack..

    A template stack is an ordered list, and where two or more member templates configure the same setting the one nearest the top of the stack wins. That ordering is the whole design intent: a global baseline sits at the bottom, regional or site templates sit above it, and each higher layer overrides only the specific values it defines while inheriting everything else. Understanding the direction of precedence is what makes stacks usable, because moving a template up or down changes which values reach the device. The option describing all settings from all templates being applied is not possible where they conflict, since a single setting can hold only one value. The option in which an administrator is prompted to choose does not reflect how a commit works, as the resolution is deterministic rather than interactive. The option in which Panorama decides based on firewall location would make the outcome unpredictable, whereas the stack order is explicit and under the administrator's control.

  4. Question 4

    What are two benefits of nested device groups in Panorama? (Choose two.)
    1. A. Reuse of the existing Security policy rules and objects
    2. B. Requires configuring both function and location for every device
    3. C. All device groups inherit settings from the Shared group
    4. D. Overwrites local firewall configuration
    Explanation

    The correct answers are: A. Reuse of the existing Security policy rules and objects, C. All device groups inherit settings from the Shared group.

    Nesting device groups creates an inheritance path, and the two benefits that follow are reuse of existing security policy rules and objects, and the fact that everything inherits from the Shared group at the top. Reuse is the practical payoff: a rule or address object defined once at a higher level applies to every device group beneath it, so common policy is maintained in one place while site-specific rules are added lower down. Inheritance from Shared is what makes that possible, since Shared is the common ancestor of the whole hierarchy. Requiring both function and location to be configured for every device is not a benefit and not a requirement; those are optional attributes used to organise and filter managed devices. Overwriting local firewall configuration is not what nesting does, and it is the more tempting distractor because Panorama can force template values, but that is a separate push option rather than a consequence of nesting device groups.

  5. Question 5

    Which three settings are defined within the Templates object of Panorama? (Choose three.)
    1. A. Setup
    2. B. Virtual Routers
    3. C. Interfaces
    4. D. Security
    5. E. Application Override
    Explanation

    The correct answers are: A. Setup, B. Virtual Routers, C. Interfaces.

    A template carries Device and Network tab configuration, so the three settings that belong there are Setup, virtual routers and interfaces. Setup covers the device's own system configuration, including management settings, services, DNS and NTP; virtual routers and interfaces are Network-tab items describing how the firewall connects and routes. All three are the classic contents of a template and are what allows a fleet of firewalls to share one network and system baseline. Security is a policy type and lives in a device group, because policy rules and the objects they reference are distributed through the device group hierarchy as pre-rules and post-rules. Application Override is likewise a policy type rather than a template setting, and it belongs in a device group for the same reason. The dividing line is consistent throughout Panorama: templates supply Device and Network, device groups supply Objects and Policies.

Other Palo Alto Networks Certified Network Security Engineer (PCNSE) domains

Practice all 39 Deploy and Configure Firewalls Using Panorama questions · Browse Palo Alto Networks Certified Network Security Engineer (PCNSE)