exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 418 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 418
Topic #: 1
[All PCNSE Questions]



Based on the screenshots above, and with no configuration inside the Template Stack itself, what access will the device permit on its Management port?

  • A. The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1.
  • B. The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-2.
  • C. The firewall will allow HTTP, Telnet, SNMP, HTTPS, SSH and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.
  • D. The firewall will allow HTTP, Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
procheeseburger
Highly Voted 1 year, 6 months ago
Selected Answer: A
I just tested in my panorama by making the same thing and when you have a permitted IP in both templates it only pushes config from the top one. Making A the only possible answer.
upvoted 13 times
...
chrisy042
Highly Voted 2 years, 1 month ago
Selected Answer: C
The Panorama will push values from both templates, if any conflict is present it will take the value from the top template.
upvoted 9 times
procheeseburger
1 year, 6 months ago
Your answer contradicts your comment.. There are 3 conflicts meaning it can't be C (based on your own comment)
upvoted 5 times
...
...
corpguy
Most Recent 2 months ago
Selected Answer: C
The template stack levels are additive and only when there is a match i the setting overwritten with the value in the higher template.
upvoted 1 times
...
NSO_Blue
2 months, 2 weeks ago
All the four answers are not correct. The http field stays in conflict between both templates. Therefore the value from the top template takes place. And here is the box not ticked!
upvoted 4 times
...
findkeywordcommand
10 months ago
Selected Answer: A
I tested this in lab, A is correct. In the 3rd screenshot you can see that DEVICE_TEMP has higher priority. This is why the $permitted-subnet-1 takes precendence and also the configured SNMP checkbox in REGIONAL_TEMP won't take effect because of this. The info text in Panorama GUI for Template Stacks is: The Template at the top of the Stack has the highest priority in the presence of overlapping config
upvoted 1 times
...
Marshpillowz
11 months, 2 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
Kaifus
12 months ago
On the 1/23/24 exam
upvoted 3 times
...
Orcun1905
1 year ago
this was one of the questions of todays exam
upvoted 2 times
...
Metgatz
1 year ago
Selected Answer: A
A Permitted IP addresses do not merge
upvoted 1 times
...
franko_72
1 year, 1 month ago
OK, here is old Frankies take: The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1 and since Permitted IP Addresses is a duplicate, it will prefererence the higher template. Now it will also allow SNMP as it's in the lower template but, for this example, SNMP is still only applied to $permitted-subnet-1 rendering the other answers useless, so it's A. Bottom line is Permitted IP Addresses is duplicate, as are most of the other (http, https, ssh, ping) but Telnet and SNMP are unique in each template but will still only apply to $permitted-subnet-1.
upvoted 6 times
...
Betty2022
1 year, 5 months ago
Selected Answer: A
A, as per procheeseburger, i tested this as well in my lab.
upvoted 3 times
...
sujss
1 year, 8 months ago
Selected Answer: A
https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-force-template-value-option/td-p/496620 "- Force Template Value will as the name suggest remove any local configuratio and apply the value define the panorama template. But this is valid only for overlapping configuration" "You need to be careful, what is actually defined in the template. For example - if you decide to enable HA in the template, but after that you decide to not push it with template and just disable it again (remove the check from the "Enable HA" checkbox). This still will be part of the template, because now your template is explicitely defining HA disabled. If you made a change in the template, and later decide that you don't want to control this setting with template, you need to revert the config by clicking the green bar next to the changed value"
upvoted 4 times
...
jhoncena
1 year, 9 months ago
Selected Answer: A
100%A IPs will never be merged and also SNMP already disabled by the first template ...
upvoted 5 times
...
Bilou18
1 year, 9 months ago
Selected Answer: A
The question said and "no configuration inside the Template Stack itself" I would say A
upvoted 2 times
...
Klash
1 year, 9 months ago
Selected Answer: D
Green bar next to value means value is explicitly specified. As higher template takes priority, the SNMP setting will be taken from device-template which has snmp explicitly disabled.
upvoted 2 times
Klash
1 year, 9 months ago
Apologies. This actually gives an answer of A, as permitted IP addresses do not merge. (tested on 10.1)
upvoted 4 times
...
...
kewokil120
1 year, 10 months ago
Selected Answer: C
c is for cookie
upvoted 2 times
...
Marbot
1 year, 10 months ago
Selected Answer: D
Device_Temp is higher in priority so SNMP will be disabled and permitted IP address will be combined. Reference: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-templates-and-template-stacks/configure-a-template-stack
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago