Exam PCNSE All QuestionsBrowse all questions from this exam
Question 270

A Panorama administrator configures a new zone and uses the zone in a new Security policy. After the administrator commits the configuration to Panorama, which device-group commit push operation should the administrator use to ensure that the push is successful?

    Correct Answer: B

    To ensure that the new zone and the security policy referencing it are successfully pushed to the devices, the administrator should use the 'include device and network templates' option. This option allows both the device group changes and the associated template changes to be pushed in a single operation, ensuring that all necessary configurations are applied correctly.

Discussion
certprep2021Option: B

"Commit from Device Group, with the Include Network and Device Template option enabled to allow the template push to succeed along with the Device Group references." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpwCAC

scallyOption: B

B is the correct answer. You need to push both the template and device group.

TAKUM1yOption: B

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpwCAC

ali_sh85Option: B

B is correct not related to the candidate config

WhizdhumOption: B

Answer is B. To ensure that commit of template configurations work when referencing Device Group object, the commit must be done from the Device Group tab, with “Include Device and Network Templates” option enabled.

Sammy3637Option: B

After Panorama push ,next step is to push it to the devices

VickiFOption: B

But, the question specifies device group push.

Mmiri

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/panorama-web-interface/panorama-commit-operations#:~:text=(Selected%20by%20default)%20Pushes%20both%20the%20device%20group%20changes%20and%20the%20associated%20template%20changes%20to%20the%20selected%20firewalls%20and%20virtual%20systems%20in%20a%20single%20operation.%20To%20push%20these%20changes%20as%20separate%20operations%2C%20clear%20this%20option.

confusionOption: B

B Template to get the Zone applied on the FW. Device-group to get the Security Policy applied on the FW.

KuronekosamaOption: B

B A: cleared to ignore local candidate config D: Will work, but you'll wipe out all the local config changes on that firewall. Not wrong, but not a great answer.

secdaddyOption: D

A and B are both default C isn't listed as a push operation Why not D to 'ensure that the push is successful ? https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/panorama-web-interface/panorama-commit-operations