Skip to content

PCCNSA Palo Alto Networks Certified Network Security Analyst Practice Questions

Prepare for PCCNSA with more than an answer.

299 questions in the full set20 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Palo Alto Networks Certified Network Security Analyst 130 questions Locked
  • PCCNSALegacy Palo Alto Networks Certified Network Security Analyst 299 questions Current
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 4
  1. Object Configuration Creation and Application30%
  2. Policy Creation and Application30%
  3. Management and Operations26%
  4. Troubleshooting14%
  1. 1

    A security administrator notices that a Security Policy allowing 'ssl' and 'web-browsing' is not matching traffic as expected. The traffic is being dropped by the default deny rule. Investigation shows the traffic is identified as 'google-base'. What is the correct way to fix this using App-ID best practices?

    Show answer details

    Correct answer: B

    App-ID identifies the specific application. Since the firewall identified the traffic as 'google-base' (which depends on web-browsing/ssl), you must explicitly allow 'google-base' in the policy for it to pass.

  2. 2

    Which three actions are required to successfully implement a Decryption Policy for outbound SSL traffic? (Select THREE)

    Show answer details

    Correct answer: A, D, E

    The firewall needs a CA cert to resign the traffic.

    Required to present to clients when the original server certificate is untrusted.

    The policy rule triggers the decryption engine.

  3. 3

    An organization uses a proprietary backup application that uses a dynamic range of high ports and does not have a standard handshake. The firewall keeps dropping the traffic or misidentifying it. The backup server is at IP 10.1.1.50. What is the most appropriate solution to ensure this traffic passes reliably without disabling security for other traffic?

    Show answer details

    Correct answer: D

    Application Override bypasses the App-ID engine's deep inspection, forcing the traffic to be identified as the specified custom app. This is ideal for high-throughput, proprietary internal applications that might otherwise be misidentified or consume excessive resources.

  4. 4

    You need to route internet traffic from a specific VLAN (10.10.10.0/24) through a secondary ISP link (ethernet1/2), while all other traffic uses the primary ISP (ethernet1/1). The secondary ISP gateway is 203.0.113.1. Which policy type and configuration is required?

    Show answer details

    Correct answer: D

    PBF overrides the virtual router's routing table based on policy criteria (like source IP). Specifying the egress interface and next-hop IP directs the traffic correctly.

  5. 5

    Case Study:

    Scenario:
    TechGlobal Inc. has a main office and three branch offices. They are transitioning to an SD-WAN architecture managed via Strata Cloud Manager.

    Requirements:

    1. Real-time video traffic (Zoom, Teams) must use the link with the lowest latency.
    2. Bulk file transfers (SMB, FTP) should use the link with the most available bandwidth.
    3. If the primary link's packet loss exceeds 2%, video traffic must failover immediately.

    Configuration:
    You have created an SD-WAN Interface Profile and mapped the physical links.

    Which combination of SD-WAN configuration objects is required to meet these requirements?

    Show answer details

    Correct answer: D

    This correctly maps the requirements. Path Quality Profiles handle the SLA (loss/latency) for video. Traffic Distribution Profiles control how traffic is load-balanced (bandwidth usage) for bulk. SD-WAN Policy rules bind these apps to the profiles.

  6. 6

    A network security analyst needs to configure a Security Profile Group to protect a high-security finance zone. The requirement dictates that all web traffic must be inspected for known malware, command-and-control traffic, and drive-by downloads. Additionally, the organization wants to strictly block any file uploads to untrusted file sharing sites while allowing downloads. Which combination of profiles and actions in the Security Profile Group satisfies these requirements?

    Show answer details

    Correct answer: C

    To meet the requirements: Antivirus blocks known malware; Anti-Spyware blocks command-and-control traffic; and File Blocking can be configured with a specific profile to block the 'upload' direction for file sharing categories while allowing 'download'. URL Filtering is used here but the critical control for file direction is within the File Blocking profile.

  7. 7

    An organization is deploying SSL Decryption using Strata Cloud Manager. They need to decrypt outbound traffic from internal users to the internet to inspect for threats. However, they must ensure that banking and healthcare websites are NOT decrypted due to privacy compliance and certificate pinning issues. Which type of Decryption Profile and Policy configuration should be applied?

    Show answer details

    Correct answer: D

    SSL Forward Proxy is the correct mode for outbound user traffic. To exempt specific categories like banking and health, a 'No-Decrypt' policy rule matching those URL categories must be placed before the general decryption rule.

  8. 8

    A security analyst is configuring an External Dynamic List (EDL) to block malicious IP addresses provided by a third-party threat intelligence feed. The feed updates every 30 minutes. The analyst configures the EDL in Strata Cloud Manager but notices that new IPs from the feed are not being blocked immediately. What is the most likely cause of this delay?

    Show answer details

    Correct answer: B

    EDLs have a configurable update frequency (e.g., Five Minutes, Hourly, Daily). If the firewall is configured to check daily, it will miss the 30-minute updates from the source until the next scheduled check.

  9. 9

    An administrator needs to create a custom URL category to control access to a specific set of internal partner portals that do not share a common domain but follow a specific naming convention in the URL path. Which method is most appropriate for defining this custom object?

    Show answer details

    Correct answer: D

    Custom URL Categories support pattern matching (wildcards) which allows matching specific path segments across different domains, satisfying the requirement.

  10. 10

    A financial institution requires that all 'Credit Card Numbers' detected in outbound file transfers be blocked, but 'Social Security Numbers' should only generate an alert for auditing purposes. Both data types are detected using predefined data patterns. How should the Data Security Profile be configured?

    Show answer details

    Correct answer: B

    A single Data Security Profile can contain multiple data filtering rules with different actions (Block vs Alert) for different data patterns.

Create an account to continue.