1. Home
  2. Palo Alto Networks
  3. NGFW-Engineer Exam Syllabus

Palo Alto Networks NGFW-Engineer Exam Syllabus

Start Free NGFW-Engineer Exam Practice After Reviewing the Topics

Before starting your NGFW-Engineer exam preparation, it is recommended to review the complete Palo Alto Networks Next-Generation Firewall Engineer exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free NGFW-Engineer questions. We also provide premium NGFW-Engineer practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

Palo Alto Networks NGFW-Engineer Exam Objectives

Section Weight Objectives
PAN-OS Networking Configuration 38% 1.1 Configure interface
1.1.1 Layer 2
1.1.2 Layer 3
1.1.3 Virtual wire
1.1.4 Tunnel interfaces
1.1.5 Aggregate Ethernet (AE)
1.1.6 Management
1.2 Configure zones
1.3 Configure high availability (HA)
1.3.1 Active/active
1.3.2 Active/passive
1.3.3 Link and Path Monitoring
1.4 Configure routing
1.4.1 Dynamic routing protocols
1.4.2 Redistribution and policies
1.4.3 Route monitoring
1.4.4 Advanced Routing Engine
1.5 Configure GlobalProtect
1.5.1 Portals
1.5.2 Gateways
1.5.3 Authentication
1.5.4 Split tunneling
1.6 Configure tunnels
1.6.1 IPSec
1.6.2 Quantum-resistant cryptography
1.6.3 Generic Routing Encapsulation (GRE)
PAN-OS Device Setting Configuration 38% 2.1 Implement authentication roles, profiles, and sequences
2.2 Configure virtual systems (VSYS)
2.2.1 Interfaces and zones
2.2.2 Virtual routers
2.2.3 Logical routers
2.2.4 Inter-VSYS routing and security
2.3 Configure logging
2.3.1 Strata Logging Service
2.3.2 Log forwarding
2.3.3 Log collectors and log collector groups
2.4 Implement PAN-OS software updates
2.5 Configure certificates
2.5.1 PKI integration
2.5.2 Authentication
2.5.3 SLS/TLS profiles
2.5.4 Decryption (e.g., subordinate CA, forward trust/untrust)2.5.5 Certificate profiles
2.6 Configure on-premises and Cloud Identity Engine User-ID
2.6.1 Group mapping and directory sync
2.6.2 User-to-IP mapping and user context
2.6.3 Redistribution and Segments
2.7 Configure web proxy on PAN-OS
Integration and Automation 24% 3.1 Install the selected deployment option
3.1.1 PA-Series
3.1.2 VM-Series
3.1.3 CN-Series
3.1.4 Cloud NGFW
3.1.5 AI Runtime Security
3.2 Use APIs to automate deployment
3.3 Manage third-party services to deploy NGFWs (e.g., Kubernetes, hypervisors, CSPs,
Terraform, Ansible)
3.4 Use on-premises centralized management
3.4.1 Panorama
3.4.2 Templates and Device Groups
3.4.3 Pre- and post-ruleset
3.5 Build Application Command Center (ACC) dashboards and custom reports
Official Information https://www.paloaltonetworks.com/services/education/palo-alto-networks-ngfw-engineer