exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 308 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 308
Topic #: 1
[All PCNSE Questions]

An administrator needs to evaluate a recent policy change that was committed and pushed to a firewall device group. How should the administrator identify the configuration changes?

  • A. review the configuration logs on the Monitor tab
  • B. use Test Policy Match to review the policies in Panorama
  • C. context-switch to the affected firewall and use the configuration audit tool
  • D. click Preview Changes under Push Scope
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ThirdLevel
2 months ago
A 100% verified
upvoted 1 times
...
scanossa
5 months ago
Selected Answer: A
If it were several config changes, i would go for C but in this case it´s "policy change", meaning only 1 config change. Its' easier to check it on configuration logs
upvoted 1 times
...
Adilon
6 months ago
C : beacause preview change is available when you want to perform a commit and push. ( pre-view of your config )audit log can bring you the exact details of all detailed push and configuration performed by any others authorized users.
upvoted 1 times
...
JRKhan
6 months, 1 week ago
Selected Answer: B
B is most appropriate as it provides evaluation of rules within the rule base. Since, the configuration has been pushed to the firewalls, the test policy function can be used. Preview changes or switching to firewall context and using config audit tool just compare the configurations.
upvoted 1 times
...
babujiju
6 months, 1 week ago
Selected Answer: C
Config Audit. Option C
upvoted 1 times
...
Sammy3637
7 months ago
Selected Answer: C
Going with option C
upvoted 1 times
...
Mocix
7 months, 1 week ago
C for sure! From Panorama you need to switch to the firewall you want, and then you can use the config audit tool to check the current config with the previous one.
upvoted 1 times
...
Kris92
8 months, 1 week ago
change that was committed and pushed to a firewall device group - this means change was pushed from panorama, you will not find the panorama change in config audit if you are connected to the firewall, so C will not work
upvoted 1 times
...
playthegamewithme
1 year, 1 month ago
The config changes under the Monitor tab, only show you if the state of the commit, it doesn't show you the config change The audit tool shows you what has changed in the configuration as you can select 2 dates of the configuration and then compare, what has changed. Just checked now in Panorama. D its only relevant if the commit was not performed and B its out of the question I believe that the most appropriate answer is C here, as you can compare an old configuration with the most recent one to check what is different.
upvoted 4 times
...
mohr22
1 year, 5 months ago
A : There is option for before and after change .
upvoted 2 times
...
Sarbi
1 year, 6 months ago
A is 100 % right
upvoted 3 times
...
confusion
1 year, 8 months ago
A (given how the question is worded). Misleading one IMO, admin needs to "evaluate recent policy change", then question asks for "identify the config change". evaluate = "Test policy match", nothing else would provide you better way to evaluate, so B mostly fits on this requirement identify = "Configuration log", as there you get an entry of every (recent and not only) change, so A mostly fits on this requirement finally to see exactly what the change in the config was, you can do the "configuration audit tool", so C would mostly fits here if they were asking for
upvoted 1 times
...
west33637
1 year, 9 months ago
Selected Answer: A
I would go with A. The config audit tool shows the diff between the running config and the candidate config (saved config not yet committed). The question says that the config has already been committed, which means the running config and candidate config will be the same. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEaCAK
upvoted 4 times
...
Gabuu
1 year, 9 months ago
Selected Answer: A
Configuration log Displays an entry for each configuration change. Each entry includes the date and time, the administrator username, the IP address from where the change was made, the type of client (web interface or CLI), the type of command executed, whether the command succeeded or failed, the configuration path, and the values before and after the change. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/monitor/monitor-logs/log-types
upvoted 2 times
...
datz
1 year, 9 months ago
Selected Answer: A
A for sure you can check config changes directly on Pano, using Monitor Tab and configuration and can filter out using user/device etc....
upvoted 2 times
...
bimyo
1 year, 9 months ago
C I would pick C here as the question asks to "evaluate" the resent config changes and the conf audit tool on the fw gives us the best overview of the changes that were committed. A is more log entry that config changes were made, but does not give you the config changes that could be hundreds of lines(not 100% sure here), but C is talking about exactly the tool that is specially developed to evaluate config changes. Correct me if I have something wrong here.
upvoted 2 times
Kalipso21
1 year, 5 months ago
In the config audit tool from the firewall itself, you won't be able to see the changes pushed by the panorama. Only local changes can be seen there. So, C is not the correct answer.
upvoted 1 times
...
...
secdaddy
1 year, 9 months ago
A seems reasonable https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/monitor/monitor-logs/log-types#ide5162f14-a43b-4105-97eb-fae3d0c9e01a
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago