
Palo Alto Networks Certified Next-Generation Firewall Engineer
The Palo Alto Networks Certified Next-Generation Firewall Engineer certification validates the skills required to deploy, configure, manage, and troubleshoot Palo Alto Networks Next-Generation Firewalls. It is designed for engineers and administrators who work with PAN-OS networking, device configuration, integration, and automation. Earning this credential demonstrates your ability to manage network security infrastructure effectively, making you a valuable asset in protecting your organization's digital environment.
379 practice questions · Updated 2026-07-30
NEXT-GENERATION-FIREWALL-ENGINEER Curriculum
Every domain, objective, and concept the NEXT-GENERATION-FIREWALL-ENGINEER exam measures.
- Layer 2 Interface Configuration
- Layer 3 Interface Configuration
- Virtual Wire Interface Configuration
- Tunnel Interface Configuration
- Aggregate Ethernet (AE) Interface Configuration
- Management Interface Configuration
- Zone definition and purpose
- Zone types
- Creating zones
- Assigning interfaces to zones
- Zone protection profiles
- Zone-based policy enforcement
- Inter-zone vs intra-zone traffic
- Zone configuration best practices
- Active/Active HA Overview
- Active/Active Configuration
- Active/Active Load Balancing and Asymmetric Traffic
- Active/Passive HA Overview
- Active/Passive Configuration
- HA Failover and State Synchronization
- Link Monitoring
- Path Monitoring
- Monitoring Configuration and Actions
- Dynamic routing protocols
- Redistribution and policies
- Route monitoring
- Advanced Routing Engine
- GlobalProtect Portal Configuration
- GlobalProtect Gateway Configuration
- GlobalProtect Authentication Methods
- GlobalProtect Split Tunneling
- IPSec fundamentals
- IPSec configuration on PAN-OS
- IPSec troubleshooting
- Quantum-resistant cryptography concepts
- Configuring quantum-resistant crypto profiles
- GRE tunnel fundamentals
- Configuring GRE tunnels on PAN-OS
- GRE troubleshooting
- Authentication Roles
- Authentication Profiles
- Authentication Sequences
- Role-Based Access Control (RBAC)
- Profile Groups
- Local Authentication
- External Authentication Integration
- Authentication Profile Settings
- Sequence Configuration
- Testing and Verification
- VSYS Interface and Zone Assignment
- VSYS Virtual Router Configuration
- Logical Router Configuration
- Inter-VSYS Routing
- Inter-VSYS Security Policy
- Strata Logging Service overview
- Strata Logging Service configuration
- Log forwarding profiles
- Log forwarding to Strata Logging Service
- Log collectors and log collector groups
- Configuring log collector groups
- Log collector group assignment
- PAN-OS software update types
- Update availability and release channels
- Downloading and installing updates
- Scheduling updates
- Update validation and checksums
- Pre-update checks and prerequisites
- Post-update verification
- Rollback and recovery
- Update impact on configuration and sessions
- Best practices for PAN-OS updates
- PKI Integration
- Certificate Authentication
- SSL/TLS Profiles
- Decryption Subordinate CA
- Forward Trust and Untrust Certificates
- Certificate Profiles
- Group Mapping Configuration
- Directory Sync Setup
- User-to-IP Mapping Methods
- User Context in Policies
- User-ID Redistribution
- User-ID Segments
- Web Proxy Overview
- Proxy Configuration Methods
- Proxy Server Settings
- PAC File Configuration
- Proxy Bypass Rules
- Proxy and Security Policies
- Troubleshooting Web Proxy
- PA-Series Deployment
- VM-Series Deployment
- CN-Series Deployment
- Cloud NGFW Deployment
- AI Runtime Security Deployment
- API fundamentals for NGFW
- REST API basics
- Panorama API usage
- Firewall API usage
- API authentication methods
- Automating deployment workflows
- Error handling and debugging
- Kubernetes integration
- Hypervisor integration
- Cloud service provider (CSP) integration
- Terraform automation
- Ansible automation
- Third-party service management
- Panorama overview
- Panorama deployment modes
- Panorama device registration
- Templates and device groups purpose
- Template and device group hierarchy
- Template and device group configuration
- Pre- and post-ruleset concept
- Pre- and post-ruleset usage
- ACC Dashboard Overview
- Creating Custom ACC Dashboards
- Configuring ACC Dashboard Widgets
- Using ACC Dashboard Filters
- Building Custom Reports
- Configuring Report Settings
- Managing and Viewing Reports
- Integrating ACC and Reports with Automation
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for NEXT-GENERATION-FIREWALL-ENGINEER, so none is invented.