Capstone Practice Exam
68 questions spanning all 14 modules, weighted roughly by module size (Access & Identity and VM-Series & Public Cloud carry the most questions since they're the largest modules). This is a self-assessment tool for this guide, not a copy of or substitute for the real Certified NGFW Engineer exam — use it to find which modules need another pass, not to memorize exact wording. Answer everything, click Check Answers, and you'll get both an overall score and a per-module breakdown below the questions.
Practice Exam
Foundations
1. A security rule permits only the "web-browsing" application on TCP/8080. Traffic analysis shows a proprietary database-replication protocol tunneling over that same port and being correctly blocked. Which mechanism identified the mismatch between the rule's intent and the traffic's actual identity?
2. An engineer enables Threat Prevention, WildFire, and URL Filtering on the same security rule and is concerned about added latency from each subscription re-inspecting the packet. Under Single-Pass Parallel Processing (SP3), what actually happens?
3. A customer is sizing a firewall for a link where they plan to enable decryption, App-ID, and full threat inspection on all traffic. Which two factors should most directly influence platform selection? (Choose two.)
Traffic Classification
4. A custom internal application isn't recognized by any built-in App-ID signature. How will the firewall most likely classify its traffic by default?
5. A group of users share a single IP address on a Citrix XenApp/RDP terminal server, and standard IP-to-user mapping techniques (login monitoring, WMI probes) all report the same address for every session. Which two User-ID sources are designed to correctly disambiguate individual users on a shared IP? (Choose two.)
6. What does Content-ID add on top of what App-ID and User-ID already establish about a session?
7. An internal application evades App-ID's signature-based classification by mimicking normal HTTP behavior over port 80. Which two App-ID mechanisms work together to eventually reclassify this kind of evasive traffic? (Choose two.)
8. Content-ID's stream-based scanning is valuable primarily because:
Encrypted Traffic
9. Which decryption mode is used for outbound user traffic, where the firewall presents a certificate signed by an internal enterprise CA?
10. Why does SSL Inbound Inspection not require re-signing traffic with a forward-trust CA, unlike Forward Proxy?
11. An architect is defining SSL Decryption exclusions before a broad decryption rollout. Which two categories of traffic are commonly excluded from decryption because inspecting them causes practical problems? (Choose two.)
12. Why should a forward-trust CA certificate ideally chain to an enterprise root CA rather than stand alone?
Policy & Segmentation
13. Two security policy rules could both match a session: a broad "allow any" rule near the top, and a specific deny rule further down. What happens?
14. A NAT rule performs destination NAT, translating a public IP to an internal server's private IP. Which two statements correctly describe how PAN-OS evaluates the corresponding Security Policy rule for this session? (Choose two.)
15. What is DIPP (dynamic-IP-and-port) oversubscription primarily used for?
16. What is the default behavior for intrazone vs. interzone traffic when no explicit rule matches?
17. Which two statements accurately distinguish Zone Protection profiles from DoS Protection profiles/rules? (Choose two.)
Firewall Fundamentals & Admin
18. An admin makes several configuration edits but hasn't clicked Commit. Which two statements correctly describe the state of the configuration at this point? (Choose two.)
19. What does "Validate" do during the commit workflow that "Preview" does not?
20. A custom Role Based admin profile was scoped last year. PAN-OS has since added a new feature area. What happens to that admin's access to the new feature?
21. Which two characteristics make Virtual Wire interface mode a good fit for inserting a firewall into an existing network with zero re-addressing, such as for a migration or POC? (Choose two.)
22. Why can't a Virtual System administrator role configure interfaces, VLANs, or virtual routers?
Threat & Content Services
23. What does Advanced Threat Prevention add specifically on top of standard Threat Prevention?
24. A brand-new, never-before-seen executable crosses the firewall. Which two techniques does WildFire use to determine whether it's malicious? (Choose two.)
25. What does Advanced WildFire's Intelligent Run-time Memory Analysis specifically target?
26. What does Advanced URL Filtering add beyond the base URL Filtering (PAN-DB category) subscription?
27. What license is a prerequisite for DNS Security?
28. Which two reasons explain why decryption is a practical prerequisite for most of Content-ID's threat-facing services (Threat Prevention, WildFire, URL Filtering) to be fully effective? (Choose two.)
AI-Powered Security
29. What is the primary purpose of the Discovery stage in Prisma AIRS / AI Runtime Security?
30. Which Prisma AIRS stage is responsible for actively inspecting and blocking malicious prompts, responses, and agent actions in real time?
31. Which two AI/LLM-specific risks does Prisma AIRS address that conventional network-layer Threat Prevention/IPS signatures are not designed to catch? (Choose two.)
32. What must an organization typically decide during the Deploy stage of AI Runtime Security?
Access & Identity
33. What is the primary purpose of GlobalProtect in the context of User-ID?
34. What's the difference between an Authentication Profile and an Authentication Sequence?
35. Which factor category does Multi-Factor Authentication add beyond username/password on the firewall?
36. How does Credential Phishing Prevention typically restrict where corporate credentials can be submitted?
37. Which two roles does the Cloud Identity Engine play for organizations with both on-prem AD and cloud directories like Azure AD/Okta? (Choose two.)
38. What does SCIM provisioning automate in this context?
39. In a large multi-vsys or multi-firewall environment, which two reasons explain why User-ID Redistribution is needed? (Choose two.)
40. When implementing User-ID in policy, which two of the following can the Source User field match against? (Choose two.)
VPN & Connectivity
41. In an IKE/IPSec site-to-site VPN, what do Proxy IDs primarily define?
42. Which two factors make manually configuring many individual site-to-site IPSec tunnels a poor fit for branch-heavy deployments? (Choose two.)
43. What risk does Quantum-Ready VPN specifically aim to mitigate?
Software Firewalls: Containers & Kubernetes
44. What networking characteristic of Kubernetes makes traditional perimeter-only firewalls insufficient for east-west traffic inside a cluster?
45. Which two things does CN-Series bring into a Kubernetes cluster that differentiate it from relying on native Kubernetes network policies alone? (Choose two.)
46. In CN-Series architecture, what two main components typically work together to enforce policy?
47. What does CN-Series deployment tie together from the earlier architecture discussion?
Software Firewalls: VM-Series & Public Cloud
48. In a hub-and-spoke cloud network security design, why route spoke VPC/VNet traffic through a central security VPC/VNet?
49. Which two factors primarily determine VM-Series instance sizing and licensing requirements in a public cloud deployment? (Choose two.)
50. What's a common VM-Series traffic flow design for inbound internet-facing workloads in the cloud?
51. Which two capabilities does AWS Gateway Load Balancer (GWLB) integration with VM-Series provide? (Choose two.)
52. What is the Azure equivalent design pattern to AWS Gateway Load Balancer for inserting VM-Series transparently?
53. On GCP, what capability does Google Cloud Intrusion Detection provide relative to VM-Series?
54. What use case does VM-Series on NSX-T primarily address?
55. Which two benefits come from deploying VM-Series consistently across AWS, Azure, GCP, and on-prem/NSX-T rather than mixing different vendors' firewalls per environment? (Choose two.)
Resilience & Scale
56. In an active/passive HA pair, what state does NOT automatically sync between the two firewalls?
57. Which two capabilities does NGFW Clustering provide beyond what a standard two-node active/passive HA pair offers? (Choose two.)
58. What is the primary use case for Virtual Systems (vsys) on a single physical firewall?
59. Which shared network resources can a Virtual System administrator NOT configure, per the platform's RBAC model?
Management & Ops
60. What is Panorama's core role in a multi-firewall deployment?
61. Which two reasons commonly justify forwarding firewall logs to an external SIEM in addition to keeping them in Panorama/Strata Logging Service? (Choose two.)
62. What does Strata Logging Service provide that changes the traditional on-prem log-collector model?
63. When reading a Traffic log entry, what does the Action field combined with the Session End Reason together tell you?
64. Which two categories of data does Device Telemetry upload to Palo Alto Networks by design? (Choose two.)
65. What does Platform Security / Intelligent Malware Analysis (IMA) primarily add to the platform's own operational security?
Licensing & Summary
66. Which two capabilities ship on every NGFW at no additional subscription cost, unlike Advanced Threat Prevention, Advanced WildFire, or Advanced URL Filtering? (Choose two.)
67. A customer wants inline ML-based catching of brand-new phishing pages, not just PAN-DB category blocking. Which subscription do they need?
68. What is the single biggest recurring trade-off called out across this entire guide's pros/cons summaries?