About the Exam

Validates experienced network security engineers and firewall administrators on PAN-OS networking, device settings, integration and automation, object configuration, policy creation, and the management and operation of next-generation firewalls. It is designed for network engineers, security engineers, firewall engineers, firewall administrators, professional services consultants, network security support engineers, and others responsible for PAN-OS and firewall administration. Passing demonstrates job-ready skills for deploying, operating, and administering Palo Alto Networks NGFW products, including centralized management with Panorama, templates, and rulesets.

Exam Topics

  • PAN-OS Networking Configuration40%
  • PAN-OS Device Setting Configuration40%
  • Integration and Automation20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 7, 2026 at 2:10 AM

Topic filter
Retired questions
Question sort

QuestionQ1

PAN-OS Networking Configuration

In an active/active high-availability (HA) deployment using two PA-Series firewalls, how is the HA3 interface used by the firewalls?

  • A To forward packets to the HA peer during session setup and asymmetric traffic flow
  • B To exchange hellos, heartbeats, HA state information, and management plane synchronization for routing and User-ID information
  • C To synchronize sessions, forwarding tables, IPSec security associations, and ARP tables between firewalls in an HA pair
  • D To perform session cache synchronization among all HA peers having the same cluster ID
Explanation

In active/active HA, the HA3 link enables a firewall to forward packets to its HA peer for session setup and for processing asymmetrically routed traffic, including Layer 7 inspection. HA1 is the control link, HA2 carries state synchronization, and HA4 is used for session-cache synchronization among cluster members.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

PAN-OS Networking Configuration

While upgrading routing infrastructure in a customer environment, a network administrator plans to implement the Advanced Routing Engine (ARE) on a Palo Alto Networks firewall.

Which firewall models support this configuration?

Choose three
  • A PA-5280, PA-7080, PA-3250, VM-Series
  • B PA-455, VM-Series, PA-1410, PA-5450
  • C PA-3260, PA-5410, PA-850, PA-460
  • D PA-7050, PA-1420, VM-Series, CN-Series
Explanation

The Advanced Routing Engine is supported on PA-7000, PA-5400, PA-5200, PA-3200, PA-1400, and PA-400 Series firewalls, as well as VM-Series and CN-Series firewalls. Accordingly, the model groups in A, B, and D are supported. PA-850 is not included in the supported-platform list, so C is not valid.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

PAN-OS Networking Configuration

An organization is deploying VM-Series firewalls in Microsoft Azure to protect its VNets. A key requirement is for the security infrastructure to withstand the failure of an entire Azure Availability Zone.

What is the recommended approach to meet this objective?

  • A Deploy multiple, independent VM-Series firewalls in different Availability Zones and use an Azure Load Balancer to distribute traffic to them.
  • B Implement a Terraform configuration that automatically redeploys the firewall in a new zone if the original one fails.
  • C Use Azure Traffic Manager to direct traffic to a primary VM-Series firewall, with a second firewall in another zone as a failover target.
  • D Configure PAN-OS active/passive high availability (HA) between two VM-Series instances in separate Availability Zones using HA links over a VNet peering connection.
Explanation

Deploying independent VM-Series firewalls in separate Availability Zones behind an Azure Load Balancer provides resilience to an Availability Zone outage. The load balancer health-checks the instances and distributes traffic only to healthy firewalls, so loss of one zone does not eliminate the security path.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

PAN-OS Networking Configuration

When configuring a Zone Protection profile, under which section (protection type) would an NGFW engineer set options to defend against activities such as spoofed IP addresses and split-handshake session-establishment attempts?

  • A Flood Protection
  • B Protocol Protection
  • C Packet-Based Attack Protection
  • D Reconnaissance Protection
Explanation

Packet-Based Attack Protection includes IP Drop settings for spoofed IP addresses and TCP Drop settings for Split Handshake, which enforces the standard TCP three-way handshake.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

PAN-OS Networking Configuration

Which feature can be enabled on a Layer 3 interface but is unavailable on Layer 2 interfaces?

  • A NetFlow profile
  • B LLDP profile
  • C QoS profile
  • D DHCP client
Explanation

A DHCP client is configured on a Layer 3 interface to obtain a dynamically assigned IPv4 address. Layer 2 interfaces do not provide this Layer 3 IP-addressing function. NetFlow and LLDP can be used with Layer 2 interfaces as well.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home