nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #34

What is the purpose of assigning an Admin Role Profile to a user in a Palo Alto Networks NGFW?

The correct answer is C. Define granular permissions for management tasks. An Admin Role Profile in PAN-OS implements role-based access control (RBAC) for firewall administrators. It defines exactly which management functions, configuration areas, CLI commands, and reports a given administrator is permitted to access or modify. For example, a…

Management Plane Access Control

Question

What is the purpose of assigning an Admin Role Profile to a user in a Palo Alto Networks NGFW?

Options

  • AAllow access to all resources without restrictions.
  • BEnable multi-factor authentication (MFA) for administrator access.
  • CDefine granular permissions for management tasks.
  • DRestrict access to sensitive report data.

How the community answered

(41 responses)
  • B
    2% (1)
  • C
    93% (38)
  • D
    5% (2)

Explanation

An Admin Role Profile in PAN-OS implements role-based access control (RBAC) for firewall administrators. It defines exactly which management functions, configuration areas, CLI commands, and reports a given administrator is permitted to access or modify. For example, a help-desk role profile might allow viewing logs but not changing security policy, while a network-ops role might allow interface configuration but not user-ID or certificate management. This granular permission model is the primary purpose of Admin Role Profiles. Answer A (unrestricted access) describes a superuser account, not a custom role profile. Answer B (MFA) is an authentication setting, not a role definition. Answer D is too narrow - Admin Role Profiles control all management tasks, not only report access.

Topics

#Admin Roles#RBAC#User Management#Permissions

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice