Official Bank 0/369

Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 10.0 (PCNSE) - PaloAlto Networks Actual Exam Questions

Last updated on May 06, 2026

97% Exam Compliance
369 Total Questions
1
Question

After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall After troubleshooting the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports What can the engineer do to solve the VoIP traffic issue?

Options
A

Disable ALG under H.323 application

B

Increase the TCP timeout under H.323 application

C

Increase the TCP timeout under SIP application

D

Disable ALG under SIP application

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to "any." There is one link group configured containing member interfaces ethernet1/1 and ethernet1/2 with a Group Failure Condition set to "all." Which HA state will the Active firewall go into if ethernet1/1 link goes down due to a failure?'

Options
A

Active-Secondary

B

Non-functional

C

Passive

D

Active

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers. Which VPN configuration would adapt to changes when deployed to the future site?

Options
A

Preconfigured GlobalProtect satellite

B

Preconfigured GlobalProtect client

C

Preconfigured IPsec tunnels

D

Preconfigured PPTP Tunnels

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

An administrator has been tasked with configuring decryption policies, Which decryption best practice should they consider?

Options
A

Consider the local, legal, and regulatory implications and how they affect which traffic can be decrypted.

B

Decrypt all traffic that traverses the firewall so that it can be scanned for threats.

C

Place firewalls where administrators can opt to bypass the firewall when needed.

D

Create forward proxy decryption rules without Decryption profiles for unsanctioned applications.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?

Options
A

Enable PFS under the IKE gateway advanced options.

B

Enable PFS under the IPSec Tunnel advanced options.

C

Add an authentication algorithm in the IPSec Crypto profile.

D

Select the appropriate DH Group under the IPSec Crypto profile.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.