NGFW-ENGINEER Sample Questions

NGFW-ENGINEER Sample Questions & Answers

Centers on two closely tied heavyweights: setting up authentication roles, virtual systems and logging, and configuring high availability alongside interfaces and zones, rounded out by deployment options, API-driven automation, and integrating third-party services.

Launch the full NGFW-ENGINEER simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 2

    Integration and Automation · Install the selected deployment option

    A company has deployed CN-Series firewalls to secure its Kubernetes cluster. The DevOps team wants to ensure that security policies are automatically applied to new application pods based on Kubernetes labels without manual intervention. Which TWO components are essential for this integration? (Choose TWO).

    Show answer & explanation

    Correct answers: A, C

  2. Question 2Intermediate

    PAN-OS Networking Configuration · Configure routing

    An engineer is troubleshooting a BGP peering issue between a Palo Alto Networks firewall and a Cisco router. The firewall's system logs show the BGP state is stuck in 'Active'. What is the most likely cause of this issue from the perspective of the Palo Alto Networks firewall?

    Show answer & explanation

    Correct answer: A

    The BGP 'Active' state indicates that the firewall is actively trying to establish a TCP connection (on port 179) with its peer but is not receiving a response. This is often due to a network connectivity issue, such as an intermediate firewall blocking the connection, an incorrect peer IP address, or a routing problem preventing the TCP SYN packet from reaching the peer or the SYN-ACK from returning. An 'Idle' state would mean it's waiting, 'Connect' means TCP is established and waiting for an OPEN message, and 'Established' is a successful peering.

  3. Question 3IntermediateSelect 2

    PAN-OS Device Setting Configuration · Configure on-premises and Cloud Identity Engine User-ID

    A hospital is using a PA-3220 firewall to segment its network. They have created a custom application signature for their Electronic Health Record (EHR) system. The security policy must allow access to the EHR system only for users in the 'Clinical-Staff' Active Directory group. All other access attempts to the EHR servers must be blocked and logged. Which two security policy rules, in the correct order, are required to implement this? (Choose two.)

    Show answer & explanation

    Correct answers: A, C

  4. Question 4Intermediate

    PAN-OS Networking Configuration · Configure GlobalProtect

    An organization wants to provide remote access to its developers. The requirements are:

    • All developer traffic must be routed through the corporate firewall for inspection.
    • Developers should NOT be able to access their local network resources while connected to the VPN.
    • The solution must be centrally managed via Panorama.

    Which GlobalProtect configuration on the Gateway will enforce these requirements?

    Show answer & explanation

    Correct answer: D

    Disabling split tunneling (also known as 'tunnel all' mode) forces all traffic from the client, including internet-bound traffic, through the GlobalProtect VPN tunnel. This meets the requirement for full traffic inspection. Additionally, the 'No direct access to local network' option, which is part of the agent configuration pushed from the portal, prevents the user from accessing their local network resources, satisfying the second requirement.

  5. Question 5Intermediate

    Integration and Automation · Manage third-party services to deploy NGFWs

    A company is using Terraform to manage its Cloud NGFW for AWS deployment. The lead engineer needs to define a ruleset that will be applied to multiple firewall resources. Which Terraform resource should be used to define a reusable collection of security rules?

    Show answer & explanation

    Correct answer: C

    In the Palo Alto Networks Cloud NGFW provider for Terraform, the paloaltonetworks_cloudngfw_aws_rule_stack resource is used to define a collection of security rules (a ruleset). This rule stack can then be associated with one or more paloaltonetworks_cloudngfw_aws_firewall resources, allowing for the definition of reusable, modular security policies.

  6. Question 6Advanced

    PAN-OS Device Setting Configuration · Configure virtual systems (VSYS)

    A university has implemented a multi-VSYS environment on a PA-7050 to provide distinct virtual firewalls for its 'Academics', 'Administration', and 'Research' departments. The Research department requires direct, high-speed access to a shared supercomputing resource located in the Administration network. A standard inter-VSYS L3 interface is causing performance bottlenecks due to packet processing overhead. What is the most efficient method to connect the Research VSYS to the Administration VSYS to maximize throughput?

    Show answer & explanation

    Correct answer: D

    Logical Routers provide high-speed, line-rate routing between VSYSs on the same physical firewall. Unlike traditional inter-VSYS routing that involves Layer 3 interfaces and additional packet processing, a Logical Router performs routing in hardware, significantly reducing latency and maximizing throughput. This is the ideal solution for performance-sensitive inter-VSYS communication.

  7. Question 7Intermediate

    PAN-OS Networking Configuration · Configure tunnels

    An administrator is setting up a site-to-site IPSec VPN tunnel and wants to ensure the tunnel is re-established automatically if it goes down. They have configured Dead Peer Detection (DPD) on the Palo Alto Networks firewall. If the firewall sends a DPD probe and does not receive a response, what is its immediate next action?

    Show answer & explanation

    Correct answer: A

    Dead Peer Detection does not tear down the tunnel after a single failed probe. By default, it will retry sending probes according to the configured interval and retry count (typically 5 retries). Only after all retries have failed without a response will the firewall declare the peer dead, tear down the Security Associations (SAs), and attempt to re-establish the tunnel.

  8. Question 8Advanced

    PAN-OS Device Setting Configuration · Configure certificates

    A security engineer has configured SSL Forward Proxy decryption. Users report that they can no longer access an internal business application that requires mutual authentication using client certificates. The security policy already excludes this application's destination from decryption. What is the most likely remaining misconfiguration causing this issue?

    Show answer & explanation

    Correct answer: C

    Even if a site is excluded from decryption, the firewall still processes the initial part of the TLS handshake to identify the destination (e.g., via SNI). If the server requests a client certificate during this handshake, the firewall must decide how to handle it. The decryption profile includes an option 'Block sessions with client authentication'. If this is enabled, the firewall will block the session even if it was destined for a decryption exclusion, causing the application to fail. The correct configuration is to set this to 'Allow' or to configure a no-decrypt rule specifically for the application.

  9. Question 9IntermediateSelect 3

    Integration and Automation · Build Application Command Center (ACC) dashboards and custom reports

    An administrator is creating custom reports in Panorama to track bandwidth usage for specific applications. They want to generate a weekly report that is automatically emailed to department heads. What are the key components that must be configured in Panorama to achieve this? (Select THREE).

    Show answer & explanation

    Correct answers: A, B, D

  10. Question 10Beginner

    PAN-OS Networking Configuration · Configure interface

    A network engineer needs to configure an Aggregate Ethernet (AE) interface group on a PA-5260 firewall to connect to a switch stack. The goal is to maximize throughput and provide redundancy. The switch stack is configured for dynamic link aggregation. Which LACP mode should be configured on the firewall's AE interface?

    Show answer & explanation

    Correct answer: C

    When connecting to a device configured for dynamic link aggregation (LACP), the firewall should also use LACP. In LACP, Active mode means the interface will actively try to form an LACP bundle with its peer. Passive mode will only form a bundle if the peer initiates the negotiation. To ensure the bundle forms reliably, at least one side must be Active. Configuring the firewall as Active is the standard best practice. Static mode is used when the peer device does not support LACP and is configured for static aggregation.

Ready for the real thing?

The full NGFW-ENGINEER simulator has every exam-style question, timed mode, and instant scoring.