PCNSA PREP -PALO ALTO NETWORKS |ACTUAL
QUESTIONS AND VERIFIED ANSWERS|BRAND NEW
2026-2027 UPDATE|GRADED A+
Question 1
Which Palo Alto Networks firewall security platform provides network security for mobile
endpoints by inspecting traffic deployed as internet gateways?
A. GlobalProtect
B. AutoFocus
C. Aperture
D. Panorama
CORRECT ANSWER
A. GlobalProtect
Question 2
An administrator receives a global notification for a new malware that infects hosts. The
infection will result in the infected host attempting to contact a command-and-control (C2)
server. Which two security profile components will detect and prevent this threat after the
firewall's signature database has been updated? (Choose two.)
A. vulnerability protection profile applied to outbound security policies
B. anti-spyware profile applied to outbound security policies
C. antivirus profile applied to outbound security policies
D. URL filtering profile applied to outbound security policies
CORRECT ANSWER
B, D - p. 140-141
1
,Question 3
When is the content inspection performed in the packet flow process?
A. after the application has been identified
B. after the SSL Proxy re-encrypts the packet
C. before the packet forwarding process
D. before session lookup
CORRECT ANSWER
A - p. 122
Question 4
An administrator is configuring a NAT ruleAt a minimum, which three forms of information
are required? (Choose three.)
A. name
B. source zone
C. destination interface
D. destination address
E. destination zone
CORRECT ANSWER
B,D,E - p. 133-134
Question 5
Based on the graphic, what is the purpose of the SSL/TLS Service profile configuration
option?
2
,A. It defines the SSUTLS encryption strength used to protect the management interface.
B. It defines the CA certificate used to verify the client's browser.
C. It defines the certificate to send to the client's browser from the management interface.
D. It defines the firewall's global SSL/TLS timeout values.
CORRECT ANSWER
Question 6
In the example security policy shown, which two websites are blocked? (Choose two.)
A. LinkedIn
B. Facebook
C. YouTube
D. Amazon
CORRECT ANSWER
A, B
Question 7
Which attribute can a dynamic address group use as a filtering condition to determine its
membership?
A. tag
B. wildcard mask
C. IP address
D. subnet mask
CORRECT ANSWER
3
, A - p. 85-86
Question 8
A network administrator is required to use a dynamic routing protocol for network
connectivity.
Which three dynamic routing protocols are supported by the NGFW Virtual Router for this
purpose? (Choose three.)
A. RIP
B. OSPF
C. IS-IS
D. EIGRP
E. BGP
CORRECT ANSWER
A,B,E-p.64
Question 9
After making multiple changes to the candidate configuration of a firewall, the
administrator would like to start over with a candidate configuration that matches the
running configuration.
Which command in Device > Setup > Operations would provide the most operationally
efficient way to accomplish this?
A. Import named config snapshot
B. Load named configuration snapshot
C. Revert to running configuration
D. Revert to last saved configuration
CORRECT ANSWER
B - p. 23
4
QUESTIONS AND VERIFIED ANSWERS|BRAND NEW
2026-2027 UPDATE|GRADED A+
Question 1
Which Palo Alto Networks firewall security platform provides network security for mobile
endpoints by inspecting traffic deployed as internet gateways?
A. GlobalProtect
B. AutoFocus
C. Aperture
D. Panorama
CORRECT ANSWER
A. GlobalProtect
Question 2
An administrator receives a global notification for a new malware that infects hosts. The
infection will result in the infected host attempting to contact a command-and-control (C2)
server. Which two security profile components will detect and prevent this threat after the
firewall's signature database has been updated? (Choose two.)
A. vulnerability protection profile applied to outbound security policies
B. anti-spyware profile applied to outbound security policies
C. antivirus profile applied to outbound security policies
D. URL filtering profile applied to outbound security policies
CORRECT ANSWER
B, D - p. 140-141
1
,Question 3
When is the content inspection performed in the packet flow process?
A. after the application has been identified
B. after the SSL Proxy re-encrypts the packet
C. before the packet forwarding process
D. before session lookup
CORRECT ANSWER
A - p. 122
Question 4
An administrator is configuring a NAT ruleAt a minimum, which three forms of information
are required? (Choose three.)
A. name
B. source zone
C. destination interface
D. destination address
E. destination zone
CORRECT ANSWER
B,D,E - p. 133-134
Question 5
Based on the graphic, what is the purpose of the SSL/TLS Service profile configuration
option?
2
,A. It defines the SSUTLS encryption strength used to protect the management interface.
B. It defines the CA certificate used to verify the client's browser.
C. It defines the certificate to send to the client's browser from the management interface.
D. It defines the firewall's global SSL/TLS timeout values.
CORRECT ANSWER
Question 6
In the example security policy shown, which two websites are blocked? (Choose two.)
A. LinkedIn
B. Facebook
C. YouTube
D. Amazon
CORRECT ANSWER
A, B
Question 7
Which attribute can a dynamic address group use as a filtering condition to determine its
membership?
A. tag
B. wildcard mask
C. IP address
D. subnet mask
CORRECT ANSWER
3
, A - p. 85-86
Question 8
A network administrator is required to use a dynamic routing protocol for network
connectivity.
Which three dynamic routing protocols are supported by the NGFW Virtual Router for this
purpose? (Choose three.)
A. RIP
B. OSPF
C. IS-IS
D. EIGRP
E. BGP
CORRECT ANSWER
A,B,E-p.64
Question 9
After making multiple changes to the candidate configuration of a firewall, the
administrator would like to start over with a candidate configuration that matches the
running configuration.
Which command in Device > Setup > Operations would provide the most operationally
efficient way to accomplish this?
A. Import named config snapshot
B. Load named configuration snapshot
C. Revert to running configuration
D. Revert to last saved configuration
CORRECT ANSWER
B - p. 23
4