Palo Alto Networks Certified Next-Generation Firewall Engineer Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 228 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NGFW-ENGINEER Sample Questions

  1. Question 1

    Q1

    A financial services company is deploying an active/active HA cluster of PA-5450 firewalls. To meet compliance requirements, all traffic for a specific high-frequency trading application must have session state mirrored in real-time. However, to optimize resource usage, sessions for general internet browsing should not be synchronized. Which configuration achieves this specific requirement?

    Show answer & explanation

    Correct answer: D

    In an active/active HA configuration, session synchronization is enabled globally. To selectively exclude certain sessions from being synchronized, you create a security policy rule that matches the specific traffic (in this case, general internet browsing) and select the 'Do not sync session' option within that rule's action settings. This provides granular control over HA resource utilization while ensuring critical application sessions are fully synchronized. Denying the traffic is incorrect, and session sync cannot be configured per-application or with different settings in multiple rules.

  2. Question 2

    Q2

    A network security team is leveraging the PAN-OS XML API to automate the creation of address objects. The team needs to create a new address object named 'Prod-DB-Server' with the IP address '10.100.5.25' on a firewall managed by Panorama. Which XPath is required to correctly target the location for this new object within the API call?

    Show answer & explanation

    Correct answer: B

    When configuring objects on a firewall managed by Panorama, the configuration is typically pushed via Device Groups. The '/config/shared/' XPath is used to target the shared scope within Panorama, from which objects can be referenced by device groups. The other XPaths refer to a local firewall configuration ('localhost.localdomain'), a specific device group, or a non-existent path.

  3. Question 3

    Q3

    During a security audit, it was discovered that administrators were using non-compliant TLS versions to manage a PA-3410 firewall. The security architect has mandated that only TLSv1.3 be used for all management connections. Which component must be configured and applied to the management interface to enforce this policy?

    Show answer & explanation

    Correct answer: B

    An SSL/TLS Service Profile is used to define the specific SSL/TLS protocol versions and cipher suites that the firewall will use for services it hosts, such as the management web UI. By creating a profile that only permits TLSv1.3 and applying it to the management interface, all other protocol versions will be rejected. Decryption profiles are for inspecting traffic, a Certificate Profile is for client certificate validation, and an Interface Mgmt profile enables services but does not control the TLS version.

  4. Question 4

    Q4

    A consultant is designing a network with a PA-850 firewall that must inspect traffic between two switch ports in a strictly transparent mode without participating in spanning-tree. The firewall should not perform any routing or NAT and must be invisible to the connected devices. Which interface type configuration meets all these requirements?

    Show answer & explanation

    Correct answer: C

    A Virtual Wire interface pair connects two physical interfaces on the firewall, allowing traffic to pass between them transparently. It does not have an IP address, does not participate in routing, and does not process spanning-tree BPDUs by default, making it logically invisible on the network. This perfectly matches the requirement for transparent inspection without network participation. Layer 2 interfaces participate in switching and spanning-tree, and Layer 3 interfaces participate in routing.

  5. Question 5

    Q5

    True or False: When configuring a PAN-OS firewall as an explicit web proxy, the firewall must have a Layer 3 interface configured in the same security zone as the clients to intercept the proxy requests.

    Show answer & explanation

    Correct answer: A

    For the firewall to act as an explicit proxy, clients must be able to route traffic directly to it. This requires the firewall to have a Layer 3 interface with an IP address that is reachable by the clients. This interface must be in a security zone from which traffic is allowed to be proxied.

  6. Question 6

    Q6Multiple answers

    A company has deployed CN-Series firewalls to secure its Kubernetes cluster. The DevOps team wants to ensure that security policies are automatically applied to new application pods based on Kubernetes labels without manual intervention. Which TWO components are essential for this integration? (Choose TWO).

    Show answer & explanation

    Correct answers: A, C

  7. Question 7

    Q7

    An engineer is troubleshooting a BGP peering issue between a Palo Alto Networks firewall and a Cisco router. The firewall's system logs show the BGP state is stuck in 'Active'. What is the most likely cause of this issue from the perspective of the Palo Alto Networks firewall?

    Show answer & explanation

    Correct answer: A

    The BGP 'Active' state indicates that the firewall is actively trying to establish a TCP connection (on port 179) with its peer but is not receiving a response. This is often due to a network connectivity issue, such as an intermediate firewall blocking the connection, an incorrect peer IP address, or a routing problem preventing the TCP SYN packet from reaching the peer or the SYN-ACK from returning. An 'Idle' state would mean it's waiting, 'Connect' means TCP is established and waiting for an OPEN message, and 'Established' is a successful peering.

  8. Question 8

    Q8Multiple answers

    A hospital is using a PA-3220 firewall to segment its network. They have created a custom application signature for their Electronic Health Record (EHR) system. The security policy must allow access to the EHR system only for users in the 'Clinical-Staff' Active Directory group. All other access attempts to the EHR servers must be blocked and logged. Which two security policy rules, in the correct order, are required to implement this? (Choose two.)

    Show answer & explanation

    Correct answers: A, C

  9. Question 9

    Q9

    An organization wants to provide remote access to its developers. The requirements are:

    • All developer traffic must be routed through the corporate firewall for inspection.
    • Developers should NOT be able to access their local network resources while connected to the VPN.
    • The solution must be centrally managed via Panorama.

    Which GlobalProtect configuration on the Gateway will enforce these requirements?

    Show answer & explanation

    Correct answer: B

    Disabling split tunneling (also known as 'tunnel all' mode) forces all traffic from the client, including internet-bound traffic, through the GlobalProtect VPN tunnel. This meets the requirement for full traffic inspection. Additionally, the 'No direct access to local network' option, which is part of the agent configuration pushed from the portal, prevents the user from accessing their local network resources, satisfying the second requirement.

  10. Question 10

    Q10

    A company is using Terraform to manage its Cloud NGFW for AWS deployment. The lead engineer needs to define a ruleset that will be applied to multiple firewall resources. Which Terraform resource should be used to define a reusable collection of security rules?

    Show answer & explanation

    Correct answer: B

    In the Palo Alto Networks Cloud NGFW provider for Terraform, the paloaltonetworks_cloudngfw_aws_rule_stack resource is used to define a collection of security rules (a ruleset). This rule stack can then be associated with one or more paloaltonetworks_cloudngfw_aws_firewall resources, allowing for the definition of reusable, modular security policies.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NGFW-ENGINEER sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 228 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon