StudyToCert

All certifications / NGFW Engineer / Cheat sheet

NGFW Engineer NGFW-Engineer cheat sheet

Every exam tip and key term from the free NGFW Engineer lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: PAN-OS networking configuration (38%)

Exam tips

Key terms

Virtual wire
A pair of interfaces bound together so the firewall inspects traffic transparently with no IP addresses, routing or switching.
Tap interface
An interface fed by a switch SPAN or mirror port that gives visibility and logging but cannot enforce or block.
Aggregate Ethernet (AE)
A logical interface bundling several same-speed physical ports, optionally negotiated with LACP, for bandwidth and redundancy.
LACP
Link Aggregation Control Protocol, which negotiates an aggregate bundle with the peer and removes failed or misconnected members.
Subinterface
A logical interface on a parent port that handles one 802.1Q VLAN tag, with its own zone and addressing.
Tunnel interface
A logical Layer 3 interface used as the endpoint of a route-based IPsec, GRE or GlobalProtect tunnel.
Loopback interface
An always-up logical Layer 3 interface used for services such as management, DNS proxy or a GlobalProtect portal.
VLAN interface
A Layer 3 interface attached to a Layer 2 VLAN so its hosts can be routed to other networks.
Security zone
A logical group of interfaces with the same trust level that security and NAT policy reference.
intrazone-default
The predefined rule that allows traffic whose source and destination zone are the same; not logged by default.
interzone-default
The predefined rule that denies traffic between different zones; not logged by default.
External zone
A zone type used on multi-vsys firewalls to represent another virtual system for inter-vsys traffic.
Tunnel zone
A zone type used with tunnel content inspection so policy can apply to traffic inside a cleartext tunnel.
Enable User Identification
A per-zone setting that tells the firewall to map IP addresses in that zone to usernames.
Rule override
Changing the settings, such as logging or profiles, of a predefined default rule, which cannot be deleted.
Zone protection profile
A profile applied to an ingress zone that defends against floods, reconnaissance and malformed packets before policy lookup.
SYN cookies
A SYN flood defense where the firewall completes the handshake on the server's behalf and forwards only validated connections.
Random Early Drop (RED)
A flood defense that drops a growing share of packets once the Activate threshold is exceeded.
Reconnaissance protection
Zone protection settings that detect port scans and host sweeps and can alert, block or block the source IP.
DoS protection policy
Rules with DoS profiles that protect specific hosts using classified or aggregate thresholds.
Interface management profile
A profile that controls which management and response services (ping, SSH, HTTPS, response pages and more) a data interface accepts.
Virtual router
The legacy PAN-OS routing instance holding interfaces, static routes and dynamic protocols with its own routing table.
Logical router
The routing instance used when the Advanced Routing Engine is enabled, configured with reusable routing profiles and route maps.
Administrative distance
A preference value for route sources; lower wins when prefixes are equal length. PAN-OS defaults include static 10 and OSPF internal 30.
Floating static route
A static route given a higher administrative distance so it is used only when the preferred dynamic route disappears.
ECMP
Equal-cost multipath: installing multiple equal routes to a destination and balancing sessions across them.
RIB and FIB
The routing information base holds all learned routes; the forwarding information base holds the best routes actually used to forward.
Policy-based forwarding (PBF)
Rules that forward matching traffic by criteria like source, user or application instead of the routing table.
Application cache
The record of App-ID results by destination that lets later sessions of an application match app-based PBF rules.
Symmetric return
A PBF option that sends replies back out the same interface and next hop on which the original traffic arrived.
Service route
