Troubleshooting for Palo Alto Networks Certified Network Security Engineer (PCNSE)
This page covers the Troubleshooting domain of the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Master Cybersecurity offers 33 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Which CLI command is used to simulate traffic going through the firewall and determine which Security policy rule, NAT translation, static route, or PBF rule will be triggered by the traffic?- A. check
- B. find
- C. test
- D. sim
Explanation
The correct answer is: C. test.
The test command family lets an administrator ask the firewall which rule a hypothetical flow would match without generating any real traffic. Supplying a source, destination, protocol, port and other selectors returns the rule that would apply, and separate forms exist for security policy, NAT policy, policy-based forwarding and route lookup, so the same technique answers questions across all of them. This is the fastest way to settle whether a rule ordering problem is real, and it is safe to run at any time because nothing is forwarded and no configuration changes. Check, find and sim are not commands in PAN-OS, and their plausibility is the point of the question, since each is a word an administrator might reasonably expect. It is worth pairing the command with log evidence, because test reports what policy would do while the Traffic log reports what actually happened, and a disagreement between the two usually points at something determined at runtime such as the identified application or a resolved address group.
Question 2
Refer to the exhibit. An organization has Palo Alto Networks NGFWs that send logs to remote monitoring and security management platforms. The network team has reported excessive traffic on the corporate WAN. How could the Palo Alto Networks NGFW administrator reduce WAN traffic while maintaining support for all the existing monitoring/security platforms?- A. Forward logs from firewalls only to Panorama and have Panorama forward logs to other external services.
- B. Forward logs from external sources to Panorama for correlation, and from Panorama send them to the NGFW.
- C. Configure log compression and optimization features on all remote firewalls.
- D. Any configuration on an M-500 would address the insufficient bandwidth concerns.
Explanation
The correct answer is: A. Forward logs from firewalls only to Panorama and have Panorama forward logs to other external services..
Each firewall at the remote site is sending its own log stream across the WAN to every monitoring and security platform in the data centre, which multiplies the same records by the number of destinations and is why the link is saturated. Forwarding logs only to the local Panorama and letting Panorama relay them onward collapses that fan-out: one aggregated stream crosses the WAN, and Panorama distributes to the external services from the data centre side, so every existing platform keeps receiving what it needs. Sending logs from external sources into Panorama and then down to the firewalls reverses the direction of flow and would add traffic rather than remove it. There is no log compression or optimisation feature on the firewalls that would address this, so configuring one is not an available option. An M-500 is a Panorama hardware appliance, and adding one changes log storage and processing capacity, but capacity was never the constraint here; the problem is how many copies of each record traverse the WAN.
Question 3
An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?- A. Security policy rule allowing SSL to the target server
- B. Firewall connectivity to a CRL
- C. Root certificate imported into the firewall with "Trust" enabled
- D. Importation of a certificate from an HSM
Explanation
The correct answer is: A. Security policy rule allowing SSL to the target server.
SSL Inbound Inspection decrypts traffic to a server the organisation controls, using a copy of that server's own certificate and private key, and the traffic still has to be permitted by policy before any of that matters. A Security policy rule allowing SSL to the target server is therefore the first thing to check, because a session blocked by policy never reaches the decryption stage and the symptom looks like a decryption failure. Connectivity to a certificate revocation list is not relevant to inbound inspection, since the firewall is not validating a remote server's certificate; it already holds the key material for its own server. A root certificate imported with trust enabled belongs to outbound forward proxy, where the firewall must validate certificates presented by external sites. Importing a certificate from a hardware security module is a key storage arrangement rather than a triage step, and while an HSM can hold the server key, that is a deployment choice rather than the first thing to examine.
Question 4
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach http://www.company.com. At other times the session times out. The NGFW has been configured with a PBF rule that the user's traffic matches when it goes to http://www.company.com. How can the firewall be configured automatically disable the PBF rule if the next hop goes down?- A. Create and add a Monitor Profile with an action of Wait Recover in the PBF rule in question.
- B. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question.
- C. Enable and configure a Link Monitoring Profile for the external interface of the firewall.
- D. Configure path monitoring for the next hop gateway on the default route in the virtual router.
Explanation
The correct answer is: B. Create and add a Monitor Profile with an action of Fail Over in the PBF rule in question..
Policy-based forwarding sends matching traffic to a chosen next hop regardless of the routing table, which is exactly why it needs its own health check: if that next hop fails, the rule keeps forwarding into a black hole and sessions time out intermittently, which is the behaviour described. A Monitor profile attached to the rule with an action of Fail Over solves it by disabling the rule when the next hop stops responding, so traffic falls back to normal routing. Wait Recover is the other available action and does the opposite, holding traffic for the rule while waiting for the path to return, which prolongs the outage rather than routing around it. A Link Monitoring profile watches physical interface state for high availability failover, so it reacts to a link going down rather than to a next hop becoming unreachable while the link stays up. Path monitoring on the default route governs whether a static route is installed, which does not help because policy-based forwarding is evaluated before the routing table is consulted.
Question 5
A speed/duplex negotiation mismatch is between the Palo Alto Networks management port and the switch port to which it connects. How would an administrator configure the interface to 1Gbps?- A. set deviceconfig interface speed-duplex 1Gbps-full-duplex
- B. set deviceconfig system speed-duplex 1Gbps-duplex
- C. set deviceconfig system speed-duplex 1Gbps-full-duplex
- D. set deviceconfig Interface speed-duplex 1Gbps-half-duplex
Explanation
The correct answer is: C. set deviceconfig system speed-duplex 1Gbps-full-duplex.
The management interface is configured under deviceconfig system rather than as one of the data interfaces, because it belongs to the firewall's own system settings alongside the management IP address, DNS servers and permitted services. The value must also name a complete mode, and 1Gbps-full-duplex is the valid keyword for gigabit operation. Both parts have to be right, which is what makes the distractors effective. The two options placing speed-duplex under deviceconfig interface put the setting in the wrong branch of the configuration entirely, since data plane interfaces are configured under network interface. The option using 1Gbps-duplex omits whether the link is full or half, so it is not a defined value. The half-duplex variant would parse but makes the mismatch worse rather than better. Where a negotiation mismatch is suspected, the reliable fix is to set both ends explicitly to the same speed and duplex rather than leaving one side to autonegotiate against a fixed peer.
Other Palo Alto Networks Certified Network Security Engineer (PCNSE) domains
- Core Concepts (24 questions)
- Deploy and Configure Core Components (48 questions)
- Deploy and Configure Features and Subscriptions (88 questions)
- Deploy and Configure Firewalls Using Panorama (39 questions)
- Manage and Operate (39 questions)