PCNSE Exam Details

  • Exam Code
    :PCNSE
  • Exam Name
    :Palo Alto Networks Certified Network Security Engineer - PAN-OS 11.x (PCNSE)
  • Certification
    :Palo Alto Networks Certifications
  • Vendor
    :Palo Alto Networks
  • Total Questions
    :860 Q&As
  • Last Updated
    :Mar 23, 2026

Palo Alto Networks PCNSE Online Questions & Answers

  • Question 361:

    An administrator discovers that a file blocked by the WildFire inline ML feature on the firewall is a false-positive action. How can the administrator create an exception for this particular file?

    A. Add partial hash and filename in the file section of the WildFire inline ML tab of the Antivirus profile.
    B. Set the WildFire inline ML action to allow for that protocol on the Antivirus profile.
    C. Add the related Threat ID in the Signature exceptions tab of the Antivirus profile.
    D. Disable the WildFire profile on the related Security policy.

  • Question 362:

    What are the differences between using a service versus using an application for Security Policy match?

    A. Use of a "service" enables the firewall to take action after enough packets allow for App-ID identification
    B. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers Use of an "application" allows the firewall to take action after enough packets allow for App-ID identification regardless of the ports being used.
    C. There are no differences between "service" or "application" Use of an "application" simplifies configuration by allowing use of a friendly application name instead of port numbers.
    D. Use of a "service" enables the firewall to take immediate action with the first observed packet based on port numbers. Use of an "application" allows the firewall to take immediate action it the port being used is a member of the application standard port list

  • Question 363:

    Cortex XDR notifies an administrator about grayware on the endpoints.

    There are no entnes about grayware in any of the logs of the corresponding firewall.

    Which setting can the administrator configure on the firewall to log grayware verdicts?

    A. within the log settings option in the Device tab
    B. within the log forwarding profile attached to the Security policy rule
    C. in WildFire General Settings, select "Report Grayware Files"
    D. in Threat General Settings^ select "Report Grayware Files"

  • Question 364:

    What will be the source address in the ICMP packet?

    A. 10.30.0.93
    B. 10.46.72.93
    C. 10.46.64.94
    D. 192.168.93.1

  • Question 365:

    An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance. Which interface type and license feature are necessary to meet the requirement?

    A. Decryption Mirror interface with the Threat Analysis license
    B. Virtual Wire interface with the Decryption Port Export license
    C. Tap interface with the Decryption Port Mirror license
    D. Decryption Mirror interface with the associated Decryption Port Mirror license

  • Question 366:

    After configuring HA in Active/Passive mode on a pair of firewalls the administrator gets a failed commit with the following details.

    What are two explanations for this type of issue? (Choose two)

    A. The peer IP is not included in the permit list on Management Interface Settings
    B. The Backup Peer HA1 IP Address was not configured when the commit was issued
    C. Either management or a data-plane interface is used as HA1-backup
    D. One of the firewalls has gone into the suspended state

  • Question 367:

    Before an administrator of a VM-500 can enable DoS and zone protection, what actions need to be taken?

    A. Measure and monitor the CPU consumption of the firewall data plane to ensure that each firewall is properly sized to support DoS and zone protection
    B. Create a zone protection profile with flood protection configured to defend an entire egress zone against SYN. ICMP ICMPv6, UDP. and other IP flood attacks
    C. Add a WildFire subscription to activate DoS and zone protection features
    D. Replace the hardware firewall because DoS and zone protection are not available with VM-Series systems

  • Question 368:

    A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial of-service attacks.

    How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?

    A. Define a custom App-ID to ensure that only legitimate application traffic reaches the server
    B. Add QoS Profiles to throttle incoming requests
    C. Add a tuned DoS Protection Profile
    D. Add an Anti-Spyware Profile to block attacking IP address

  • Question 369:

    Which two features require another license on the NGFW? (Choose two.)

    A. SSL Inbound Inspection
    B. SSL Forward Proxy
    C. Decryption Mirror
    D. Decryption Broker

  • Question 370:

    Refer to the diagram.

    An administrator needs to create an address object that will be useable by the NYC. MA, CA and WA device groups.

    Where will the object need to be created within the device-group hierarchy?

    A. Americas
    B. US
    C. East
    D. West

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Palo Alto Networks exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PCNSE exam preparations and Palo Alto Networks certification application, do not hesitate to visit our Vcedump.com to find your solutions here.