PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 330


A firewall has Security policies from three sources:

1. locally created policies

2. shared device group policies as pre-rules

3. the firewall's device group as post-rules

How will the rule order populate once pushed to the firewall?

Show Answer
Correct Answer: A

The correct order follows a logical sequence based on precedence and application of rules: shared device group policies (pre-rules) are applied first to ensure that any centrally managed important rules are prioritized, followed by local policies which are specific to the particular firewall, and finally, the firewall's device group policies (post-rules) which are evaluated last to finalize any additional configurations or exceptions required at the device group level.

Discussion

13 comments
Sign in to comment
mysteryzjokerOption: A
Sep 12, 2022

A, not D. Post rules are applied after local policies.

lol12Option: A
Dec 23, 2022

A Tricky wording. Just focus on Pre/Local/Post

TAKUM1yOption: A
Oct 28, 2022

https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/manage-device-groups/manage-the-rule-hierarchy

guilhermeandradeOption: A
Oct 26, 2022

A. because the 3 option is post-rule

SarbiOption: A
Dec 27, 2022

A is correct

nose999Option: D
Sep 6, 2022

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

nose999Option: A
Sep 6, 2022

Sorry A is correct

confusionOption: A
Oct 29, 2022

A Shared-Local-Post

DenskyDenOption: A
Jan 17, 2023

A. 1 million percent!

hifumi_daisukiOption: A
Dec 21, 2023

Shared Pre-Rules Device Group Pre-Rules Local Firewall Rules Device Group Post Rule Shared Post-Rules Default Rules https://docs.paloaltonetworks.com/panorama/11-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

avatorOption: A
Jan 25, 2024

the pre-rule and the post-rule are mentioned in the question not on the answers we need to map it with the listed choice so A is the correct answer.

428cd48
Mar 20, 2024

Palo creates tests for you to fail, all other vendors for you to learn and pass

ATRRHMNOption: A
Jul 10, 2024

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/panorama-web-interface/defining-policies-on-panorama