ExamGecko
Question list
Search
Search

Question 306 - PCNSA discussion

Report
Export

Which policy set should be used to ensure that a policy is applied just before the default security rules?

A.
Parent device-group post-rulebase
Answers
A.
Parent device-group post-rulebase
B.
Child device-group post-rulebase
Answers
B.
Child device-group post-rulebase
C.
Local Firewall policy
Answers
C.
Local Firewall policy
D.
Shared post-rulebase
Answers
D.
Shared post-rulebase
Suggested answer: D

Explanation:

The policy set that should be used to ensure that a policy is applied just before the default security rules is the shared post-rulebase. The shared post-rulebase is a set of Security policy rules that are defined on Panorama and apply to all firewalls or device groups. The shared post-rulebase is evaluated after the local firewall policy and the child device-group post-rulebase, but before the default security rules.The shared post-rulebase can be used to enforce common security policies across multiple firewalls or device groups, such as blocking high-risk applications or traffic1.Reference:Security Policy Rule Hierarchy,Security Policy Rulebase,Certifications - Palo Alto Networks,Palo Alto Networks Certified Network Security Administrator (PAN-OS 10.0)or [Palo Alto Networks Certified Network Security Administrator (PAN-OS 10.0)].

asked 23/09/2024
VEDA VIKASH Matam Shashidhar
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first