exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 137 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 137
Topic #: 1
[All PCNSA Questions]

Which statement is true about Panorama managed devices?

  • A. Panorama automatically removes local configuration locks after a commit from Panorama.
  • B. Local configuration locks prohibit Security policy changes for a Panorama managed device.
  • C. Security policy rules configured on local firewalls always take precedence.
  • D. Local configuration locks can be manually unlocked from Panorama.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Racoon1
Highly Voted 1 year, 3 months ago
Selected Answer: A
Panorama Administrator's Guide Manage Locks for Restricting Configuration Changes Locking the candidate or running configuration prevents other administrators from changing the configuration until you manually remove the lock or Panorama removes it automatically (after a commit). Locks ensure that administrators don’t make conflicting changes to the same settings or interdependent settings during concurrent login sessions.
upvoted 5 times
...
abbasr
Most Recent 4 months ago
Correct Answer is D Local Configuration Locks: Local configuration locks are used to prevent changes from being applied to a managed device while a configuration is being edited or committed. These locks can prevent conflicts between local and Panorama configurations. Manual Unlocking: From Panorama, administrators can manually unlock a device if there are local configuration locks. This is useful when you need to override or clear these locks remotely
upvoted 2 times
...
Blender808
1 year, 3 months ago
Selected Answer: B
In the context of "panorama managed devices" i think a local configuration lock is a lock placed on a firewall config locally, by logging on to it, rather than logging on to panorama. If any lock placed by another administrator, in panorama or locally on a firewall. Would simply be unlocked by a commit done in panorama by any administrator, it's purpose would be defeated.
upvoted 2 times
...
mr_flubber
1 year, 7 months ago
Selected Answer: B
B is correct. Once lock from local PA, new policy cant be push from Pano
upvoted 1 times
...
Najmmm
2 years, 1 month ago
Selected Answer: B
B is correct. Once lock from local PA, new policy cant be push from Pano
upvoted 4 times
...
BC1c1c
2 years, 3 months ago
B is correct: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltACAS "When a user has a configuration lock, it is not possible to perform a commit or push a policy from Panorama. If the administrator is not available to remove the lock, a device WebGUI or CLI command can be used by a superuser to force the removal of the configuration lock." A is not correct. You can't perform a commit while a lock is in place, therefore, the lock can't be automatically removed after a commit that you cannot execute.
upvoted 2 times
...
z8d21oczd
2 years, 5 months ago
B is correct. If you trey to push a config to a device with a local local you get the following message: Details: . Other administrators are holding device wide config locks.
upvoted 1 times
...
mjw80013
2 years, 7 months ago
Selected Answer: B
local locks prevent panorama pushes. they have to be removed by the admin who locked it
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago