Skip to main content

PAN-NGFE Real Exam Questions

Palo Alto Networks Network Next-Generation Firewall Engineer

83 questions available · Page 1 of 9

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An engineer needs to configure administrator authentication using both TACACS+ and SAML simultaneously during a migration period.

Which configuration meets this requirement?

  1. A

    Create two separate authentication profiles and assign both to the same administrator account.

  2. B

    Configure an authentication sequence including both TACACS+ and SAML server profiles.

  3. C

    Enable fallback authentication directly within the SAML identity provider settings.

  4. D

    Configure TACACS+ as primary and SAML as secondary within a single server profile.

Show answer and explanation

Correct answer: B

Question 2 Single choice

A firewall administrator wants to be able to see all NAT sessions that are going through a firewall with source NAT.

Which CLI command can the administrator use?

  1. A

    show session all filter nat source

  2. B

    show running nat-rule-ippool rule "rule_name"

  3. C

    show running nat-policy

  4. D

    show session all filter nat-rule-source

Show answer and explanation

Correct answer: A

Question 3 Multiple choice

Which two actions must an engineer take to configure SSL Forward Proxy decryption? (Choose two.)

  1. A

    Configure the decryption profile.

  2. B

    Configure SSL decryption rules.

  3. C

    Define a Forward Trust Certificate.

  4. D

    Configure a SSL / TLS service profile.

Show answer and explanation

Correct answers: B, C

Question 4 Single choice

A PA-Series firewall with all licensable features is being installed. The customer's Security policy requires that users do not directly access websites. Instead, a security device must create the connection, and there must be authentication back to the Active Directory servers for all sessions.

Which action meets the requirements in this scenario?

  1. A

    Deploy the transparent proxy with Web Cache Communications Protocol (WCCP).

  2. B

    Deploy the Next-Generation Firewalls as normal and install the User-ID agent.

  3. C

    Deploy the Advanced URL Filtering license and captive portal.

  4. D

    Deploy the explicit proxy with Kerberos authentication scheme.

Show answer and explanation

Correct answer: D

Question 5 Single choice

An administrator plans to upgrade a pair of active/passive firewalls to a new PAN-OS release. The environment is highly sensitive, and downtime must be minimized.

What is the recommended upgrade process for minimal disruption in this high availability (HA) scenario?

  1. A

    Suspend the active firewall to trigger a failover to the passive firewall. With traffic now running on the former passive unit, upgrade the suspended (now passive) firewall and confirm proper operation. Then fail traffic back and upgrade the remaining firewall.

  2. B

    Shut down the currently active firewall and upgrade it offline, allowing the passive firewall to handle all traffic. Once the active firewall finishes upgrading, bring it back online and rejoin the HA cluster. Finally, upgrade the passive firewall while the newly upgraded unit remains active.

  3. C

    Isolate both firewalls from the production environment and upgrade them in a separate, offline setup.
    Reconnect them only after validating the new software version, resuming HA functionality once both units are fully upgraded and tested.

  4. D

    Push the new PAN-OS version simultaneously to both firewalls, having them upgrade and reboot in parallel. Rely on automated HA reconvergence to restore normal operations without manually failing over traffic.

Show answer and explanation

Correct answer: A

Question 6 Single choice

An engineer configures multiple Layer 3 interfaces in the same subnet but cannot achieve communication between hosts.

What is the most likely reason?

  1. A

    Interfaces are assigned to different virtual routers.

  2. B

    Interfaces are in different zones without a security policy.

  3. C

    ARP is disabled on the interfaces.

  4. D

    Duplicate IP addresses exist on the interfaces.

Show answer and explanation

Correct answer: B

Question 7 Single choice

Which configuration in the LACP tab will enable pre-negotiation for an Aggregate Ethernet (AE) interface on a Palo Alto Networks high availability (HA) active/passive pair?

  1. A

    Set Transmission Rate to "fast."

  2. B

    Set passive link state to "Auto."

  3. C

    Set "Enable in HA Passive State."

  4. D

    Set LACP mode to "Active."

Show answer and explanation

Correct answer: C

Question 8 Multiple choice

A company is expanding its existing log storage and alerting solutions. All company Palo Alto Networks firewalls currently forward logs to Panorama.

Which two additional log forwarding methods will PAN-OS support? (Choose two.)

  1. A

    SSL

  2. B

    TLS

  3. C

    HTTP

  4. D

    Email

Show answer and explanation

Correct answers: C, D

Question 9 Single choice

A firewall engineer creates a source NAT rule to allow the company's internal private network 10.0.0.0/23 to access the internet. However, for security reasons, one server in that subnet (10.0.0.10/32) should not be allowed to access the internet, and therefore should not be translated with the NAT rule.

Which set of steps should the engineer take to accomplish this objective?

  1. A

    1. Create a NAT rule (NAT-Rule-1) and set the source address in the original packet to 10.0.0.10/32.
    2. Check the box for negate option to negate this IP from the NAT translation.

  2. B

    1. Create a NAT rule (NAT-Rule-1) and set the source address in the original packet to 10.0.0.0/23.
    2. Check the box for negate option to negate this IP subnet from NAT translation.

  3. C

    1. Create a source NAT rule (NAT-Rule-1) to translate 10.0.0.0/23 with source address translation set to dynamic IP and port.
    2. Create another NAT rule (NAT-Rule-2) with source IP address in the original packet set to
    10.0.0.10/32 and source translation set to none.
    3. Place (NAT-Rule-2) above (NAT-Rule-1).

  4. D

    1. Create a source NAT rule (NAT-Rule-1) to translate 10.0.0.0/23 with source address translation set to dynamic IP and port.
    2. Create another NAT rule (NAT-Rule-2) with source IP address in the original packet set to
    10.0.0.10/32 and source translation set to none.
    3. Place (NAT-Rule-1) above (NAT-Rule-2).

Show answer and explanation

Correct answer: C

Question 10 Single choice

An organization runs multiple Kubernetes clusters both on-premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within each cluster, maintain consistent Security policies across all environments, and dynamically scale as containerized workloads spin up or down. They also plan to use a centralized Panorama instance for policy management and visibility.

Which approach meets these requirements?

  1. A

    Install standalone CN-Series instances in each cluster with local configuration only.
    Export daily policy configuration snapshots to Panorama for recordkeeping, but do not unify policy enforcement.

  2. B

    Configure the CN-Series only in public cloud clusters, and rely on Kubernetes Network Policies for on-premises cluster security. Synchronize partial policy information into Panorama manually as needed.

  3. C

    Use Kubernetes-native deployment tools (e.g., Helm) to deploy CN-Series in each cluster, ensuring local insertion into the service mesh or CNI. Manage all CN-Series firewalls centrally from Panorama, applying uniform Security policies across on-premises and cloud clusters.

  4. D

    Deploy a single CN-Series firewall in the on-premises data center to process traffic for all clusters, connecting remote clusters via VPN or peering. Manage this single instance through Panorama.

Show answer and explanation

Correct answer: C