TechNuggets Academy

Core Concepts

Free Palo Alto Networks Certified Network Security Engineer practice — 6 questions on Core Concepts, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 1: Core Concepts
A firewall is connected to a switch SPAN port using a Tap interface for passive traffic visibility. The security team configures a Vulnerability Protection profile with the action set to 'Reset Both' and attaches it to a security policy rule matching the tapped traffic, expecting the firewall to terminate sessions matching known exploit signatures. What is the actual result?
Tap mode is strictly passive/out-of-band — the firewall only receives a mirrored copy of traffic and has no ability to forward, block, or inject packets. Security profiles still run and generate logs/alerts, but any blocking action (reset-client, reset-server, reset-both, drop) has no effect on the actual traffic flow.
Question 2 of 6 · Domain 1: Core Concepts
A firewall is deployed in virtual wire mode between a core switch and a router. The organization has three VLANs (10, 20, 30) trunked across this link and requires each VLAN's traffic to be inspected and separated into its own security zone for distinct policy enforcement, without adding physical interfaces or changing the Layer 2/3 topology upstream. Which configuration achieves this?
Virtual wire subinterfaces let you tag specific VLAN IDs on a vwire pair and map each tagged VLAN to a distinct zone. This provides Layer 2 transparency (no routing/topology change) while still allowing granular, VLAN-based security policy enforcement — a core vwire capability tested on the PCNSE.
Question 3 of 6 · Domain 1: Core Concepts
A destination NAT rule translates the public address 203.0.113.10 (received on the Untrust zone) to the internal server 10.1.1.50 residing in the DMZ zone. When writing the corresponding Security policy rule to permit this traffic, which destination address and zone should the administrator reference?
PAN-OS evaluates Security policy using the original (pre-NAT) packet addresses/ports for matching, but uses the post-NAT destination zone because the zone lookup occurs after the NAT policy lookup determines the egress interface/zone. This mixed pre/post-NAT behavior is one of the most heavily tested packet-flow concepts on the PCNSE.
Question 4 of 6 · Domain 1: Core Concepts
Which statement accurately describes a defining characteristic of PAN-OS's Single-Pass Parallel Processing (SP3) architecture as it relates to traffic classification and content inspection?
Single-pass architecture performs networking, policy lookup, App-ID classification, and content scanning (threat, URL, data filtering) in one integrated pass over the traffic stream, rather than making multiple sequential passes — this is the primary throughput/latency advantage over traditional multi-engine UTM designs.
Question 5 of 6 · Domain 1: Core Concepts
A retail company wants the firewall to enforce security policy between three VLANs on the same physical segment, but does not want the firewall to perform any Layer 3 routing or change the existing IP addressing/gateway scheme — end hosts should continue to use their existing default gateway (a separate router). Which deployment model satisfies this requirement?
Layer 2 deployment lets the firewall act as a transparent switch, forwarding frames based on MAC address within a VLAN object while enforcing security policy on inter-VLAN traffic passing through different zones — with no change to IP addressing, gateways, or routing.
Question 6 of 6 · Domain 1: Core Concepts
An administrator has a security zone named 'DC-VirtualWire' containing two virtual wire interfaces. They attempt to add a Layer 3 interface (ethernet1/5) to this same zone to consolidate policy management. What happens when they try to commit this configuration?
PAN-OS enforces that a single security zone can only contain interfaces of the same deployment mode. Mixing a Layer 3 interface with virtual wire interfaces in the same zone is not permitted and will cause a validation error on commit.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →