Exam PCNSA All QuestionsBrowse all questions from this exam
Question 305

Which policy set should be used to ensure that a policy is applied just before the default security rules?

    Correct Answer: D

    To ensure that a policy is applied just before the default security rules, the appropriate option is the Child device-group post-rulebase. The default security rules are typically the last set of rules applied, and the post-rulebase of the child device-group is evaluated right before these default rules, making it the correct choice.

Discussion
rehorOption: A

Order: Shared pre-rules Device group pre-rules Local firewall rules Device group post-rules Shared post-rules Intrazone-default Interzone-default

cjaceOption: A

A. Shared post-rulebase The shared post-rulebase is evaluated after the pre-rulebase and before the default security rule

AredusOption: D

Answer should be D as the question asks for the policy to be placed JUST BEFORE the default rules

redgi0Option: B

Based on the poorly worden question, and reply from rehor, I'm tempted to say that the answer is B ! Local firewall rules = policy no ??

redgi0

my bad answer is A :)

443AnnnyOption: A

answer A

[Removed]Option: A

I'm not sure but according to this link it would be answer A https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies