PCCNSA Sample Questions

PCCNSA Sample Questions & Answers

Weighted toward two tied top areas: building application override, decryption and security policies, and creating external dynamic lists alongside decryption and security profiles, then centralized management, incident and alert remediation, and troubleshooting.

Launch the full PCCNSA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Object Configuration Creation and Application · Log forwarding profiles

    You are configuring a Log Forwarding Profile to send logs to the Strata Logging Service. You want to ensure that only 'Critical' and 'High' severity Threat logs are forwarded to reduce noise, while all Traffic logs should be forwarded for audit trails. Which configuration achieves this?

    Show answer & explanation

    Correct answer: A

    Log Forwarding Profiles allow detailed filtering. You can create separate match list items: one for Traffic logs (no filter/all) and one for Threat logs with a specific query filter for severity.

  2. Question 2IntermediateSelect 2

    Object Configuration Creation and Application · SD-WAN profiles and templates

    Which TWO components are required to configure an SD-WAN Profile for path quality monitoring in Strata Cloud Manager? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    Defines the thresholds for latency, jitter, and packet loss.

    Defines how traffic is distributed across available links (e.g., Best Available, Weighted Round Robin).

  3. Question 3Beginner

    Object Configuration Creation and Application · IoT security profiles

    A manufacturing company wants to implement IoT Security. They need to automatically discover devices and enforce policies based on the device identity (e.g., 'MRI Machine', 'Thermostat'). Which step must be taken first to enable this visibility in Strata Cloud Manager?

    Show answer & explanation

    Correct answer: D

    IoT Security relies on analyzing traffic logs sent to the cloud (Strata Logging Service). The first step is licensing and ensuring logs reach the analysis engine.

  4. Question 4Advanced

    Object Configuration Creation and Application · DoS protection profiles

    When configuring a DoS Protection Profile, what is the purpose of the 'Classified' DoS protection policy compared to 'Aggregate'?

    Show answer & explanation

    Correct answer: A

    Aggregate limits the total packet rate for all traffic matching the rule. Classified allows you to set limits per single IP (e.g., limit each source IP to 1000 pps), which is essential for stopping botnets without blocking all legitimate traffic.

  5. Question 5Beginner

    Object Configuration Creation and Application · Security profiles and security profile groups

    True or False: A Security Profile Group can contain multiple profiles of the same type (e.g., two different Antivirus profiles).

    Show answer & explanation

    Correct answer: B

    A Security Profile Group allows you to bundle profiles for easier application to policies, but it can only contain ONE profile of each type (one AV, one Spyware, one URL, etc.).

  6. Question 6Intermediate

    Object Configuration Creation and Application · Custom objects

    A network administrator creates a custom application signature for an internal proprietary application 'App-Internal'. The application runs on TCP port 8080. The administrator wants to ensure that this traffic is identified as 'App-Internal' and not 'web-browsing'. Which object configuration is required?

    Show answer & explanation

    Correct answer: C

    To identify custom traffic, you create a Custom Application with specific signatures (patterns). Setting the parent to 'web-browsing' helps the firewall understand the context if it runs over HTTP but has unique characteristics.

  7. Question 7Intermediate

    Object Configuration Creation and Application · Security profiles and security profile groups

    Which WildFire Analysis Profile action settings should be configured to ensure that users are protected from zero-day malware in real-time while maintaining file availability?

    Show answer & explanation

    Correct answer: C

    The WildFire Analysis Profile ensures files are sent to the cloud. The protection comes from the Antivirus Profile, which uses the signatures generated by WildFire (often within seconds/minutes) to block the content.

  8. Question 8Intermediate

    Object Configuration Creation and Application · External dynamic lists (EDLs)

    You are creating a custom URL category for a list of competitor websites to monitor employee access. You have a text file with 500 domains. What is the most efficient way to maintain this list if the domains change frequently?

    Show answer & explanation

    Correct answer: B

    EDLs allow the firewall to dynamically import lists from a URL. This allows you to update the text file centrally without modifying the firewall configuration every time.

  9. Question 9Intermediate

    Object Configuration Creation and Application · SD-WAN profiles and templates

    A customer wants to use SD-WAN to route traffic. They need to ensure that 'Voice' traffic always uses the link with the lowest jitter. Which object configuration is essential for this logic?

    Show answer & explanation

    Correct answer: C

    The Path Quality Profile defines the sensitivity to latency, jitter, and packet loss. This object is referenced in the SD-WAN policy to select the best path.

  10. Question 10Advanced

    Object Configuration Creation and Application · External dynamic lists (EDLs)

    The command set deviceconfig system update-schedule ... is related to which component of object configuration?

    Show answer & explanation

    Correct answer: A

    This command configures the schedule for downloading and installing dynamic content updates like Applications and Threats.

Ready for the real thing?

The full PCCNSA simulator has every exam-style question, timed mode, and instant scoring.

Go to the PCCNSA simulator →