exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 308 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 308
Topic #: 1
[All PCNSE Questions]

An administrator needs to evaluate a recent policy change that was committed and pushed to a firewall device group. How should the administrator identify the configuration changes?

  • A. review the configuration logs on the Monitor tab
  • B. use Test Policy Match to review the policies in Panorama
  • C. context-switch to the affected firewall and use the configuration audit tool
  • D. click Preview Changes under Push Scope
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
af67d32
2 weeks, 1 day ago
Selected Answer: C
A and C are both valid answers, however, Configuration log shows any configuration change to the candidate, even not commited. I tested that with my lab While config audit shows every change by Commit, with discrepancies between the 2 versions. As the question here is to track back a COMMITTED change, only C applies
upvoted 1 times
...
mustfaozturknetworks
1 month, 1 week ago
Selected Answer: C
Context-switching to the firewall ensures the administrator is reviewing the exact device impacted by the policy change.
upvoted 1 times
...
Cyril_the_Squirl
1 month, 3 weeks ago
Selected Answer: C
Context-switching to the firewall ensures the administrator is reviewing the exact device impacted by the policy change. C is correct
upvoted 1 times
...
ThirdLevel
8 months, 3 weeks ago
A 100% verified
upvoted 1 times
...
scanossa
11 months, 3 weeks ago
Selected Answer: A
If it were several config changes, i would go for C but in this case it´s "policy change", meaning only 1 config change. Its' easier to check it on configuration logs
upvoted 1 times
...
Adilon
1 year ago
C : beacause preview change is available when you want to perform a commit and push. ( pre-view of your config )audit log can bring you the exact details of all detailed push and configuration performed by any others authorized users.
upvoted 1 times
...
JRKhan
1 year ago
Selected Answer: B
B is most appropriate as it provides evaluation of rules within the rule base. Since, the configuration has been pushed to the firewalls, the test policy function can be used. Preview changes or switching to firewall context and using config audit tool just compare the configurations.
upvoted 1 times
...
babujiju
1 year ago
Selected Answer: C
Config Audit. Option C
upvoted 1 times
...
Sammy3637
1 year, 1 month ago
Selected Answer: C
Going with option C
upvoted 1 times
...
Mocix
1 year, 1 month ago
C for sure! From Panorama you need to switch to the firewall you want, and then you can use the config audit tool to check the current config with the previous one.
upvoted 1 times
...
Kris92
1 year, 2 months ago
change that was committed and pushed to a firewall device group - this means change was pushed from panorama, you will not find the panorama change in config audit if you are connected to the firewall, so C will not work
upvoted 1 times
...
playthegamewithme
1 year, 7 months ago
The config changes under the Monitor tab, only show you if the state of the commit, it doesn't show you the config change The audit tool shows you what has changed in the configuration as you can select 2 dates of the configuration and then compare, what has changed. Just checked now in Panorama. D its only relevant if the commit was not performed and B its out of the question I believe that the most appropriate answer is C here, as you can compare an old configuration with the most recent one to check what is different.
upvoted 4 times
...
mohr22
2 years ago
A : There is option for before and after change .
upvoted 2 times
...
Sarbi
2 years, 1 month ago
A is 100 % right
upvoted 3 times
...
confusion
2 years, 3 months ago
A (given how the question is worded). Misleading one IMO, admin needs to "evaluate recent policy change", then question asks for "identify the config change". evaluate = "Test policy match", nothing else would provide you better way to evaluate, so B mostly fits on this requirement identify = "Configuration log", as there you get an entry of every (recent and not only) change, so A mostly fits on this requirement finally to see exactly what the change in the config was, you can do the "configuration audit tool", so C would mostly fits here if they were asking for
upvoted 1 times
...
west33637
2 years, 3 months ago
Selected Answer: A
I would go with A. The config audit tool shows the diff between the running config and the candidate config (saved config not yet committed). The question says that the config has already been committed, which means the running config and candidate config will be the same. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEaCAK
upvoted 4 times
...
Gabuu
2 years, 3 months ago
Selected Answer: A
Configuration log Displays an entry for each configuration change. Each entry includes the date and time, the administrator username, the IP address from where the change was made, the type of client (web interface or CLI), the type of command executed, whether the command succeeded or failed, the configuration path, and the values before and after the change. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/monitor/monitor-logs/log-types
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...