Skip to content

NGFW-ENGINEER Next-Generation Firewall Engineer Practice Questions

Prepare for NGFW-ENGINEER with more than an answer.

228 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 3
  1. PAN-OS Networking Configuration38%
  2. PAN-OS Device Setting Configuration40%
  3. Integration and Automation22%
  1. 1

    Case Study: A retail company, 'StyleStream', is centralizing its IT infrastructure. They have two main data centers (DC1 and DC2) and are using Panorama to manage a pair of PA-5450 firewalls in each data center. The firewalls in each DC are configured as an active/passive HA pair. StyleStream's primary requirement is to maintain consistent security policies across both data centers while allowing for some site-specific configurations, such as different NAT policies for their local internet breakouts.

    The network team has created a device group hierarchy in Panorama. They have a parent 'Global' device group and two child device groups: 'DC1-Firewalls' and 'DC2-Firewalls'. The goal is to push all common security rules, objects, and profiles from the 'Global' device group, while NAT rules and specific interface configurations are managed in the child device groups. An engineer has created a set of shared security rules in the 'Global' device group.

    After pushing the configuration, the engineer observes that the NAT policies configured locally in the 'DC1-Firewalls' device group are not being applied to traffic. Instead, traffic is matching a broader outbound rule from the 'Global' device group. Which configuration in Panorama is necessary to ensure that the site-specific NAT policies in the child device group are evaluated before the shared rules in the parent device group?

    Show answer details

    Correct answer: D

    Panorama evaluates rules based on a specific hierarchy. 'Pre-rules' from all device groups in the hierarchy (from the specific child DG up to the highest parent DG) are evaluated first. Then, local firewall rules are evaluated. Finally, 'post-rules' from all device groups are evaluated. To ensure the site-specific NAT policies in the 'DC1-Firewalls' group are processed before the general rules in the 'Global' group, the DC1 rules must be configured as 'pre-rules'. This guarantees they are matched before any broader 'post-rules' or even other 'pre-rules' from the parent 'Global' device group.

  2. 2

    A firewall administrator is configuring User-ID and has integrated with an Active Directory server for group mapping. The goal is to create a security policy for users in the 'Finance' group. However, the 'Finance' group is nested inside the 'Departments' group in Active Directory. By default, will the firewall be able to identify a user as a member of the 'Finance' group?

    Show answer details

    Correct answer: A

    PAN-OS supports nested groups in Active Directory, but for performance reasons, this feature is not enabled by default. To make the firewall aware of nested group memberships, the administrator must explicitly enable 'Nested Groups' within the specific Group Mapping configuration profile under the 'Group Include List' tab. Without this setting, the firewall will only see the top-level group memberships.

  3. 3

    To enhance security for a site-to-site VPN, an engineer is implementing a route-based VPN with BGP running over the tunnel. Which two configuration elements are necessary on the Palo Alto Networks firewall for this setup? (Choose two.)

    Show answer details

    Correct answer: B, D

    Route-based VPNs use a Tunnel Interface as the logical endpoint for the VPN. This interface must be placed in a security zone and virtual router to participate in routing. To run BGP over the tunnel, you configure BGP peering using the IP addresses assigned to the tunnel interfaces on each side as the BGP neighbor addresses. Proxy IDs are used in policy-based VPNs, not route-based VPNs where routing protocols determine the traffic to be encrypted.

  4. 4

    A new PAN-OS software version has been downloaded to a firewall. An administrator needs to perform the upgrade during a maintenance window but wants to ensure they can quickly revert to the previous version if any issues arise. What is the recommended first step to take on the firewall immediately before installing the new software version?

    Show answer details

    Correct answer: C

    Before performing a software upgrade, it is a critical best practice to save or export the current configuration and device state. This creates a snapshot of the running configuration, which can be used to quickly restore the firewall to its pre-upgrade state. The firewall also has a 'revert' link next to the previously running software version, but having an external backup is a crucial safety measure.

