Revision Guide · Certified Next-Generation Firewall (NGFW) Engineer

Licensing & Summary

← Back to full guide index

~2 min read
Prerequisites: Management & Ops — this is the capstone/summary module, best read last.

Subscription Map — What's Free vs. Paid 57

Learning objectives

  • Distinguish which core NGFW capabilities ship free vs. which require a paid subscription
  • Map each subscription to the specific feature it unlocks, and its prerequisites (e.g. DNS Security requires Threat Prevention)
  • Explain why "buy the box" and "buy the platform's full capability" are different budgets

Core NGFW hardware/software includes App-ID, User-ID, Content-ID, Security Policy, NAT, HA, Virtual Systems (base count), and basic GlobalProtect at no extra license. The following unlock further capability:

Modular subscriptions plug into a common Core NGFW capability base.
Modular subscriptions plug into a common Core NGFW capability base.
SubscriptionUnlocks
Threat PreventionAV, anti-spyware/C2, vulnerability protection (IPS), built-in malicious-host EDLs, infected-host DNS detection
Advanced Threat Prevention+ inline cloud deep-learning engine for evasive/unknown C2
DNS SecurityCloud-generated DNS threat signatures / sinkholing (requires Threat Prevention)
Advanced DNS Security+ real-time DNS response inspection for hijacked/misconfigured domains
URL Filtering / Advanced URL FilteringPAN-DB category control, credential-phishing prevention, ML real-time web inspection
WildFire / Advanced WildFireCloud malware sandboxing; advanced tier adds run-time memory analysis for evasive malware
GlobalProtect Gateway licenseHIP checks, mobile app, IPv6, clientless VPN (basic portal/gateway is free)
Virtual Systems licensevsys count beyond each platform's included base
SD-WANDynamic path selection, auto VPN topology, centralized via Panorama
Enterprise DLPML-based sensitive-data classification/policy enforcement
IoT SecurityAI-based discovery/classification of IoT devices + policy recommendations
SaaS Security InlineShadow-IT SaaS discovery and policy enforcement; required for App-ID Cloud Engine
AutoFocusThreat-intel-enriched graphical analysis of firewall traffic logs
Strata Logging ServiceCloud-based centralized log storage, underpins several cloud-delivered services
Strata Cloud Manager (Essentials/Pro)Cloud-based unified management, AIOps, ADEM, device telemetry apps
Why it matters: NGFW's advertised feature set is broad, but real-world cost and deployment planning depends heavily on which of these subscriptions are actually licensed — "buy the box" and "buy the platform's full capability" are two very different budgets.

Exam trap

DNS Security and Advanced DNS Security are add-ons on top of Threat Prevention — they don't stand alone. Likewise, standalone URL Filtering is no longer sold; Advanced URL Filtering is required for the full ML-based feature set. Don't assume any subscription is independent without checking its prerequisite.
Self-check
Q1. A customer wants DNS sinkholing for malicious domains but has not purchased Threat Prevention. Can they enable DNS Security?
A: No — DNS Security requires an active Threat Prevention license; it is not sold as a fully standalone subscription.
Q2. Which two subscriptions specifically add machine-learning/deep-learning detection beyond static signatures, and what does each one protect against?
A: Advanced Threat Prevention (inline cloud deep-learning for evasive/unknown C2) and Advanced URL Filtering (real-time ML inspection of web pages for brand-new phishing/exploit sites) — Advanced WildFire's run-time memory analysis is a related but separate ML-based capability for sandbox-evasive malware.

Source: pan-os/11-1/pan-os-admin/subscriptions

Overall Platform — Pros & Cons 58

Learning objectives

  • Summarize the platform-wide strengths that recur across every module in this guide
  • Summarize the platform-wide weaknesses/costs that recur across every module in this guide
  • Use this as a final gut-check before the exam: can you justify each pro/con with a specific feature from earlier modules?
Radial map of every capability module in this guide radiating from a central NGFW single-pass core.
Every module in this guide, radiating from the NGFW's single-pass core.

