exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 254 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 254
Topic #: 1
[All PCNSE Questions]

An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy.
Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?

  • A. Preview Changes
  • B. Policy Optimizer
  • C. Managed Devices Health
  • D. Test Policy Match
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
datz
Highly Voted 2 years, 8 months ago
Selected Answer: A
Common guys? "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" which tool is used to review policy creation and also can verify that Unwanted traffic is not allowed? how on earth Test Policy will tell you what unwanted trafffic will be allowed? :/ I am going for A :)
upvoted 5 times
Kris92
1 year, 3 months ago
pretty simple, you test policy with unwanted traffic and make sure it's denied how on earth is preview change going to help with that?
upvoted 8 times
...
Kris92
1 year, 3 months ago
"validate that policies that will be deployed" - preview change "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" - test policy match
upvoted 7 times
...
...
ALCOSTA35
Most Recent 5 days, 16 hours ago
Selected Answer: A
The question was terribly written. He wanted to know how I can ensure that the policies go to the intended Device group in the hierarchy.
upvoted 1 times
...
corpguy
1 week, 4 days ago
Selected Answer: D
Test the policy rules in your running configuration to ensure that your policies appropriately allow and deny traffic and access to applications and websites in compliance with your business needs and requirements. You can test and verify that your policy rules are allowing and denying the correct traffic by executing policy match tests for your firewalls directly from the web interface.
upvoted 1 times
...
af67d32
2 weeks, 3 days ago
Selected Answer: B
Policy Optimizer is the only option out of the 4 that displays the rules in comprehensive order of the policy
upvoted 1 times
...
corpguy
1 month, 1 week ago
Selected Answer: D
I think D is the best answer https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/test-policy-rule-traffic-matches
upvoted 1 times
...
hcir
7 months, 3 weeks ago
Selected Answer: D
You test before adding the rule. Preview Changes only compares the candidate config with the running.
upvoted 3 times
...
Shastings1
10 months ago
This is a poorly worded question, but the answer is D - test policy match. Goal here to use a tool to verify that you already have a “deny” rule . Test policy match check the current config for the unwanted traffic. There should be a deny or you need to add another rule. Test policy match source ( bad guy) destination (Crown Jewels) action = deny…..
upvoted 1 times
...
VenomX51
10 months, 2 weeks ago
Selected Answer: A
An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy. If you add a policy to device groups for firewall 2 and 3, you can use Preview changes to ensure that that policy is not going to be applied to FW1 and allow unwanted traffic. Preview Changes will verify your "policy creation logic" - i.e. If I create a policy in this device group it will not be applied to these firewalls.
upvoted 1 times
...
Thunnu
11 months ago
Answer D https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/test-policy-rule-traffic-matches
upvoted 2 times
...
SH_
1 year ago
Selected Answer: A
"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.
upvoted 1 times
...
SH_
1 year ago
"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.
upvoted 1 times
...
JRKhan
1 year, 1 month ago
Selected Answer: A
A is correct. Question is about policies that havent been deployed yet. Test policy match the policies that have already been deployed.
upvoted 1 times
...
Metgatz
1 year, 1 month ago
Selected Answer: D
Say check the logic Option D
upvoted 3 times
...
Adilon
1 year, 1 month ago
D for me
upvoted 2 times
...
Whizdhum
1 year, 2 months ago
Selected Answer: A
Answer is A. Preview Changes asks the firewall to compare the configurations you selected in the Commit Scope to the running configuration. The answer is not Test Policy Match, which tests policy rules in your running configuration. Preview Changes is pre-commit, Test Policy Match is post-commit.
upvoted 2 times
...
dorf05
1 year, 2 months ago
Selected Answer: D
preview (before) commit and review ( after commit). and the question is " ..........administrator use to review the policy creation and verify that unwanted traffic is not allowed". this similar to question # 1
upvoted 2 times
...
Metgatz
1 year, 2 months ago
The correct option is D Test Policy Match
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago