nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #12

Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?

The correct answer is B. Local firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules. Panorama uses a three-tier policy hierarchy to give central administrators control while still allowing local firewall administrators flexibility. The evaluation order is: (1) Panorama pre-rules - pushed from Panorama and evaluated first; these are typically used to enforce…

Centralized Management

Question

Which statement applies to the relationship between Panorama-pushed Security policy and local firewall Security policy?

Options

  • AWhen a policy match is found in a local firewall policy, if any Panorama shared post-rule is
  • BLocal firewall rules are evaluated after Panorama pre-rules and before Panorama post-rules.
  • CPanorama post-rules can be configured to be evaluated before local firewall policy for the
  • DThe order of policy evaluation can be configured differently in different device groups.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    88% (28)
  • C
    9% (3)

Explanation

Panorama uses a three-tier policy hierarchy to give central administrators control while still allowing local firewall administrators flexibility. The evaluation order is: (1) Panorama pre-rules - pushed from Panorama and evaluated first; these are typically used to enforce mandatory organizational policies that cannot be overridden locally. (2) Local firewall rules - defined directly on the firewall; evaluated second, allowing local admins to add site-specific rules. (3) Panorama post-rules - pushed from Panorama and evaluated last; typically used for catch-all or default deny rules. This sandwich model (pre > local > post) means Panorama can enforce top-priority rules and default rules while local admins manage what's in between. Options A, C, and D describe behaviors that do not exist: Panorama shared post-rules don't continue evaluating after a local match, post-rules cannot be moved before local rules, and the evaluation order is fixed within a device group - it cannot be reconfigured differently.

Topics

#Panorama#Security Policy#Policy Evaluation Order

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice