PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 254


An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy.

Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?

Show Answer
Correct Answer: D

The correct tool to review the policy creation logic and verify that unwanted traffic is not allowed is 'Test Policy Match'. This tool allows administrators to simulate specific traffic conditions and determine which policy rules would be triggered. By doing so, it helps ensure that any newly created policies will function as intended before they are deployed, thereby preventing unwanted traffic from being allowed.

Discussion

17 comments
Sign in to comment
datzOption: A
May 28, 2022

Common guys? "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" which tool is used to review policy creation and also can verify that Unwanted traffic is not allowed? how on earth Test Policy will tell you what unwanted trafffic will be allowed? :/ I am going for A :)

Kris92
Nov 9, 2023

pretty simple, you test policy with unwanted traffic and make sure it's denied how on earth is preview change going to help with that?

Kris92
Nov 9, 2023

"validate that policies that will be deployed" - preview change "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" - test policy match

MetgatzOption: D
Jan 12, 2024

Say check the logic Option D

MetgatzOption: D
Dec 9, 2023

The correct option is D Test Policy Match

dorf05Option: D
Dec 10, 2023

preview (before) commit and review ( after commit). and the question is " ..........administrator use to review the policy creation and verify that unwanted traffic is not allowed". this similar to question # 1

WhizdhumOption: A
Dec 16, 2023

Answer is A. Preview Changes asks the firewall to compare the configurations you selected in the Commit Scope to the running configuration. The answer is not Test Policy Match, which tests policy rules in your running configuration. Preview Changes is pre-commit, Test Policy Match is post-commit.

AdilonOption: D
Jan 3, 2024

D for me

dgonzOption: D
Aug 30, 2023

it asks for "which tool" not sure if the preview pane can be considered as a tool... so I choose D, which is a tool

Omid2022Option: A
Oct 31, 2023

Test policy match works after commiting the config, so you belowed up the network then you want to check it!!!

RoamingFoOption: D
Nov 23, 2023

Preview will only show the changes, which is not enough to determine if traffic will be allowed or denied. This is a collective result of all the rules old and new. I think D is the most acceptable answer for this poorly worded question.

scanossaOption: D
Nov 23, 2023

The question doesn´t say "preview", it says "review". It could involve rules already deployed, som answer D. Answer A doesn't show if a specific traffic is allowed or not

JRKhanOption: A
Jan 14, 2024

A is correct. Question is about policies that havent been deployed yet. Test policy match the policies that have already been deployed.

SH_Option: A
Feb 5, 2024

"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.

SH_Option: A
Feb 5, 2024

"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.

ThunnuOption: D
Mar 23, 2024

Answer D https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/test-policy-rule-traffic-matches

VenomX51Option: A
Apr 8, 2024

An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy. If you add a policy to device groups for firewall 2 and 3, you can use Preview changes to ensure that that policy is not going to be applied to FW1 and allow unwanted traffic. Preview Changes will verify your "policy creation logic" - i.e. If I create a policy in this device group it will not be applied to these firewalls.

Shastings1Option: D
Apr 21, 2024

This is a poorly worded question, but the answer is D - test policy match. Goal here to use a tool to verify that you already have a “deny” rule . Test policy match check the current config for the unwanted traffic. There should be a deny or you need to add another rule. Test policy match source ( bad guy) destination (Crown Jewels) action = deny…..

hcirOption: D
Jun 30, 2024

You test before adding the rule. Preview Changes only compares the candidate config with the running.