Palo Alto Networks PCNSE Exam
Palo Alto Networks Certified Network Security Engineer (Page 13 )

Updated On: 15-Feb-2026

An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing.

The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown. The next two entries show traffic allowed as application SSL.

Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?

  1. Create a decryption rule matching the encrypted BitTorrent traffic with action “No-Decrypt,” and place the rule at the top of the Decryption policy.
  2. Create a Security policy rule that matches application “encrypted BitTorrent” and place the rule at the top of the Security policy.
  3. Disable the exclude cache option for the firewall.
  4. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the decryption rule.

Answer(s): D


Reference:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRtCAK



Refer to the exhibit.

Which certificates can be used as a Forward Trust certificate?

  1. Certificate from Default Trust Certificate Authorities
  2. Domain Sub-CA
  3. Forward_Trust
  4. Domain-Root-Cert

Answer(s): B



Which option would an administrator choose to define the certificate and protocol that Panorama and its managed devices use for SSL/TLS services?

  1. Configure a Decryption Profile and select SSL/TLS services.
  2. Set up SSL/TLS under Policies > Service/URL Category > Service.
  3. Set up Security policy rule to allow SSL communication.
  4. Configure an SSL/TLS Profile.

Answer(s): D


Reference:

https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/device/device-certificate-management-ssltls-service-profile



Which menu item enables a firewall administrator to see details about traffic that is currently active through the NGFW?

  1. ACC
  2. System Logs
  3. App Scope
  4. Session Browser

Answer(s): D



Which protection feature is available only in a Zone Protection Profile?

  1. SYN Flood Protection using SYN Flood Cookies
  2. ICMP Flood Protection
  3. Port Scan Protection
  4. UDP Flood Protections

Answer(s): C






Post your Comments and Discuss Palo Alto Networks PCNSE exam prep with other Community members:

Join the PCNSE Discussion