exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 549 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 549
Topic #: 1
[All PCNSE Questions]



Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?

  • A. shared pre-rules

    DATACENTER_DG pre-rules -
    rules configured locally on the firewall

    DATACENTER_DG post-rules -
    shared post-rules
    shared default rules
  • B. shared pre-rules

    DATACENTER_DG pre-rules -
    rules configured locally on the firewall
    shared post-rules

    DATACENTER_DG post-rules -
    DATACENTER_DG default rules
  • C. shared pre-rules

    DATACENTER_DG pre-rules -
    rules configured locally on the firewall
    shared post-rules

    DATACENTER_DG post-rules -
    shared default rules
  • D. shared pre-rules

    DATACENTER_DG pre-rules -
    rules configured locally on the firewall

    DATACENTER_DG post-rules -
    shared post-rules
    DATACENTER_DG default rules
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ALCOSTA35
2 months, 3 weeks ago
Selected Answer: D
The DATACENTER Default rules override the Shared ones. D is the answer
upvoted 2 times
...
98a8af0
4 months, 4 weeks ago
Selected Answer: D
Default rules are override
upvoted 2 times
...
thelittleyellowbirdie
6 months, 1 week ago
this question was in my exam 09/08/2024
upvoted 2 times
...
apiloran
7 months, 1 week ago
Selected Answer: D
Screenshots indicate that the default rules have been overridden. The accurate answer is D. If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level.
upvoted 4 times
af67d32
3 days, 7 hours ago
so if you override the default Interzone, it will be evaluated first ^^? This boils down to dropping 100% of your traffic, not that effective
upvoted 1 times
...
...
Mtro
9 months, 2 weeks ago
Selected Answer: D
Shared Pre-Policies Device group hierarchy Pre-Policies Local Firewall Policies Device group hierarchy Post-Policies Shared Post-Policies Default Rules there is no shared defaukt event hough it exist and it can be used as well. This is a document from Palo training ... we have to use same wording as they provide it ( it is an exam so go with whatever they want the answer to be. Even if it's not 100% correct)
upvoted 2 times
...
Pacheco
1 year ago
Selected Answer: A
Default rules belong to the Shared level and not any particular device group, which leaves us with only option A and C. The following doc states this and also explicitly gives us the order :) Shared pre Group pre Locals Group post Shared post Shared defaults https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies
upvoted 2 times
TeachTrooper
1 week, 2 days ago
this is from the link that you shared, please read before you share Firewall—You can override default rules that are part of the predefined configuration on the firewall or vsys, or that Panorama pushed from the Shared location or a device group.
upvoted 1 times
...
...
Marshpillowz
1 year ago
Selected Answer: A
I think A
upvoted 2 times
...
[Removed]
1 year ago
Based on that A 1. Shared pre-rules 2. Device group pre-rules 3. Local firewall rules 4. Device group post-rules 5. Shared post-rules 6. intrazone-default interzone-default https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies
upvoted 1 times
...
TeachTrooper
1 year ago
Selected Answer: D
I would choose D based on https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies: If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level. As we have overridden the default ruleset in the device group it will be applied instead of the shared one.
upvoted 2 times
Jared28
11 months, 3 weeks ago
TeachTrooper is correct. However, the answer should also include shared default rule at the very bottom as the interzone rule does not have an override. Due to so many people stating A, I labbed it, re-confirming it, to make sure I wasn't thinking of this incorrectly.
upvoted 1 times
...
...
scanossa
1 year, 1 month ago
I got this question in the exam
upvoted 1 times
...
hifumi_daisuki
1 year, 2 months ago
Selected Answer: A
Shared Pre-Rules Device Group Pre-Rules Local Firewall Rules Device Group Post Rule Shared Post-Rules Default Rules The default rules apply only to the Security rulebase, and are predefined on Panorama (at the Shared level) and the firewall (in each vsys). https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies
upvoted 2 times
...
wallaka
1 year, 2 months ago
Selected Answer: A
A. This one isn't as tricky as it looks--device groups don't have default rules.
upvoted 2 times
Eiffelsturm
1 year, 2 months ago
sure they have. Take a look into your Panorama
upvoted 2 times
...
...
tune_in
1 year, 3 months ago
Selected Answer: A
https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies DG post-rules before Shared post rules
upvoted 2 times
...
dgonz
1 year, 5 months ago
Selected Answer: D
yup.. sorry it is D
upvoted 2 times
...
lmla89
1 year, 5 months ago
Selected Answer: D
As per News088
upvoted 2 times
...
news088
1 year, 5 months ago
Would choose D. base on doc from dgonz the order is: Shared pre rules DG prer ules local rules DG post rules Shared post rules default rules Then be aware of order in DG when 2 config matches. in DG the config maintained is the child. On template is the oposite , the config maintained is the father. From the same doc. If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level.
upvoted 3 times
...
dgonz
1 year, 5 months ago
Selected Answer: A
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies
upvoted 2 times
homersimpson
1 year, 2 months ago
Why do you keep voting different answers?
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago