PCNSA · Question #275
Which Security policy set should be used to ensure that a policy is applied first?
The correct answer is B. Shared pre-rulebase. The Shared pre-rulebase ensures that policies are applied first because it is processed before any other rulebases (device-group or local) on the firewall.
Question
Which Security policy set should be used to ensure that a policy is applied first?
Options
- ALocal firewall policy
- BShared pre-rulebase
- CParent device-group pre-rulebase
- DChild device-group pre-rulebase
How the community answered
(56 responses)- A2% (1)
- B93% (52)
- C4% (2)
- D2% (1)
Why each option
The Shared pre-rulebase ensures that policies are applied first because it is processed before any other rulebases (device-group or local) on the firewall.
Local firewall policies are processed last, after Shared and Device Group policies, so they would not be applied first.
The Shared pre-rulebase is processed first among all policy types (Shared, Device Group, Local), ensuring that rules defined within it take precedence and are applied before any other policies.
Parent device-group pre-rulebase policies are processed after the Shared pre-rulebase, but before child device-group or local policies, meaning they are not applied first overall.
Child device-group pre-rulebase policies are processed after Shared and parent device-group policies, meaning they are not applied first.
Concept tested: Security policy rulebase hierarchy
Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/security-policy-rule-precedence
Topics
Community Discussion
No community discussion yet for this question.