Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 418 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 418
Topic #: 1
[All PCNSE Questions]



Based on the screenshots above, and with no configuration inside the Template Stack itself, what access will the device permit on its Management port?

  • A. The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1.
  • B. The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-2.
  • C. The firewall will allow HTTP, Telnet, SNMP, HTTPS, SSH and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.
  • D. The firewall will allow HTTP, Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1 and $permitted-subnet-2.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
procheeseburger
Highly Voted 9 months, 2 weeks ago
Selected Answer: A
I just tested in my panorama by making the same thing and when you have a permitted IP in both templates it only pushes config from the top one. Making A the only possible answer.
upvoted 9 times
...
chrisy042
Highly Voted 1 year, 4 months ago
Selected Answer: C
The Panorama will push values from both templates, if any conflict is present it will take the value from the top template.
upvoted 7 times
procheeseburger
9 months, 2 weeks ago
Your answer contradicts your comment.. There are 3 conflicts meaning it can't be C (based on your own comment)
upvoted 3 times
...
...
findkeywordcommand
Most Recent 3 weeks, 5 days ago
Selected Answer: A
I tested this in lab, A is correct. In the 3rd screenshot you can see that DEVICE_TEMP has higher priority. This is why the $permitted-subnet-1 takes precendence and also the configured SNMP checkbox in REGIONAL_TEMP won't take effect because of this. The info text in Panorama GUI for Template Stacks is: The Template at the top of the Stack has the highest priority in the presence of overlapping config
upvoted 1 times
...
Marshpillowz
2 months, 2 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
Kaifus
2 months, 3 weeks ago
On the 1/23/24 exam
upvoted 2 times
...
Orcun1905
3 months, 3 weeks ago
this was one of the questions of todays exam
upvoted 2 times
...
Metgatz
4 months ago
Selected Answer: A
A Permitted IP addresses do not merge
upvoted 1 times
...
franko_72
4 months ago
OK, here is old Frankies take: The firewall will allow HTTP Telnet, HTTPS, SSH, and Ping from IP addresses defined as $permitted-subnet-1 and since Permitted IP Addresses is a duplicate, it will prefererence the higher template. Now it will also allow SNMP as it's in the lower template but, for this example, SNMP is still only applied to $permitted-subnet-1 rendering the other answers useless, so it's A. Bottom line is Permitted IP Addresses is duplicate, as are most of the other (http, https, ssh, ping) but Telnet and SNMP are unique in each template but will still only apply to $permitted-subnet-1.
upvoted 5 times
...
Betty2022
8 months, 2 weeks ago
Selected Answer: A
A, as per procheeseburger, i tested this as well in my lab.
upvoted 3 times
...
sujss
11 months, 4 weeks ago
Selected Answer: A
https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-force-template-value-option/td-p/496620 "- Force Template Value will as the name suggest remove any local configuratio and apply the value define the panorama template. But this is valid only for overlapping configuration" "You need to be careful, what is actually defined in the template. For example - if you decide to enable HA in the template, but after that you decide to not push it with template and just disable it again (remove the check from the "Enable HA" checkbox). This still will be part of the template, because now your template is explicitely defining HA disabled. If you made a change in the template, and later decide that you don't want to control this setting with template, you need to revert the config by clicking the green bar next to the changed value"
upvoted 4 times
...
jhoncena
1 year ago
Selected Answer: A
100%A IPs will never be merged and also SNMP already disabled by the first template ...
upvoted 5 times
...
Bilou18
1 year ago
Selected Answer: A
The question said and "no configuration inside the Template Stack itself" I would say A
upvoted 2 times
...
Klash
1 year ago
Selected Answer: D
Green bar next to value means value is explicitly specified. As higher template takes priority, the SNMP setting will be taken from device-template which has snmp explicitly disabled.
upvoted 2 times
Klash
1 year ago
Apologies. This actually gives an answer of A, as permitted IP addresses do not merge. (tested on 10.1)
upvoted 4 times
...
...
kewokil120
1 year ago
Selected Answer: C
c is for cookie
upvoted 2 times
...
Marbot
1 year, 1 month ago
Selected Answer: D
Device_Temp is higher in priority so SNMP will be disabled and permitted IP address will be combined. Reference: https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-templates-and-template-stacks/configure-a-template-stack
upvoted 2 times
...
mz101
1 year, 4 months ago
Just did a lab and found that services pushed from both templates, while the permitted subnets only pushed from the top template. So, if my lab is valid/correct, the answer should be: 1. If based on the services, C should be correct (if subnet2 is removed) 2. If based on the permitted subnets, A is correct (if snmp is added)
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...