Pros

  • Single-pass architecture means enabling more security functions doesn't multiply inspection passes
  • App-ID/User-ID/Content-ID give policy that reflects actual business intent, not raw ports
  • Consistent feature model across hardware appliances, VM-Series, CN-Series (containers), and cloud-native NGFW offerings
  • WildFire's community-shared verdicts and Advanced Threat Prevention's inline ML meaningfully raise the bar against unknown/evasive threats
  • Panorama/Strata Cloud Manager provide real centralized management at fleet scale

Cons

  • True "next-gen" protection (decryption + Threat Prevention + WildFire + Advanced URL Filtering + DNS Security) requires stacking multiple paid subscriptions on top of the hardware/VM cost
  • Decryption — the prerequisite for most deep inspection — is CPU-expensive, breaks HA session sync, and carries legal/compliance caveats
  • Feature/platform support is uneven across the product line (vsys, HA modes, NGFW Clustering, PA-410 monitoring all have platform-specific caveats)
  • Operational complexity is real: App-ID content updates change rule behavior over time, User-ID depends on correct directory integration, and rulebases need ongoing audit discipline
  • Panorama becomes a critical dependency for consolidated visibility and several advanced features, so it must itself be sized and made resilient

Exam trap

Don't confuse "single-pass architecture" (one classification pass feeding every service) with "single point of failure" — SP3 is about avoiding redundant re-parsing across chained engines, not about resilience/HA, which is a separate, platform-dependent concern.
Self-check
Q1. A colleague argues that once you buy the NGFW hardware, you effectively have "next-gen" protection out of the box. What's the strongest counter-argument from this module?
A: Core hardware/software only includes App-ID/User-ID/Content-ID, Security Policy, NAT, HA, and basic GlobalProtect for free — real threat protection (Threat Prevention, WildFire, Advanced URL Filtering, DNS Security) and the decryption needed to make them effective against HTTPS all require separate paid subscriptions layered on top.
Q2. Name one operational (not licensing) cost that recurs across nearly every module in this guide.
A: Several are valid: App-ID content updates changing rule behavior over time, User-ID's dependence on correct directory/agent integration, decryption's CPU cost and HA session-sync limitation, or rulebase/administration discipline needed as the environment grows.

Module Quiz

1. A customer purchases only the NGFW appliance with no additional subscriptions and asks what security classification capability they still get out of the box. What's the accurate answer?

App-ID/User-ID/Content-ID are core to every NGFW license; WildFire, Advanced URL Filtering, and DNS Security all require separate paid subscriptions.

2. A customer has an active Threat Prevention license but has not purchased DNS Security. What DNS-related protection, if any, do they still get?

Threat Prevention itself includes some infected-host DNS-query analysis; the dedicated DNS Security cloud signature service and Advanced DNS Security response inspection remain separate add-on subscriptions.

3. A licensing audit needs to confirm prerequisite dependencies before renewal. Which single subscription is a prerequisite for both DNS Security and Advanced DNS Security?

DNS Security and its Advanced tier both require an active Threat Prevention license — neither is sold as a fully standalone subscription.

4. A security team wants to discover shadow-IT SaaS applications in use across the organization and enforce policy against them, and also plans to adopt App-ID Cloud Engine. Which subscription must be in place?

SaaS Security Inline provides shadow-IT SaaS discovery and enforcement, and is also a prerequisite for App-ID Cloud Engine.

5. During a design review, a colleague claims Single-Pass Architecture (SP3) is what keeps the firewall running through a hardware failure. Why is this claim incorrect?

SP3 avoids redundant re-parsing across chained inspection engines; HA and NGFW Clustering are the separate mechanisms responsible for resilience.

6. A CFO asks why the firewall's total cost of ownership keeps growing after the initial hardware purchase. Which recurring theme from this guide best explains it?

This theme — a licensing stack plus ongoing operational discipline — recurs throughout the Threat & Content Services, User-ID, and Decryption modules.

7. A threat intel team is specifically concerned about malware engineered to detect and evade standard sandboxing. Which subscription's capability directly addresses this?

Advanced WildFire adds Intelligent Run-time Memory Analysis specifically to catch sandbox-evasive malware that behaves differently once it detects detonation.

8. An architect is designing a multi-region fleet and wants a single log destination that several other cloud-delivered subscriptions also rely on, instead of sizing on-prem Log Collectors per site. Which service fits, and why?

Strata Logging Service is the cloud log backbone that several other subscriptions and cloud-delivered features depend on, removing per-site on-prem storage sizing.