exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 181 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 181
Topic #: 1
[All PCNSE Questions]

The following objects and policies are defined in a device group hierarchy.

Dallas-Branch has Dallas-FW as a member of the Dallas-Branch device-group
NYC-DC has NYC-FW as a member of the NYC-DC device-group
What objects and policies will the Dallas-FW receive if "Share Unused Address and Service Objects" is enabled in Panorama?

  • A. Address Objects -Shared Address1 -Branch Address1 Policies -Shared Policy1 -Branch Policy1
  • B. Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1
  • C. Address Objects -Shared Address1 -Shared Address2 -Branch Address1 -DC Address1 Policies -Shared Policy1 -Shared Policy2 -Branch Policy1
  • D. Address Objects -Shared Address1 -Shared Address2 -Branch Address1 Policies -Shared Policy1 -Branch Policy1
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
homersimpson
Highly Voted 2 years, 10 months ago
Selected Answer: D
Panorama will not push anything from Data-Centers group. That rules out C. Panorama will push all objects from "Shared", which rules out A. Note that the target of "Shared Policy 2" is NYC-FW, so this policy won't get pushed to Dallas-FW. This rules out B. Thus, answer is D.
upvoted 11 times
...
Micutzu
Highly Voted 2 years, 10 months ago
D is correct.
upvoted 5 times
Bighize
2 years, 10 months ago
I agree with Micutzu. I built this out in my lab. Dallas will not recieve anything from the DataCenter Group. Only from the the shared and the Branch group. D is Correct.
upvoted 1 times
...
...
scanossa
Most Recent 9 months ago
Selected Answer: D
Question askes about Dallas-FW, so every answer with "Shared Policy2" is discarded since it is related to NYC-FW A is discarded because it does not have both address objects D is the correct answer
upvoted 1 times
...
Marshpillowz
9 months, 1 week ago
Selected Answer: D
D is correct
upvoted 1 times
...
ansibai
10 months, 1 week ago
Selected Answer: D
When you push configuration changes Device Groups, by default Panorama pushes all shared objects to firewalls whether or not any shared or device group policy rules reference the objects. However, you can configure Panorama to push only the shared objects that rules reference in the device groups. The Share Unused Address and Service Objects with Devices option enables you to limit the objects that Panorama pushes to the managed firewalls. If "Share Unused Address and Service Objects with Device" is disabled/unchecked, Panorama evaluates unused objects while pushing configuration to the device. However this feature ignores the "target device" in security rules while evaluating unused objects.
upvoted 1 times
...
ansibai
10 months, 1 week ago
Selected Answer: D
When you push configuration changes Device Groups, by default Panorama pushes all shared objects to firewalls whether or not any shared or device group policy rules reference the objects. However, you can configure Panorama to push only the shared objects that rules reference in the device groups. The Share Unused Address and Service Objects with Devices option enables you to limit the objects that Panorama pushes to the managed firewalls. If "Share Unused Address and Service Objects with Device" is disabled/unchecked, Panorama evaluates unused objects while pushing configuration to the device. However this feature ignores the "target device" in security rules while evaluating unused objects.
upvoted 1 times
...
DatITGuyTho1337
10 months, 2 weeks ago
Answer is "D" but I had to re-read the meaning of the "share unused address and service objects with devices" phrase because it is entirely COUNTER PRODUCTIVE to what it actually does. By default Panorama will share ALL objects whether or not they are used by members of the device group. Ticking the option above DISABLES that function forcing Panorama to only send objects that are used by the members of service groups. I swear a lot of PAN articles need proper grammar checks as they confuse learners. Even the aforementioned phrase should be changed to something like: "DISABLE sharing unused address and service objects with devices" See how much more clear that option now is? I think I will contact PAN customer support to factor this change. PAN tech is complicated enough, we don't need overly complicated grammar to make it even worse to understand!!!!!
upvoted 1 times
...
DenskyDen
1 year, 9 months ago
Selected Answer: D
D. Because everything will be shared except for the shared policy 2, because it is targeting to share only with NYC-FW.
upvoted 1 times
...
Pretorian
2 years, 2 months ago
There's no "Branch Policy1" by the way...
upvoted 2 times
...
secdaddy
2 years, 3 months ago
None of the above as the shared policy 1 has a typo in the target fw name (yes I know none of the above isn't an option)
upvoted 1 times
...
UFanat
2 years, 4 months ago
Selected Answer: D
"Shared Policy 2" has set Target Device as NYC-FW, so Dallas-FW will never get it. (so B and C are not applicable) Dallas-FW should also get both Shared Addresses 1 and 2 (So A is not applicable)
upvoted 1 times
...
AbuHussain
2 years, 7 months ago
Selected Answer: D
D is correct.
upvoted 1 times
...
confusion
2 years, 7 months ago
Selected Answer: D
Definitely D
upvoted 1 times
...
GivemeMoney
2 years, 9 months ago
Selected Answer: D
Hard to freaking read, but yes answer is really D.
upvoted 2 times
...
anil4924
2 years, 10 months ago
A is correct..
upvoted 1 times
...
Bighize
2 years, 10 months ago
D is correct. I agree with Micutzu. I built this out in my lab. Dallas will not recieve anything from the DataCenter Group. Only from the the shared and the Branch group. D is Correct.
upvoted 1 times
...
Plato22
2 years, 10 months ago
C is correct. It will receive everything under the Share.
upvoted 2 times
homersimpson
2 years, 10 months ago
No, it will not receive Shared Policy 2 because that policy has a specific target of NYC.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago