nerdexam
Palo_Alto_Networks

PCNSA · Question #162

Which statement is true about Panorama managed devices?

The correct answer is B. Local configuration locks prohibit Security policy changes for a Panorama managed device. When a user has a configuration lock, it is not possible to perform a commit or push a policy from Panorama. If the administrator is not available to remove the lock, a device WebGUI or CLI command can be used by a superuser to force the removal of the configuration lock…

Submitted by cyberguy42· Apr 18, 2026Device Management and Services

Question

Which statement is true about Panorama managed devices?

Options

  • APanorama automatically removes local configuration locks after a commit from Panorama.
  • BLocal configuration locks prohibit Security policy changes for a Panorama managed device.
  • CSecurity policy rules configured on local firewalls always take precedence.
  • DLocal configuration locks can be manually unlocked from Panorama.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    89% (33)
  • C
    5% (2)
  • D
    3% (1)

Explanation

When a user has a configuration lock, it is not possible to perform a commit or push a policy from Panorama. If the administrator is not available to remove the lock, a device WebGUI or CLI command can be used by a superuser to force the removal of the configuration lock. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltACAS

Topics

#Panorama#Centralized Management#Configuration Locks#Device Management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice