Palo Alto Networks Certified Security Engineer (PCNSE) PAN-OS 10.0 (PCNSE) - PaloAlto Networks Actual Exam Questions
Last updated on May 06, 2026
After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall After troubleshooting the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports What can the engineer do to solve the VoIP traffic issue?
Disable ALG under H.323 application
Increase the TCP timeout under H.323 application
Increase the TCP timeout under SIP application
Disable ALG under SIP application
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An administrator has configured a pair of firewalls using high availability in Active/Passive mode. Link and Path Monitoring is enabled with the Failure Condition set to "any." There is one link group configured containing member interfaces ethernet1/1 and ethernet1/2 with a Group Failure Condition set to "all." Which HA state will the Active firewall go into if ethernet1/1 link goes down due to a failure?'
Active-Secondary
Non-functional
Passive
Active
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A company needs to preconfigure firewalls to be sent to remote sites with the least amount of reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers. Which VPN configuration would adapt to changes when deployed to the future site?
Preconfigured GlobalProtect satellite
Preconfigured GlobalProtect client
Preconfigured IPsec tunnels
Preconfigured PPTP Tunnels
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An administrator has been tasked with configuring decryption policies, Which decryption best practice should they consider?
Consider the local, legal, and regulatory implications and how they affect which traffic can be decrypted.
Decrypt all traffic that traverses the firewall so that it can be scanned for threats.
Place firewalls where administrators can opt to bypass the firewall when needed.
Create forward proxy decryption rules without Decryption profiles for unsanctioned applications.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?
Enable PFS under the IKE gateway advanced options.
Enable PFS under the IPSec Tunnel advanced options.
Add an authentication algorithm in the IPSec Crypto profile.
Select the appropriate DH Group under the IPSec Crypto profile.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.