Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
PALO ALTO NETWORKS

Palo Alto Networks Certified Next-Generation Firewall Engineer

NEXT-GENERATION-FIREWALL-ENGINEERNext-Generation Firewall Engineer

The Palo Alto Networks Certified Next-Generation Firewall Engineer certification validates the skills required to deploy, configure, manage, and troubleshoot Palo Alto Networks Next-Generation Firewalls. It is designed for engineers and administrators who work with PAN-OS networking, device configuration, integration, and automation. Earning this credential demonstrates your ability to manage network security infrastructure effectively, making you a valuable asset in protecting your organization's digital environment.

379 practice questions · Updated 2026-07-30

3Domains
18Objectives
124Concepts
379Questions

NEXT-GENERATION-FIREWALL-ENGINEER Curriculum

Every domain, objective, and concept the NEXT-GENERATION-FIREWALL-ENGINEER exam measures.

1.1 Configure interface

6 concepts · 13 questions
  1. Layer 2 Interface Configuration
  2. Layer 3 Interface Configuration
  3. Virtual Wire Interface Configuration
  4. Tunnel Interface Configuration
  5. Aggregate Ethernet (AE) Interface Configuration
  6. Management Interface Configuration

1.2 Configure zones

8 concepts · 21 questions
  1. Zone definition and purpose
  2. Zone types
  3. Creating zones
  4. Assigning interfaces to zones
  5. Zone protection profiles
  6. Zone-based policy enforcement
  7. Inter-zone vs intra-zone traffic
  8. Zone configuration best practices

1.3 Configure high availability (HA)

9 concepts · 26 questions
  1. Active/Active HA Overview
  2. Active/Active Configuration
  3. Active/Active Load Balancing and Asymmetric Traffic
  4. Active/Passive HA Overview
  5. Active/Passive Configuration
  6. HA Failover and State Synchronization
  7. Link Monitoring
  8. Path Monitoring
  9. Monitoring Configuration and Actions

1.4 Configure routing

4 concepts · 16 questions
  1. Dynamic routing protocols
  2. Redistribution and policies
  3. Route monitoring
  4. Advanced Routing Engine

1.5 Configure GlobalProtect

4 concepts · 9 questions
  1. GlobalProtect Portal Configuration
  2. GlobalProtect Gateway Configuration
  3. GlobalProtect Authentication Methods
  4. GlobalProtect Split Tunneling

1.6 Configure tunnels

8 concepts · 24 questions
  1. IPSec fundamentals
  2. IPSec configuration on PAN-OS
  3. IPSec troubleshooting
  4. Quantum-resistant cryptography concepts
  5. Configuring quantum-resistant crypto profiles
  6. GRE tunnel fundamentals
  7. Configuring GRE tunnels on PAN-OS
  8. GRE troubleshooting

  1. Authentication Roles
  2. Authentication Profiles
  3. Authentication Sequences
  4. Role-Based Access Control (RBAC)
  5. Profile Groups
  6. Local Authentication
  7. External Authentication Integration
  8. Authentication Profile Settings
  9. Sequence Configuration
  10. Testing and Verification

2.2 Configure virtual systems (VSYS)

5 concepts · 9 questions
  1. VSYS Interface and Zone Assignment
  2. VSYS Virtual Router Configuration
  3. Logical Router Configuration
  4. Inter-VSYS Routing
  5. Inter-VSYS Security Policy

2.3 Configure logging

7 concepts · 20 questions
  1. Strata Logging Service overview
  2. Strata Logging Service configuration
  3. Log forwarding profiles
  4. Log forwarding to Strata Logging Service
  5. Log collectors and log collector groups
  6. Configuring log collector groups
  7. Log collector group assignment

2.4 Implement PAN-OS software updates

10 concepts · 34 questions
  1. PAN-OS software update types
  2. Update availability and release channels
  3. Downloading and installing updates
  4. Scheduling updates
  5. Update validation and checksums
  6. Pre-update checks and prerequisites
  7. Post-update verification
  8. Rollback and recovery
  9. Update impact on configuration and sessions
  10. Best practices for PAN-OS updates

2.5 Configure certificates

6 concepts · 22 questions
  1. PKI Integration
  2. Certificate Authentication
  3. SSL/TLS Profiles
  4. Decryption Subordinate CA
  5. Forward Trust and Untrust Certificates
  6. Certificate Profiles
  1. Group Mapping Configuration
  2. Directory Sync Setup
  3. User-to-IP Mapping Methods
  4. User Context in Policies
  5. User-ID Redistribution
  6. User-ID Segments

2.7 Configure web proxy on PAN-OS

7 concepts · 26 questions
  1. Web Proxy Overview
  2. Proxy Configuration Methods
  3. Proxy Server Settings
  4. PAC File Configuration
  5. Proxy Bypass Rules
  6. Proxy and Security Policies
  7. Troubleshooting Web Proxy

  1. PA-Series Deployment
  2. VM-Series Deployment
  3. CN-Series Deployment
  4. Cloud NGFW Deployment
  5. AI Runtime Security Deployment

3.2 Use APIs to automate deployment

7 concepts · 20 questions
  1. API fundamentals for NGFW
  2. REST API basics
  3. Panorama API usage
  4. Firewall API usage
  5. API authentication methods
  6. Automating deployment workflows
  7. Error handling and debugging
  1. Kubernetes integration
  2. Hypervisor integration
  3. Cloud service provider (CSP) integration
  4. Terraform automation
  5. Ansible automation
  6. Third-party service management
  1. Panorama overview
  2. Panorama deployment modes
  3. Panorama device registration
  4. Templates and device groups purpose
  5. Template and device group hierarchy
  6. Template and device group configuration
  7. Pre- and post-ruleset concept
  8. Pre- and post-ruleset usage
  1. ACC Dashboard Overview
  2. Creating Custom ACC Dashboards
  3. Configuring ACC Dashboard Widgets
  4. Using ACC Dashboard Filters
  5. Building Custom Reports
  6. Configuring Report Settings
  7. Managing and Viewing Reports
  8. Integrating ACC and Reports with Automation
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for NEXT-GENERATION-FIREWALL-ENGINEER, so none is invented.