PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 270


A Panorama administrator configures a new zone and uses the zone in a new Security policy. After the administrator commits the configuration to Panorama, which device-group commit push operation should the administrator use to ensure that the push is successful?

Show Answer
Correct Answer: A,B

To ensure that the new zone and the security policy referencing it are successfully pushed to the devices, the administrator should use the 'include device and network templates' option. This option allows both the device group changes and the associated template changes to be pushed in a single operation, ensuring that all necessary configurations are applied correctly.

Discussion

10 comments
Sign in to comment
scallyOption: B
Sep 10, 2022

B is the correct answer. You need to push both the template and device group.

certprep2021Option: B
Mar 8, 2023

"Commit from Device Group, with the Include Network and Device Template option enabled to allow the template push to succeed along with the Device Group references." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpwCAC

TAKUM1yOption: B
Nov 11, 2022

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpwCAC

secdaddyOption: D
Sep 25, 2022

A and B are both default C isn't listed as a push operation Why not D to 'ensure that the push is successful ? https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/panorama-web-interface/panorama-commit-operations

KuronekosamaOption: B
Oct 7, 2022

B A: cleared to ignore local candidate config D: Will work, but you'll wipe out all the local config changes on that firewall. Not wrong, but not a great answer.

confusionOption: B
Oct 27, 2022

B Template to get the Zone applied on the FW. Device-group to get the Security Policy applied on the FW.

VickiFOption: B
Feb 2, 2023

But, the question specifies device group push.

Mmiri
Sep 30, 2023

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/panorama-web-interface/panorama-commit-operations#:~:text=(Selected%20by%20default)%20Pushes%20both%20the%20device%20group%20changes%20and%20the%20associated%20template%20changes%20to%20the%20selected%20firewalls%20and%20virtual%20systems%20in%20a%20single%20operation.%20To%20push%20these%20changes%20as%20separate%20operations%2C%20clear%20this%20option.

Sammy3637Option: B
Dec 12, 2023

After Panorama push ,next step is to push it to the devices

WhizdhumOption: B
Dec 16, 2023

Answer is B. To ensure that commit of template configurations work when referencing Device Group object, the commit must be done from the Device Group tab, with “Include Device and Network Templates” option enabled.

ali_sh85Option: B
Jul 16, 2024

B is correct not related to the candidate config