Read the tunnel configuration objective on the NGFW-Engineer blueprint and there are three items under it: IPSec, quantum-resistant cryptography, and GRE. Two of those have been on firewall exams for twenty years. The third is there because the encryption standards that protect a site-to-site tunnel are being replaced, and Palo Alto has decided a certified engineer should already know that.
It is a small line on a long syllabus, and it is the clearest signal available that this blueprint was written recently rather than inherited. The Palo Alto NGFW Engineer certification asks 75 questions in 90 minutes for $250 USD, needs a scaled 860 out of 300 to 1000, and splits across just three domains. This guide works through all three, what the automation domain is doing on a firewall paper, and how the credential differs from its siblings.
Why Is Quantum-Resistant Cryptography on a Firewall Exam?
Because the tunnels a firewall builds today are expected to stay confidential for years, and the cryptography protecting them is being replaced. The NGFW-Engineer syllabus lists quantum-resistant cryptography as a tunnel configuration objective alongside IPSec and GRE, which puts it in the same category as the protocols an engineer configures rather than in a theory appendix.
The threat model behind it is the harvest-now-decrypt-later problem. Traffic captured today can be stored and decrypted later once the cryptography protecting it becomes breakable, so a VPN tunnel carrying data with a long confidentiality life is exposed by a future capability rather than a present one. That is why standards bodies moved before the capability existed.
What this actually means for the exam
Expect recognition and configuration awareness rather than mathematics. You should know that PAN-OS supports quantum-resistant options on IPSec tunnels, why an engineer would enable them, and where that setting sits relative to the conventional IPSec parameters. The underlying algorithms were standardised through NIST’s post-quantum cryptography project, which is the reference if you want the background rather than the button.
It also sets the tone for the whole blueprint. This is not a syllabus that describes a firewall as a packet filter with rules. It describes a platform with routing, identity, decryption, logging, virtual systems and an API, and the exam tests whether you can operate the whole thing.
How Do the Three NGFW Engineer Domains Divide the Marks?
PAN-OS Networking Configuration and PAN-OS Device Setting Configuration carry 40 percent each, and Integration and Automation takes the remaining 20. Three domains is unusually few, and the consequence is that each one covers far more ground than a domain name normally implies, particularly the two 40 percent blocks.
| Domain | Weight | Approximate questions of 75 |
|---|---|---|
| PAN-OS Networking Configuration | 40% | 30 |
| PAN-OS Device Setting Configuration | 40% | 30 |
| Integration and Automation | 20% | 15 |
Eighty percent of the paper is PAN-OS configuration, split between what the firewall does on the wire and what the firewall is set up to be. That split is worth internalising early, because it is not the split most study material uses. Vendor courses tend to organise by feature; this exam organises by whether the setting is about traffic or about the device.
The 20 percent automation domain then sits outside both, and it is the one that surprises people. It is not a footnote about scripting. It names deployment form factors, APIs, third-party orchestration tooling and Panorama by name, which makes it a genuine fifteen questions of material rather than a rounding error.
What Is the NGFW Engineer Exam Format?
NGFW-Engineer is 75 questions in 90 minutes at $250 USD, with a passing score of 860 on a scale that runs from 300 to 1000. Registration is through Pearson VUE. Palo Alto positions the credential at Specialist level, and recommends two instructor-led courses: EDU-210 Firewall Essentials, and Panorama NGFW Management.
| Specification | Detail |
|---|---|
| Exam number | NGFW-Engineer |
| Credential level | Specialist |
| Questions | 75 |
| Duration | 90 minutes |
| Passing score | 860 on a scale of 300 to 1000 |
| Price | $250 USD |
| Registration | Pearson VUE |
| Recommended training | EDU-210 Firewall Essentials; Panorama: NGFW Management |
The cut score is higher than it looks
An 860 on a 300 to 1000 scale is not 86 percent, because the floor is 300 rather than zero. Expressed as a position within the usable range it sits around 80 percent of the way up, which makes this a demanding cut score by any reading. Scaled scoring also means no fixed number of correct answers guarantees a pass, so practice percentages are a relative signal rather than a prediction.
Seventy-five questions in 90 minutes gives 72 seconds each, which is comfortable for recognition and tight for a multi-step configuration scenario. Working through an NGFW Engineer practice test against the clock is the only reliable way to find out which of the seven device-settings subject areas slows you down.
What Does PAN-OS Networking Configuration Cover?
This 40 percent domain is everything the firewall does with traffic on the wire. It covers interface configuration across Layer 2, Layer 3, virtual wire, tunnel, aggregate Ethernet and management types; zones; high availability in active/active and active/passive with link and path monitoring; routing; GlobalProtect; and tunnels.
Interfaces and zones are the foundation and the exam treats them as such. Virtual wire in particular is worth deliberate study because it is the mode people configure least often and the one whose behaviour is least like a conventional interface. Aggregate Ethernet appears alongside it, and the two are frequently paired in scenario questions about inserting a firewall without redesigning the network.
Routing has grown into a real topic
The objectives name dynamic routing protocols, redistribution and policies, route monitoring, and the Advanced Routing Engine specifically. That last item is the tell: PAN-OS has moved its routing implementation forward, and the exam expects you to know the current engine rather than the legacy virtual-router behaviour. This is the part of the domain most likely to catch out an engineer working from older material.
GlobalProtect closes the domain with portals, gateways, authentication and split tunnelling, which is remote access treated as a networking function rather than a separate product. The configuration detail behind all of it sits in the official PAN-OS documentation, which is the reference the exam objectives are written against.
What Sits Inside PAN-OS Device Setting Configuration?
Seven separate subject areas, which is why this 40 percent domain is the hardest to plan for. It covers authentication roles, profiles and sequences; virtual systems; logging; software updates; certificates; User-ID through the on-premises and Cloud Identity Engine; and web proxy on PAN-OS. Any one of those would be a domain on a smaller exam.
Certificates are the densest item. The objectives name PKI integration, authentication, SSL and TLS profiles, decryption including subordinate certificate authorities and forward trust and untrust, and certificate profiles. Decryption alone accounts for a meaningful share of real-world firewall complexity, and forward trust versus forward untrust is a distinction that has to be understood rather than memorised.
User-ID and virtual systems are the other two heavyweights
User-ID covers group mapping and directory synchronisation, user-to-IP mapping and user context, and redistribution and segments, across both the on-premises and Cloud Identity Engine paths. Virtual systems covers interfaces and zones inside a VSYS, virtual routers, logical routers, and inter-VSYS routing and security, which is effectively multi-tenancy on a single appliance.
- Authentication roles, profiles and sequences, and how a sequence fails over between methods
- Virtual systems, including inter-VSYS routing and the security policy that governs it
- Logging through the Strata Logging Service, forwarding, and log collector groups
- PAN-OS software update implementation
- Certificates, PKI integration, SSL and TLS profiles, and decryption
- User-ID across on-premises and Cloud Identity Engine deployments
- Web proxy on PAN-OS
The planning advice that follows from that list is blunt: do not treat this as one domain. Treat it as seven small ones and check your coverage of each, because a candidate who is strong on certificates and weak on virtual systems can still be losing a quarter of the marks in what looks like a single well-studied area.
Why Is a Fifth of the Exam About Automation and Deployment?
Because a firewall engineer no longer installs one appliance. The Integration and Automation domain is 20 percent of NGFW-Engineer and it names five deployment form factors, API-driven deployment, third-party orchestration tooling including Kubernetes, hypervisors, cloud service providers, Terraform and Ansible, plus Panorama and Application Command Center reporting.

The five form factors are the part worth learning first, because they define what the other objectives operate on. PA-Series is the hardware appliance, VM-Series the virtual machine, CN-Series the containerised form, Cloud NGFW the cloud-provider-managed service, and AI Runtime Security the newest addition. Knowing which one fits which requirement is a straightforward examinable judgement.
The orchestration half is where a traditional firewall engineer is most likely to be underprepared. Deploying CN-Series means understanding how a firewall is scheduled and networked inside a cluster, and the concepts underlying that sit in the Kubernetes documentation rather than anywhere in a firewall manual. Terraform and Ansible appear for the same reason: the exam assumes deployment is code.
Panorama then closes the domain from the management side, with templates, device groups, and pre- and post-rulesets. That last concept is genuinely examinable and genuinely confusing on first contact, because it determines the order in which centrally pushed rules and locally defined rules are evaluated.
How Does NGFW Engineer Differ From the Other Palo Alto Credentials?
NGFW-Engineer is the platform-operations credential. It is about configuring and running next-generation firewalls themselves, whereas Palo Alto’s other Specialist and Professional credentials are organised around either a different product family or a different job function within network security.
The clearest way to place it is by what the exam does not contain. There is no detection engineering, no SOC workflow, no incident response, and no security operations tooling. Those live in the operations-side credentials. Equally, there is no architecture or design content of the kind an architect credential carries, since this exam is about implementing a design rather than producing one.
That design-tier distinction is worth understanding before choosing, and this walkthrough of the NetSec Architect exam shows how differently the same vendor examines the design role. The two credentials suit different points in a career rather than different levels of the same one.
What NGFW-Engineer shares with all of them is the scaled scoring model and the Pearson VUE delivery, so preparation habits transfer even where content does not. Candidates who have sat one Palo Alto exam already know the shape of the paper.
How Should You Prepare for a Scaled 860 Cut Score?
An 860 on a 300 to 1000 scale leaves little margin, so preparation has to be broad rather than selective. With only three domains and two of them at 40 percent, there is nowhere to hide a weakness. The order below is deliberately sequential, because each stage assumes the configuration knowledge the previous one builds.

