nerdexam
Palo_Alto_Networks

PCNSA · Question #275

Which Security policy set should be used to ensure that a policy is applied first?

The correct answer is B. Shared pre-rulebase. The Shared pre-rulebase ensures that policies are applied first because it is processed before any other rulebases (device-group or local) on the firewall.

Submitted by kavita_s· Apr 18, 2026Policy Evaluation and Management

Question

Which Security policy set should be used to ensure that a policy is applied first?

Options

  • ALocal firewall policy
  • BShared pre-rulebase
  • CParent device-group pre-rulebase
  • DChild device-group pre-rulebase

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    93% (52)
  • C
    4% (2)
  • D
    2% (1)

Why each option

The Shared pre-rulebase ensures that policies are applied first because it is processed before any other rulebases (device-group or local) on the firewall.

ALocal firewall policy

Local firewall policies are processed last, after Shared and Device Group policies, so they would not be applied first.

BShared pre-rulebaseCorrect

The Shared pre-rulebase is processed first among all policy types (Shared, Device Group, Local), ensuring that rules defined within it take precedence and are applied before any other policies.

CParent device-group pre-rulebase

Parent device-group pre-rulebase policies are processed after the Shared pre-rulebase, but before child device-group or local policies, meaning they are not applied first overall.

DChild device-group pre-rulebase

Child device-group pre-rulebase policies are processed after Shared and parent device-group policies, meaning they are not applied first.

Concept tested: Security policy rulebase hierarchy

Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/security-policy-rule-precedence

Topics

#Policy Order#Panorama#Rulebase Hierarchy#Policy Management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice