Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 254 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 254
Topic #: 1
[All PCNSE Questions]

An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy.
Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?

  • A. Preview Changes
  • B. Policy Optimizer
  • C. Managed Devices Health
  • D. Test Policy Match
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/test-policy-rule-traffic-matches.html

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
datz
Highly Voted 1 year, 11 months ago
Selected Answer: A
Common guys? "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" which tool is used to review policy creation and also can verify that Unwanted traffic is not allowed? how on earth Test Policy will tell you what unwanted trafffic will be allowed? :/ I am going for A :)
upvoted 5 times
Kris92
5 months, 3 weeks ago
"validate that policies that will be deployed" - preview change "Which tool can the administrator use to review the policy creation logic and verify that unwanted traffic is not allowed?" - test policy match
upvoted 6 times
...
Kris92
5 months, 3 weeks ago
pretty simple, you test policy with unwanted traffic and make sure it's denied how on earth is preview change going to help with that?
upvoted 3 times
...
...
Shastings1
Most Recent 1 week, 5 days ago
This is a poorly worded question, but the answer is D - test policy match. Goal here to use a tool to verify that you already have a “deny” rule . Test policy match check the current config for the unwanted traffic. There should be a deny or you need to add another rule. Test policy match source ( bad guy) destination (Crown Jewels) action = deny…..
upvoted 1 times
...
VenomX51
3 weeks, 4 days ago
Selected Answer: A
An administrator needs to validate that policies that will be deployed will match the appropriate rules in the device-group hierarchy. If you add a policy to device groups for firewall 2 and 3, you can use Preview changes to ensure that that policy is not going to be applied to FW1 and allow unwanted traffic. Preview Changes will verify your "policy creation logic" - i.e. If I create a policy in this device group it will not be applied to these firewalls.
upvoted 1 times
...
Thunnu
1 month, 1 week ago
Answer D https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/test-policy-rule-traffic-matches
upvoted 1 times
...
SH_
2 months, 4 weeks ago
Selected Answer: A
"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.
upvoted 1 times
...
SH_
2 months, 4 weeks ago
"policies that will be deployed" means candidate configuration. and test policy match works on running configuration. so I'm going with A, which I think should be the "preview rule" feature which is on Panorama.
upvoted 1 times
...
JRKhan
3 months, 3 weeks ago
Selected Answer: A
A is correct. Question is about policies that havent been deployed yet. Test policy match the policies that have already been deployed.
upvoted 1 times
...
Metgatz
3 months, 3 weeks ago
Selected Answer: D
Say check the logic Option D
upvoted 3 times
...
Adilon
4 months ago
D for me
upvoted 2 times
...
Whizdhum
4 months, 2 weeks ago
Selected Answer: A
Answer is A. Preview Changes asks the firewall to compare the configurations you selected in the Commit Scope to the running configuration. The answer is not Test Policy Match, which tests policy rules in your running configuration. Preview Changes is pre-commit, Test Policy Match is post-commit.
upvoted 2 times
...
dorf05
4 months, 3 weeks ago
Selected Answer: D
preview (before) commit and review ( after commit). and the question is " ..........administrator use to review the policy creation and verify that unwanted traffic is not allowed". this similar to question # 1
upvoted 2 times
...
Metgatz
4 months, 3 weeks ago
The correct option is D Test Policy Match
upvoted 2 times
...
scanossa
5 months, 1 week ago
Selected Answer: D
The question doesn´t say "preview", it says "review". It could involve rules already deployed, som answer D. Answer A doesn't show if a specific traffic is allowed or not
upvoted 1 times
...
RoamingFo
5 months, 1 week ago
Selected Answer: D
Preview will only show the changes, which is not enough to determine if traffic will be allowed or denied. This is a collective result of all the rules old and new. I think D is the most acceptable answer for this poorly worded question.
upvoted 1 times
...
Omid2022
6 months ago
Selected Answer: A
Test policy match works after commiting the config, so you belowed up the network then you want to check it!!!
upvoted 1 times
...
dgonz
8 months, 1 week ago
Selected Answer: D
it asks for "which tool" not sure if the preview pane can be considered as a tool... so I choose D, which is a tool
upvoted 1 times
...
mlj23
10 months, 2 weeks ago
Badly worded question. D is my answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...