- Build the networking domain first on real interfaces, zones and routing, because it is 40 percent of the paper and everything in the device-settings domain is configured on top of an interface that already works.
- Break the device-settings domain into its seven subject areas and check coverage of each separately, since a candidate strong on certificates and weak on virtual systems is still losing marks inside what looks like one studied area.
- Learn the five deployment form factors next and be able to say which requirement each one answers, because the automation objectives all operate on a form factor you have chosen.
- Finish with Panorama and the API material, practising template and device-group behaviour and the evaluation order of pre- and post-rulesets, which is the concept most likely to be tested and most likely to be misremembered.
Palo Alto’s recommended route is to read the datasheet topics, work the digital learning path, then take the instructor-led courses as needed. The two courses it names are EDU-210 Firewall Essentials and Panorama NGFW Management, and the pairing tells you something: the vendor expects Panorama competence, not just single-firewall competence.
If you are coming to this from hands-on firewall administration, the gap is almost always the automation domain and the newer parts of device settings, particularly the Cloud Identity Engine and web proxy. If you are coming from a cloud or platform background, the gap is the opposite way round. A candidate who already has the site’s NGFW Engineer study materials to hand should use them to audit which half they are missing before scheduling.
Which Roles Does Palo Alto Aim This Credential At?
Palo Alto names the audience explicitly on its official NGFW Engineer page: network engineers, security engineers, firewall engineers, firewall administrators, professional services consultants, and network security support engineers. The common thread is responsibility for the configuration and running of the firewalls, rather than for the security programme around them.
That is a wider audience than the credential name suggests. Professional services consultants appear on the list because deployment work is exactly what the automation domain describes, and support engineers appear because troubleshooting a device requires knowing how every one of those seven device-settings areas was configured in the first place.
The credential sits at Specialist level, which places it as a working-practitioner qualification rather than an entry point or an expert capstone. Someone whose day involves PAN-OS is the intended candidate; someone hoping the exam will teach them PAN-OS from nothing has picked the wrong starting point.
The honest limitation is that this is a single-vendor operations credential, and its value tracks the presence of Palo Alto equipment in the organisations you are applying to. Where that equipment is present it is a strong and specific signal, because the syllabus maps closely to what the job actually involves.
Frequently Asked Questions
How many questions are on the NGFW Engineer exam?
Seventy-five questions in 90 minutes, which is 72 seconds each. Registration runs through Pearson VUE and the fee is $250 USD.
What is the passing score for Palo Alto NGFW Engineer?
860 on a scale of 300 to 1000. Because the floor is 300 rather than zero, that is not 86 percent and sits around 80 percent of the way up the usable range.
What are the NGFW Engineer exam domains?
Three: PAN-OS Networking Configuration at 40 percent, PAN-OS Device Setting Configuration at 40 percent, and Integration and Automation at 20 percent.
Does the NGFW Engineer exam cover automation tools?
Yes. The Integration and Automation domain names Kubernetes, hypervisors, cloud service providers, Terraform and Ansible directly, alongside API-driven deployment and Panorama management.
Why does the syllabus mention quantum-resistant cryptography?
It is listed as a tunnel configuration objective beside IPSec and GRE. PAN-OS supports quantum-resistant options on tunnels, and the exam expects awareness of when an engineer would enable them.
What level is the NGFW Engineer certification?
Specialist, according to Palo Alto’s own education page. That places it as a working-practitioner credential rather than an entry point or an expert-tier capstone.
Which training does Palo Alto recommend?
Two instructor-led courses: EDU-210 Firewall Essentials Configuration and Management, and Panorama NGFW Management. The pairing signals that Panorama competence is expected, not optional.
Which deployment form factors are examinable?
Five are named: PA-Series hardware, VM-Series virtual machines, CN-Series containers, Cloud NGFW, and AI Runtime Security. Knowing which fits which requirement is a straightforward examinable judgement.
Is NGFW Engineer suitable for beginners?
No. Palo Alto aims it at engineers and administrators already responsible for firewall configuration. The blueprint assumes working PAN-OS familiarity rather than teaching it.
How long should you prepare for NGFW Engineer?
Long enough to cover all seven device-settings subject areas separately rather than as one block. Practitioners already working in PAN-OS commonly need weeks; the automation domain is usually the gap.
Conclusion
NGFW-Engineer is a three-domain exam that behaves like a nine-domain one, because both 40 percent blocks hide multiple subject areas underneath a single heading. Seventy-five questions, 90 minutes, $250, a scaled 860 out of 300 to 1000, and Specialist level. Eighty percent of it is PAN-OS configuration, split between traffic and device.
Build the networking domain first because everything else configures on top of it, then break device settings into its seven areas and audit them one at a time. Learn the five deployment form factors before touching the automation objectives, and give Panorama’s template, device-group and ruleset ordering the attention the vendor’s own course recommendation implies. The quantum-resistant line in the tunnel objectives is a small thing, but it tells you what kind of blueprint this is.
