Palo Alto Networks PCNSE Exam Questions
Palo Alto Networks Certified Network Security Engineer (Page 11 )

Updated On: 15-Feb-2026

Which three authentication services can an administrator use to authenticate admins into the Palo Alto Networks NGFW without defining a corresponding admin account on the local firewall? (Choose three.)

  1. Kerberos
  2. PAP
  3. SAML
  4. TACACS+
  5. RADIUS
  6. LDAP

Answer(s): C,D,E



Which event will happen if an administrator uses an Application Override Policy?

  1. Threat-ID processing time is decreased.
  2. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.
  3. The application name assigned to the traffic by the security rule is written to the Traffic log.
  4. App-ID processing time is increased.

Answer(s): B


Reference:

https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513



Which Security policy rule will allow an admin to block facebook chat but allow Facebook in general?

  1. Deny application facebook-chat before allowing application facebook
  2. Deny application facebook on top
  3. Allow application facebook on top
  4. Allow application facebook before denying application facebook-chat

Answer(s): A


Reference:

https://live.paloaltonetworks.com/t5/Configuration-Articles/Failed-to-Block-Facebook-Chat-Consistently/ta-p/115673



A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers.Which option will protect the individual servers?

  1. Enable packet buffer protection on the Zone Protection Profile.
  2. Apply an Anti-Spyware Profile with DNS sinkholing.
  3. Use the DNS App-ID with application-default.
  4. Apply a classified DoS Protection Profile.

Answer(s): D



If the firewall is configured for credential phishing prevention using the “Domain Credential Filter” method, which login will be detected as credential theft?

  1. Mapping to the IP address of the logged-in user.
  2. First four letters of the username matching any valid corporate username.
  3. Using the same user’s corporate username and password.
  4. Matching any valid corporate username.

Answer(s): C






Post your Comments and Discuss Palo Alto Networks PCNSE exam dumps with other Community members:

Join the PCNSE Discussion