ExamGecko
Question list
Search
Search

Related questions











Question 290 - PCNSE discussion

Report
Export

To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?

A.
Add the policy to the target device group and apply a master device to the device group.
Answers
A.
Add the policy to the target device group and apply a master device to the device group.
B.
Reference the targeted device's templates in the target device group.
Answers
B.
Reference the targeted device's templates in the target device group.
C.
Clone the security policy and add it to the other device groups.
Answers
C.
Clone the security policy and add it to the other device groups.
D.
Add the policy in the shared device group as a pre-rule
Answers
D.
Add the policy in the shared device group as a pre-rule
Suggested answer: D

Explanation:

According to the Palo Alto Networks documentation1, the shared device group is a special device group that contains policies and objects that apply to all firewalls managed by Panorama. The policies in the shared device group can be configured as pre-rules or post-rules, which determine their priority relative to the policies in other device groups. Pre-rules have higher priority than the policies in other device groups, while post-rules have lower priority. Therefore, to ensure that a Security policy has the highest priority, the administrator should configure it in the shared device group as a pre-rule. Therefore, the correct answer is D.

The other options are not relevant or effective for ensuring that a Security policy has the highest priority:

Add the policy to the target device group and apply a master device to the device group: This option would add the policy to a specific device group, which is a subset of firewalls managed by Panorama.

The policy would only apply to the firewalls in that device group, not to all firewalls. Moreover, applying a master device to the device group does not affect the priority of the policy, but only allows synchronizing configuration changes across devices in the same device group2.

Reference the targeted device's templates in the target device group: This option would reference the templates that contain network and device settings for the targeted devices in the target device group. It does not affect the Security policy or its priority, but only allows applying consistent configuration settings across devices in the same device group3.

Clone the security policy and add it to the other device groups: This option would create copies of the security policy and add them to different device groups. However, this would not ensure that the policy has the highest priority, because it would still depend on whether it is configured as a pre-rule or a post-rule within each device group. Moreover, this option would create redundant and potentially conflicting policies across different device groups.

Reference: 1: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panoramaoverview/centralized-firewall-configuration-and-update-management/device-groups/device-grouppolicies 2:

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panoramaoverview/centralized-firewall-configuration-and-update-management/device-groups/synchronizeconfiguration-changes-across-devices-in-a-device-group 3:

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panoramaoverview/centralized-firewall-configuration-and-update-management/templates-and-templatestacks/reference-the-targeted-devices-templates-in-the-target-device-group

asked 23/09/2024
Joseph Washington
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first