PCNSE Exam Details

  • Exam Code
    :PCNSE
  • Exam Name
    :Palo Alto Networks Certified Network Security Engineer - PAN-OS 11.x (PCNSE)
  • Certification
    :Palo Alto Networks Certifications
  • Vendor
    :Palo Alto Networks
  • Total Questions
    :860 Q&As
  • Last Updated
    :Mar 23, 2026

Palo Alto Networks PCNSE Online Questions & Answers

  • Question 181:

    Which feature of Panorama allows an administrator to create a single network configuration that can be reused repeatedly for large-scale deployments even if values of configured objects, such as routes and interface addresses, change?

    A. Template stacks
    B. Template variables
    C. The Shared device group
    D. A device group

  • Question 182:

    Refer to the image.

    An administrator is tasked with correcting an NTP service configuration for firewalls that cannot use the Global template NTP servers. The administrator needs to change the IP address to a preferable server for this template stack but cannot impact other template stacks.

    How can the issue be corrected?

    A. Override the value on the NYCFW template.
    B. Override a template value using a template stack variable.
    C. Override the value on the Global template.
    D. Enable "objects defined in ancestors will take higher precedence" under Panorama settings.

  • Question 183:

    After pushing a security policy from Panorama to a PA-3020 firwall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs. What could be the problem?

    A. A Server Profile has not been configured for logging to this Panorama device.
    B. Panorama is not licensed to receive logs from this particular firewall.
    C. The firewall is not licensed for logging to this Panorama device.
    D. None of the firwwall's policies have been assigned a Log Forwarding profile

  • Question 184:

    An administrator needs to troubleshoot a User-ID deployment The administrator believes that there is an issue related to LDAP authentication The administrator wants to create a packet capture on the management plane. Which CLI command should the administrator use to obtain the packet capture for validating the configuration?

    A. > ftp export mgmt-pcap from mgmt.pcap to
    B. > scp export mgmt-pcap from mgmt.pcap to {username@host:path>
    C. > scp export pcap-mgmt from pcap.mgmt to (username@host:path)
    D. > scp export pcap from pcap to (usernameQhost:path)

  • Question 185:

    The SSL Forward Proxy decryption policy is configured. The following four certificate authority (CA) certificates are installed on the firewall.

    An end-user visits the untrusted website https //www firewall-do-not-trust-website com.

    Which certificate authority (CA) certificate will be used to sign the untrusted webserver certificate?

    A. Forward-Untrust-Certificate
    B. Forward-Trust-Certificate
    C. Firewall-CA
    D. Firewall-Trusted-Root-CA

  • Question 186:

    Forwarding of which two log types is configured in Device > Log Settings? (Choose two.)

    A. Threat
    B. HIP Match
    C. Traffic
    D. Configuration

  • Question 187:

    Refer to the exhibit.

    An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.)

    Which two security policy rules will accomplish this configuration? (Choose two.)

    A. Untrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow
    B. Untrust (Any) to DMZ (1.1.1.100), web-browsing -Allow
    C. Untrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
    D. Untrust (Any) to Untrust (10.1.1.1), SSH -Allow
    E. Untrust (Any) to DMZ (1.1.1.100), SSH -Allow

  • Question 188:

    You have been asked to implement GlobalProtect for your organization. You have decided on https://gp.mycompany.com for your Portal, and have received the certificate and key. Where would you navigate to on the firewall UI to import the certificate?

    A. Device > Certificate Management > Device Certificates > Certificates
    B. Device Certificates > Certificate Management > Certificates > Device
    C. Device > Device Certificates > Certificate Management > Certificates
    D. Device > Certificate Management > Certificates > Device Certificates

  • Question 189:

    While troubleshooting an issue, a firewall administrator performs a packet capture with a specific filter. The administrator sees drops for packets with a source IP address of 10.1.1.1. How can the administrator further investigate these packet drops by looking at the global counters for this packet capture filter?

    A. > show counter global filter packet-filter yes delta yes
    B. > show counter global filter severity drop
    C. > debug dataplane packet-diag set capture stage drop
    D. > show counter global filter delta yes I match 10.1.1-1

  • Question 190:

    A network security engineer has a requirement to allow an external server to access an internal web server. The internal web server must also initiate connections with the external server.

    What can be done to simplify the NAT policy?

    A. Configure ECMP to handle matching NAT traffic
    B. Configure a NAT Policy rule with Dynamic IP and Port
    C. Create a new Source NAT Policy rule that matches the existing traffic and enable the Bi-directional option
    D. Create a new Destination NAT Policy rule that matches the existing traffic and enable the Bi-directional option

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCNSE exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.