  5. 5

    An engineer has deployed a VM-Series firewall in Microsoft Azure. To comply with company policy, all administrative access to the firewall must use Azure Active Directory credentials. What PAN-OS authentication method should be configured to achieve this?

    Show answer details

    Correct answer: D

    To integrate with cloud-based identity providers like Azure Active Directory for administrative access, SAML (Security Assertion Markup Language) is the appropriate authentication method. The firewall is configured as a SAML Service Provider (SP), and Azure AD is configured as the SAML Identity Provider (IdP). This allows the firewall to redirect authentication requests to Azure AD, enabling single sign-on and centralized identity management.

  6. 6

    A financial services company is deploying an active/active HA cluster of PA-5450 firewalls. To meet compliance requirements, all traffic for a specific high-frequency trading application must have session state mirrored in real-time. However, to optimize resource usage, sessions for general internet browsing should not be synchronized. Which configuration achieves this specific requirement?

    Show answer details

    Correct answer: A

    In an active/active HA configuration, session synchronization is enabled globally. To selectively exclude certain sessions from being synchronized, you create a security policy rule that matches the specific traffic (in this case, general internet browsing) and select the 'Do not sync session' option within that rule's action settings. This provides granular control over HA resource utilization while ensuring critical application sessions are fully synchronized. Denying the traffic is incorrect, and session sync cannot be configured per-application or with different settings in multiple rules.

  7. 7

    A network security team is leveraging the PAN-OS XML API to automate the creation of address objects. The team needs to create a new address object named 'Prod-DB-Server' with the IP address '10.100.5.25' on a firewall managed by Panorama. Which XPath is required to correctly target the location for this new object within the API call?

    Show answer details

    Correct answer: D

    When configuring objects on a firewall managed by Panorama, the configuration is typically pushed via Device Groups. The '/config/shared/' XPath is used to target the shared scope within Panorama, from which objects can be referenced by device groups. The other XPaths refer to a local firewall configuration ('localhost.localdomain'), a specific device group, or a non-existent path.

  8. 8

    During a security audit, it was discovered that administrators were using non-compliant TLS versions to manage a PA-3410 firewall. The security architect has mandated that only TLSv1.3 be used for all management connections. Which component must be configured and applied to the management interface to enforce this policy?

    Show answer details

    Correct answer: A

    An SSL/TLS Service Profile is used to define the specific SSL/TLS protocol versions and cipher suites that the firewall will use for services it hosts, such as the management web UI. By creating a profile that only permits TLSv1.3 and applying it to the management interface, all other protocol versions will be rejected. Decryption profiles are for inspecting traffic, a Certificate Profile is for client certificate validation, and an Interface Mgmt profile enables services but does not control the TLS version.

  9. 9

    A consultant is designing a network with a PA-850 firewall that must inspect traffic between two switch ports in a strictly transparent mode without participating in spanning-tree. The firewall should not perform any routing or NAT and must be invisible to the connected devices. Which interface type configuration meets all these requirements?

    Show answer details

    Correct answer: D

    A Virtual Wire interface pair connects two physical interfaces on the firewall, allowing traffic to pass between them transparently. It does not have an IP address, does not participate in routing, and does not process spanning-tree BPDUs by default, making it logically invisible on the network. This perfectly matches the requirement for transparent inspection without network participation. Layer 2 interfaces participate in switching and spanning-tree, and Layer 3 interfaces participate in routing.

  10. 10

    True or False: When configuring a PAN-OS firewall as an explicit web proxy, the firewall must have a Layer 3 interface configured in the same security zone as the clients to intercept the proxy requests.

    Show answer details

    Correct answer: A

    For the firewall to act as an explicit proxy, clients must be able to route traffic directly to it. This requires the firewall to have a Layer 3 interface with an IP address that is reachable by the clients. This interface must be in a security zone from which traffic is allowed to be proxied.

Create an account to continue.