TechNuggets Academy

Deploy and Configure Firewalls Using Panorama

Free Palo Alto Networks Certified Network Security Engineer practice — 6 questions on Deploy and Configure Firewalls Using Panorama, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
A Panorama template stack named Stack-Branch contains three templates in this order (top to bottom): Template_A, Template_B, Template_C. All three templates configure a different MTU value on the same subinterface. When the stack is pushed to a managed firewall, which template's MTU value is applied to the firewall?
Within a template stack, templates are evaluated top to bottom, and the template highest in the list order takes precedence for any overlapping configuration setting. Template_A sits at the top of Stack-Branch, so its MTU value wins.
Question 2 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
An administrator creates an address object named WebServer under Shared with value 10.1.1.10. The same name, WebServer, is also defined inside device group DG-DataCenter with value 10.2.2.20. A firewall assigned to DG-DataCenter already has a locally configured address object named WebServer with value 192.168.1.5 that was never managed by Panorama. After the administrator commits to Panorama and pushes to the device group, what happens to the WebServer object on that firewall?
Objects defined in a device group take precedence over objects with the same name defined in Shared. When Panorama pushes configuration, it overwrites any existing object of the same name on the target firewall, including a previously local, unmanaged object, replacing it with the pushed device group value.
Question 3 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
An administrator is configuring a Collector Group with three Dedicated Log Collectors and wants to enable log redundancy so that no logs are lost if a single Log Collector goes offline. What is the minimum number of Log Collectors required in the Collector Group to enable the log redundancy option?
The Enable Log Redundancy Across Collectors option in a Collector Group requires a minimum of two Log Collectors. With redundancy enabled, each log is forwarded to two Log Collectors in the group so that a single collector failure does not cause log loss.
Question 4 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
An administrator clicks Commit in Panorama and selects Commit to Panorama. The commit job reports Commit succeeded. Several minutes later, the managed firewalls in device group DG-Branch are still enforcing the old policy. What should the administrator do to apply the new configuration to the firewalls?
Commit to Panorama only saves the candidate configuration to Panorama's own running configuration; it does not send anything to managed firewalls. A distinct Push to Devices operation, targeting the relevant device groups and templates, is required to deliver the configuration to the firewalls.
Question 5 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
A managed security team is building one template to standardize the configuration of 40 branch firewalls, but each firewall needs a unique IP address assigned to interface ethernet1/1, which differs per site. Which approach lets the team use a single shared template while still assigning a unique interface IP address to each firewall?
Template variables (prefixed with $) let an administrator define a placeholder value, such as an interface IP address, once in the shared template. Each firewall's entry in the template stack Variables tab can then override that placeholder with a device-specific value, enabling one template to serve many firewalls with unique settings.
Question 6 of 6 · Domain 4: Deploy and Configure Firewalls Using Panorama
Device group DG-DataCenter has a pre-rulebase security rule that permits traffic between two internal subnets. Traffic matching this rule is unexpectedly being denied. Investigation reveals a Shared pre-rule in Panorama with a broader match and a deny action. Which statement correctly explains the rule evaluation order that produces this behavior?
The rule evaluation order in a Panorama-managed hierarchy is: Shared pre-rules, then device group pre-rules (ancestor to descendant), then local firewall pre-rules, then local firewall rules, then local post-rules, device group post-rules, and finally Shared post-rules. Because Shared pre-rules are evaluated first, the broader Shared deny rule matches the traffic before the DG-DataCenter pre-rule is ever reached.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →