Cheat sheet

Palo Alto NGFW Engineer Cheat Sheet

PAN-OS Networking Configuration

40%of exam

InterfacesZonesHigh AvailabilityRoutingGlobalProtectTunnels

PAN-OS Device Settings

40%of exam

AuthenticationVirtual SystemsLoggingUpdatesCertificatesUser-ID

Integration and Automation

20%of exam

DeploymentAPIsThird-Party ServicesPanoramaRule SetsACC

Quick Facts

Credential
NGFW Engineer
Level
Specialist
Platform
Network Security
Seat time
90 min
Networking
40%
Device settings
40%
Automation
20%
Pass score
860/300-1000
ESL extension
30 min

Blueprint Weights

Network 40, device 40, automate 20.

NetworkingDevice settingsIntegrationAutomation

Layer 2 vs Layer 3

Layer 2

  • Switching mode
  • VLAN-oriented
  • No routed interface

Layer 3

  • Routed mode
  • IP addressing
  • Virtual router

Switching vs routing

Interface Picker

  1. Need routed connectivityLayer 3(IP routing)
  2. Need switchingLayer 2(VLAN design)
  3. Need transparent insertionVirtual wire(Inline inspection)
  4. Need tunnel endpointTunnel interface(Overlay traffic)
  5. Need link bundleAggregate Ethernet(AE)
  6. Need administrationManagement interface(Admin path)

Interfaces and Zones

Layer 2
Switching interface mode
Layer 3
Routed interface mode
Virtual wire
Transparent inline deployment
Tunnel interface
Tunnel traffic endpoint
Aggregate Ethernet
Bundled Ethernet linksAE
Management interface
Administrative access path
Security zone
Policy trust boundary

GlobalProtect Split

Portal configures; gateway connects.

PortalConfigurationGatewayTunnel

Virtual Wire vs Tunnel

Virtual wire

  • Transparent insertion
  • Inline traffic
  • No routed design

Tunnel

  • Overlay endpoint
  • Encapsulated traffic
  • Tunnel interface

Inline vs overlay

Resiliency Picker

  1. One active peerActive/passive(Standby peer)
  2. Both peers forwardActive/active(Dual forwarding)
  3. Watch interface healthLink monitoring(Link state)
  4. Watch path reachabilityPath monitoring(Probe target)
  5. Learn routesDynamic routing(Protocol routes)
  6. Check route healthRoute monitoring(Reachability)

HA and Routing

Active/passive
One traffic-forwarding peer
Active/active
Both peers forward
Link monitoring
Interface-health failover
Path monitoring
Reachability-health failover
Dynamic routing
Protocol-learned routes
Redistribution
Share route information
Route monitoring
Route reachability check
Advanced Routing Engine
PAN-OS routing framework

Active Passive vs Active Active

Active/passive

  • One active peer
  • Standby peer
  • Failover design

Active/active

  • Both peers active
  • Traffic forwarding
  • Dual-peer design

One forwarder vs two

GlobalProtect and Tunnels

GlobalProtect portal
Client configuration source
GlobalProtect gateway
Client tunnel endpoint
GlobalProtect authentication
Remote-user verification
Split tunneling
Selective tunnel traffic
IPSec
Encrypted IP tunnel
GRE
Generic routing overlay
Quantum-resistant cryptography
Post-quantum tunnel protection

Identity and Virtual Systems

Authentication role
Administrator privilege set
Authentication profile
Authentication service settings
Authentication sequence
Ordered authentication methods
VSYS
Virtual firewall instance
Virtual router
Independent routing table
Logical router
Routing abstraction
Inter-VSYS routing
Traffic between virtual systems

Logging Certificates Updates

Strata Logging Service
Cloud logging service
Log forwarding
Send selected logs
Log collector
Central log storage
Collector group
Log collector grouping
PAN-OS updates
Software update management
PKI
Certificate trust framework
TLS profile
TLS security settings
Certificate profile
Certificate validation rules

User-ID and Web Proxy

Cloud Identity Engine
Cloud identity integration
On-premises User-ID
Local user mapping
Group mapping
Directory group retrieval
Directory sync
Directory data synchronization
User-to-IP mapping
User address association
User context
Identity policy context
Web proxy
PAN-OS web proxy

Management Split

Templates shape; device groups govern.

TemplatesSettingsDevice groupsPolicies

Template vs Device Group

Template

  • Device settings
  • Interface configuration
  • Shared configuration

Device group

  • Policy configuration
  • Object scope
  • Shared policy

Settings vs policy

Management Picker

  1. Centralize device settingsPanorama templates(Shared settings)
  2. Centralize policiesDevice groups(Policy scope)
  3. Automate deploymentAPIs(Programmatic control)
  4. Deploy virtual firewallVM-Series(Virtual form)
  5. Deploy cloud firewallCloud NGFW(Cloud form)
  6. View applicationsACC dashboard(Operational view)

Deployment and APIs

PA-Series
Hardware firewall deployment
VM-Series
Virtual firewall deployment
CN-Series
Cloud-native firewall deployment
Cloud NGFW
Cloud firewall deployment
AI Runtime Security
AI workload protection
APIs
Deployment automation interface
Third-party services
External deployment integrations

Pre-Rule vs Post-Rule

Pre-rule

  • Before local rules
  • Centralized policy
  • Earlier evaluation

Post-rule

  • After local rules
  • Centralized policy
  • Later evaluation

Before vs after

Panorama and Reports

Panorama
On-premises centralized management
Template
Shared device settings
Device group
Shared policy scope
Pre-rule
Rule before local rules
Post-rule
Rule after local rules
ACC dashboard
Application Command Center view
Custom report
Tailored operational report

Common Traps

Interface Trap

Layer 2 ≠ Layer 3 Virtual wire ≠ tunnel

HA Trap

Link monitoring ≠ path monitoring Active/passive ≠ active/active

Management Trap

Templates ≠ device groups Pre-rules ≠ post-rules

Identity Trap

User-ID ≠ administrator role Group mapping ≠ user mapping

Logging Trap

Log forwarding ≠ collector Software update ≠ log update

Score Trap

860 ≠ raw percentage Scaled ≠ percentage score

Last Minute

  1. 1.Blueprint: 40 / 40 / 20
  2. 2.Match interface to topology
  3. 3.Zones define policy boundaries
  4. 4.Separate link and path monitoring
  5. 5.Know portal versus gateway
  6. 6.Map VSYS routing boundaries
  7. 7.Know logging-service components
  8. 8.Separate User-ID mapping types
  9. 9.Templates configure; groups govern policy
  10. 10.Place pre and post rules
  11. 11.Match deployment form factor
  12. 12.Remember 860 is scaled
Same family resources

Explore More Palo Alto Networks Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.