A setting that makes a management-plane service such as DNS, updates or syslog source its traffic from a data interface instead of MGT.
DHCP relay
A firewall interface role that forwards client DHCP broadcasts to a DHCP server on another network.
DNS proxy
A firewall feature that answers client DNS queries, forwards them to chosen servers per domain and caches the results.
DIPP
Dynamic IP and Port source NAT: many hosts share one or a few addresses with source port translation.
Dynamic IP NAT
Source NAT that maps each host one-to-one to a free pool address without port translation; the pool can be exhausted.
Static IP NAT
A fixed one-to-one address translation that can be made bi-directional to allow inbound connections.
Destination NAT
Translation of the destination address, and optionally port, usually to publish an internal server.
U-turn NAT
NAT that lets internal clients reach an internal server via its public IP by translating destination and source so traffic returns through the firewall.
Post-NAT zone
The zone where the translated destination actually lives, used as the destination zone in security rules.
HA1
The HA control link carrying hellos, heartbeats, state and configuration synchronization.
HA2
The HA data link that synchronizes sessions, forwarding tables, IPsec SAs and ARP tables.
HA3
The active/active-only link that forwards packets between peers for session setup and asymmetric flows.
Preemption
The option that lets the higher-priority (lower number) peer reclaim the active role; must be enabled on both peers.
Split brain
A failure where both peers believe they should be active, usually because the only HA1 link failed.
Link group
A set of monitored interfaces whose failure condition (any or all) triggers failover.
Floating IP
An active/active address bound to one peer that moves to the other peer on failure.
IKE gateway
The object defining the VPN peer, local interface, IKE version, authentication and IKE crypto profile for phase 1.
IKE crypto profile
Phase 1 settings: Diffie-Hellman group, encryption, authentication and key lifetime.
IPsec crypto profile
Phase 2 settings: ESP or AH, encryption, authentication, PFS DH group and lifetime.
Proxy ID
A local/remote subnet pair that defines a phase 2 SA, required when the peer uses a policy-based VPN.
Tunnel monitoring
Pings through the tunnel to a remote IP that detect a broken data path and trigger wait-recover or fail-over.
Perfect forward secrecy (PFS)
A fresh Diffie-Hellman exchange for phase 2 keys so one compromised key does not expose other sessions.
Post-quantum preshared key (PPK)
An extra shared secret mixed into IKEv2 key derivation (RFC 8784) so session keys resist future quantum attacks on Diffie-Hellman.
Harvest now, decrypt later
The threat of recording encrypted traffic today to decrypt it once quantum computers can break the key exchange.
Hybrid key exchange
Combining a classical and a post-quantum key exchange so the result is at least as strong as the stronger one.
Key encapsulation mechanism (KEM)
A public key method for establishing a shared secret, the form most post-quantum key exchange algorithms take.
GRE
Generic Routing Encapsulation, an unencrypted tunneling protocol (IP protocol 47) that encapsulates packets in a new IP header.
GRE keepalive
A periodic check that marks a GRE tunnel down when the peer stops responding so routing can react.
Portal
The GlobalProtect component that authenticates the app and delivers its configuration and gateway list.
External gateway
A gateway that terminates tunnels from remote users over the Internet and enforces policy on their traffic.
Internal gateway
A gateway inside the network used for User-ID and HIP enforcement, often without a tunnel.
Internal host detection
A reverse DNS check of a known internal IP that tells the app whether it is on the corporate network.
Pre-logon
A connect method that establishes the tunnel with a machine certificate before the user signs in.
Split tunneling
Sending only chosen routes, domains or applications through the tunnel while other traffic goes directly to the Internet.
HIP profile
A combination of HIP objects evaluated as a match condition in security policy.

Domain 2: PAN-OS device setting configuration (38%)

Exam tips

Key terms

Dynamic role
A built-in admin role such as Superuser or Device Administrator that is updated automatically with new features.
Admin role profile
A custom role defining per-area web UI, XML API, REST API and CLI permissions; must be maintained manually after upgrades.
Device Administrator
A dynamic role with full firewall access except creating administrator accounts and virtual systems.
superreader
A CLI role level that allows read-only access to the full CLI.
Vsys administrator
A role restricted to managing specific virtual systems on a multi-vsys firewall.
Vendor-specific attribute (VSA)
A value returned by RADIUS, TACACS+ or SAML that assigns an admin role or access domain without a local account.
Config log
The log that records configuration changes, including which administrator made them.
Server profile
Connection settings for an external service such as LDAP, RADIUS, TACACS+, SAML IdP or Kerberos KDC.
Authentication profile
A profile that selects the authentication method and server, username format, allow list, lockout and MFA factors.
Authentication sequence
An ordered list of authentication profiles tried one after another until one succeeds.
TACACS+
A device administration AAA protocol that runs over TCP and encrypts the entire payload.
SAML IdP metadata
The identity provider's details, including signing certificate and SSO URL, imported to build a SAML server profile.
Allow list
The users or groups in an authentication profile that are permitted to authenticate with it.
Multi-factor authentication (MFA)
Requiring more than one type of proof, such as a password plus a push approval or token code.
Authentication policy
A rulebase that decides which traffic must authenticate, how, and for how long before security policy applies to it.
Authentication enforcement object
The rule action choosing browser-challenge, web-form or no-captive-portal and an authentication profile.
Browser-challenge
An enforcement method using Kerberos SPNEGO so domain browsers authenticate without a prompt.
Redirect mode
Authentication Portal mode that redirects users to a firewall Layer 3 interface, supporting session cookies and Kerberos SSO.
Transparent mode
Authentication Portal mode where the firewall impersonates the destination site to present the challenge.
Authentication timeout
How long a user stays authenticated for an authentication rule before being challenged again.
Virtual system (vsys)
A logical firewall inside one physical firewall with its own interfaces, zones, policies and admins.
Shared gateway
A virtual system that lets multiple vsys share external interfaces; it supports NAT and PBF but has no security policy.
External zone
A zone type pointing at another vsys, used to pass traffic between virtual systems.
Multi Virtual System Capability
The device setting that enables creating additional vsys, subject to platform support and licensing.
Shared location
The configuration scope whose objects and policies are available to every vsys.
Target vsys
The CLI setting that scopes commands to a particular virtual system.
Traffic log
A per-session record written by default at session end for sessions matching rules with logging enabled.
Log forwarding profile
An object attached to security rules that sends matching policy logs to Panorama, cloud logging, syslog, SNMP, email or HTTP.
Device > Log Settings
Where System, Configuration, User-ID, HIP Match and other non-policy logs are forwarded.
Syslog server profile
Settings for syslog destinations, including transport, port, format, facility and custom message formats.
HTTP server profile
A server profile that sends logs to web services with customizable URI, headers and payload.
Strata Logging Service
Palo Alto's cloud log storage service (formerly Cortex Data Lake) used by cloud management and analytics apps.
Feature release
A PAN-OS version that introduces new capabilities, such as 11.1, identified by its first two numbers.
Base image
The .0 image of a feature release, which must be downloaded before installing a maintenance release of that feature release.
Maintenance release
A bug-fix release within a PAN-OS feature release, such as a later 11.1.x build.
Applications and Threats
The content package containing App-ID definitions and vulnerability and spyware signatures.
Threshold
A dynamic update setting that waits a set number of hours after release before installing new content.
Device state
An export of the firewall's configuration and related files used to restore or replace a device.
Certificate authority (CA)
An entity that signs certificates; endpoints trust certificates signed by CAs in their trust store.
Forward Trust certificate
The CA certificate the firewall uses to sign impersonated server certificates when the real server certificate is trusted.
Forward Untrust certificate
An untrusted CA certificate used to sign impersonated certificates for sites with invalid certificates, so users see a warning.
SSL Inbound Inspection
Decryption of traffic to your own servers using their imported certificate and private key.
SSL/TLS service profile
Settings for the certificate and TLS versions used by services the firewall hosts, such as the web interface and portal.
Certificate profile
Settings for validating client or peer certificates: trusted CAs, username field and OCSP/CRL checks.
OCSP
Online Certificate Status Protocol, a real-time query to a responder about a certificate's revocation status.
Certificate pinning
An app accepting only a specific certificate or CA for its server, which breaks when a firewall substitutes its own certificate.
Mutual TLS
TLS where the client also presents a certificate; a forward proxy cannot present the client's certificate, so it cannot decrypt the session.
SSL Decryption Exclusion list
The predefined and custom list of hostnames the firewall never decrypts, found under Certificate Management.
No Decrypt rule
A decryption policy rule that leaves matching traffic encrypted, often for sensitive URL categories.
Decryption profile
Settings that validate certificates and protocols for decrypted and non-decrypted sessions.
Decryption log
The log that records decryption sessions and failures, with reasons, used to find apps needing exclusions.
Server monitoring
User-ID collection of logon events from domain controllers, Exchange or eDirectory by the integrated or Windows User-ID agent.
Syslog parse profile
Regex or field rules that extract username and IP address from third-party syslog messages.
Terminal server agent
A User-ID component that maps users on shared multi-user hosts by source port range.
Group mapping
Retrieving directory group membership, usually via LDAP, so policy can reference groups.
Group include list
The set of directory groups the firewall retrieves for use in policy.
Cloud Identity Engine
A Palo Alto cloud service that syncs users and groups from directories and IdPs and provides cloud authentication.
Management plane
The part of the firewall that runs the web interface, CLI, logging and configuration, separate from traffic processing.
Permitted IP Addresses
A list on the MGT interface or an interface management profile limiting which hosts can reach management services.
Candidate configuration
The editable copy of the configuration that takes effect only after a commit.
Running configuration
The configuration the firewall is currently enforcing.
Partial commit
A commit of only selected changes, such as those made by specific administrators.
Config lock
A lock preventing other administrators from changing the candidate configuration.
Named snapshot
A saved, named copy of the configuration that can later be loaded into the candidate.
Explicit proxy
A proxy that clients are configured to use, directly or via a PAC file, sending requests to its IP and port.
Transparent proxy
A proxy that intercepts web traffic in the path without any client configuration.
PAC file
A proxy auto-config script that tells browsers which proxy to use for which destinations.
HTTP CONNECT
The method an explicit proxy client uses to ask the proxy to open a tunnel to an HTTPS destination.
Proxy authentication
Challenging a client that talks to an explicit proxy to prove its identity, commonly with Kerberos or SAML.
DNS proxy object
The firewall DNS proxy configuration that the web proxy uses to resolve destination names.

Domain 3: Integration and automation (24%)

Exam tips

Key terms

Device group
A Panorama container of firewalls sharing policies and objects, arranged in a hierarchy under Shared.
Shared location
The top of the device group hierarchy, whose objects and rules are inherited by every device group.
Pre-rules / post-rules
Panorama rules evaluated before, or after, a firewall's local rules.
Template
Panorama configuration for the firewall's Network and Device tab settings, such as interfaces, zones and server profiles.
Template stack
An ordered combination of templates assigned to firewalls; higher templates win when settings conflict.
Template variable
A placeholder such as $dns-primary in a template whose value is set per firewall.
Override
A local firewall value that replaces a template-pushed value until the override is reverted.
Commit to Panorama
Makes changes part of Panorama's running configuration without sending them to firewalls.
Push to Devices
Sends device group, template or collector group configuration from Panorama to managed devices.
Commit and Push
A single action that commits to Panorama and then pushes to the selected devices.
Panorama mode
The mode in which Panorama both manages devices and stores logs with its local Log Collector.
Management Only mode
Panorama mode that manages devices but stores no firewall logs locally.
Log Collector mode
Mode that makes an appliance a dedicated log collector managed by another Panorama.
Collector group
A set of Log Collectors that share log storage for redundancy and scale.
keygen
The XML API request type that returns an API key for a username and password.
XPath
The path syntax the XML API uses to address a node in the configuration tree.
set vs edit
XML API config actions: set adds or merges at the xpath, edit replaces the node at the xpath.
type=op
The XML API request type for running operational (non-configuration) commands expressed as XML.
REST API
The JSON-based PAN-OS API using versioned resource URLs and standard HTTP methods.
API-only role
An admin role profile with web UI and CLI disabled and only needed API permissions enabled.
API key lifetime
A device setting that makes API keys expire after a set period.
Infrastructure as code (IaC)
Managing configuration through version-controlled text files applied by tools rather than manual changes.
Declarative
Describing the desired end state and letting the tool compute the changes, as Terraform does.
Terraform state
The file where Terraform records the resources it manages and their current values.
Idempotent
Producing the same result no matter how many times an operation runs, a design goal of Ansible modules.
paloaltonetworks.panos
The Ansible collection of modules for managing PAN-OS firewalls and Panorama.
pan-os-python
Palo Alto's Python SDK that models firewall and Panorama configuration as an object tree.
External dynamic list (EDL)
A web-hosted list of IPs, domains or URLs that the firewall retrieves periodically and uses in policy without a commit.
Check interval
How often the firewall retrieves an EDL: every five minutes, hourly, daily, weekly or monthly.
Dynamic address group (DAG)
An address group whose members are IP addresses registered with tags that match its filter.
Tag registration
Associating a tag with an IP address or user at runtime, via the API, VM monitoring, auto-tagging or agents.
DNS sinkhole
An anti-spyware action that answers malicious domain queries with a controlled address so infected hosts can be found.
Dynamic user group
A group whose membership is users with matching tags, used for user-based quarantine.
Auto-tagging
A log forwarding built-in action that adds or removes tags on IPs or users when a matching log is generated.
Built-in action
An action inside a log forwarding profile entry, such as tagging, performed when a log matches.
Tag timeout
The time after which an auto-applied tag is removed, letting a host leave quarantine automatically.
Webhook
An HTTP request sent to another system when an event occurs, used here via an HTTP server profile.
Payload format
The per-log-type URI, headers and body template an HTTP server profile uses to build its requests.
IP-Tag log
The log that records tags registered to and removed from IP addresses.
Bootstrap package
The config, license, software, content and plugins folders a VM-Series firewall reads on first boot.
init-cfg.txt
Bootstrap file with basic management, DNS, hostname and Panorama registration settings as key-value pairs.
bootstrap.xml
An optional full configuration file loaded during bootstrapping.
authcodes
The file in the license folder containing license authorization codes applied at first boot.
VM auth key
A key generated on Panorama that lets a bootstrapping VM-Series firewall register with it.
Zero Touch Provisioning (ZTP)
A process where supported hardware firewalls automatically connect to their assigned Panorama or cloud manager on first power-up.
PA-Series
Palo Alto's physical hardware firewalls with separate management and data plane resources.
Single-pass architecture
Processing each packet once for classification and inspection instead of passing it through separate engines.
VM-Series
The virtual machine form of PAN-OS for private hypervisors and public clouds, operated by the customer.
CN-Series
Containerized firewalls for Kubernetes, with CN-MGMT and CN-NGFW components managed by Panorama.
Cloud NGFW
A managed firewall service for AWS and Azure that Palo Alto operates and customers consume as a native cloud resource.
Rulestack
The collection of rules and objects used to configure a Cloud NGFW resource.
Strata Cloud Manager (SCM)
Palo Alto's cloud-delivered console for managing and monitoring NGFWs and Prisma Access.
Folder
An SCM hierarchy container whose configuration is inherited by the folders and devices beneath it.
Snippet
A reusable, named set of configuration in SCM that can be applied to folders or devices.
Strata Logging Service
The cloud log service that SCM-managed firewalls forward logs to for visibility and reporting.
Best practice assessment
An evaluation of configuration against Palo Alto recommendations with scores and remediation advice.
AIOps
AI-driven operations features that predict health and capacity problems and flag risky configuration.
Study NGFW Engineer for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the NGFW Engineer study plan