Sign In
Home/Palo Alto/PCSFE/Free questions

PCSFE — Free Practice Questions

10 free sample questions from a bank of 164, with the correct answers and explanations. No signup required — start practising right now.

1How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?
  • By using contracts between endpoint groups that send traffic to the firewall using a shared policy
  • Through a virtual machine (VM) monitor domain
  • Through a policy-based redirect (PBR)
  • By creating an access policy
Answer: C
2What are the two appropriate routing settings required to deploy software firewall integration with Amazon Web Service (AWS) GWLB? (Choose two.)
  • Route table with ALB subnet association - Add route destined to 0.0.0.0/0 with target as NAT Gateway
  • Route table with ALB subnet association - Add route destined to 0.0.0.0/0 with target as IGW
  • Route table with IGW edge association - Add route destined to ALB with target as GWLBE
  • Route table with GWLBE subnet association - Add route destined to 0.0.0.0/0 with target as IGW
Answer: A, D
3A user must be assigned one of which two roles in order to create local rulestacks in the Cloud NGFW for AWS tenant? (Choose two.)
  • LocalRuleStackAdmin
  • FirewallRulestackAdmin
  • GlobalRulestackAdmin
  • GlobalFirewallAdmin
Answer: A, B
4Which deployment method should a GCP administrator use to deploy a VM-Series firewall to secure east-west traffic between Virtual Private Clouds (VPCs)?
  • Internet gateway
  • Hybrid IPSec VPN
  • Segmentation gateway
  • GlobalProtect
Answer: C
5What are three attributes monitored by the Panorama AWS plugin? (Choose three.)
  • Private DNS name
  • Subnet ID
  • IAM instance profile
  • VPC ID
  • Public DNS name
Answer: B, C, D
6In the Cloud NGFW for AWS distributed outbound architecture model, what is the first hop the traffic takes from the source?
  • Internet gateway
  • Cloud NGFW
  • NGFW endpoint
  • NAT gateway
Answer: C
7Which port / interface must be assigned as the HA2 link when deploying VM-Series firewalls in High Availability (HA) on Amazon Web Services (AWS)?
  • HA2
  • MGT port
  • HSCI port
  • Ethernet1/1
Answer: D
8A system engineer is working on the Proof of Concept (POC) for Cloud Next-Generation Firewall (NGFW) for Azure using an existing Panorama setup. However, connection with the Cloud NGFW instance. What could be the cause of this issue?
  • There has not been an upgrade to the PAN-OS 10.2.
  • Cloud NGFW plugin has not been installed.
  • Valid device certificate is missing.
  • Necessary ports 8443 and 443 for communication between Cloud NGFW and Panorama are blocked.
Answer: A
9A system engineer managing a deployment of CN-Series with Panorama (software version 11.0) installs the Kubernetes Plugin. When the installation is complete, templates are present. What are the names of two of these templates and for what are they used? (Choose two.)
  • K8S-Network-Setup used for daemonset
  • K8S-Network-Setup-V2 used for Kubernetes as a service deployment
  • K8S-Network-Setup-V3 used for Kubernetes as a service deployment
  • K8S-Network-Setup-V3 used for CNF daemonset
Answer: A, B
10Which two statements apply to the management Cloud NGFW by AWS firewall manager? (Choose two.)
  • Availability Zone can be created.
  • Firewall policy can be included only with specified accounts and OUs.
  • Firewall policy must be applied to all accounts under the Amazon Web Services (AWS) organization.
  • Endpoints will be created via the firewall manager.
Answer: B, D

Want the full bank of 164 questions for PCSFE? See all practice exams.