Palo Alto Networks PCNSE Exam
Palo Alto Networks Certified Network Security Engineer (Page 21 )

Updated On: 12-Feb-2026

Which two methods can be used to verify firewall connectivity to AutoFocus? (Choose two.)

  1. Verify AutoFocus status using the CLI “test” command.
  2. Check the WebUI Dashboard AutoFocus widget.
  3. Check for WildFire forwarding logs.
  4. Check the license.
  5. Verify AutoFocus is enabled below Device Management tab.

Answer(s): D,E


Reference:

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/getting-started/enable-autofocus-threat-intelligence



Which CLI command enables an administrator to check the CPU utilization of the dataplane?

  1. show running resource-monitor
  2. debug data-plane dp-cpu
  3. show system resources
  4. debug running resources

Answer(s): A



Which DoS protection mechanism detects and prevents session exhaustion attacks?

  1. Packet Based Attack Protection
  2. Flood Protection
  3. Resource Protection
  4. TCP Port Scan Protection

Answer(s): C


Reference:

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/zone-protection-and-dos-protection/zone-defense/dos-protection-profiles-and-policy-rules/dos-protection-profiles



Which two subscriptions are available when configuring Panorama to push dynamic updates to connected devices? (Choose two.)

  1. Content-ID
  2. User-ID
  3. Applications and Threats
  4. Antivirus

Answer(s): C,D


Reference:

https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/device/device-dynamic-updates



View the GlobalProtect configuration screen capture. What is the purpose of this configuration?

  1. It configures the tunnel address of all internal clients to an IP address range starting at 192.168.10.1.
  2. It forces an internal client to connect to an internal gateway at IP address 192.168.10.1.
  3. It enables a client to perform a reverse DNS lookup on 192.168.10.1 to detect that it is an internal client.
  4. It forces the firewall to perform a dynamic DNS update, which adds the internal gateway’s hostname and IP address to the DNS server.

Answer(s): C


Reference:

https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/ globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-agent-configurations






Post your Comments and Discuss Palo Alto Networks PCNSE exam prep with other Community members:

Join the PCNSE Discussion