nerdexam
Palo_Alto_Networks

PCNSA · Question #283

The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should be able to…

The correct answer is A. Administrator Type = Device Group and Template Admin. To create an administrator profile with read-only access limited to specific device groups and templates, the 'Device Group and Template Admin' type should be selected, allowing for granular privilege assignment.

Submitted by ashley.k· Apr 18, 2026Manage

Question

The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should be able to:

  • Access only EMEA-Regional device groups with read-only privileges
  • Access only EMEA-Regional templates with read-only privileges

What is the correct configuration for the new EMEA Regional Panorama Administrator profile?

Options

  • AAdministrator Type = Device Group and Template Admin
  • BAdministrator Type = Dynamic -
  • CAdministrator Type = Dynamic -
  • DAdministrator Type = Custom Panorama Admin

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    3% (1)
  • C
    14% (4)
  • D
    7% (2)

Why each option

To create an administrator profile with read-only access limited to specific device groups and templates, the 'Device Group and Template Admin' type should be selected, allowing for granular privilege assignment.

AAdministrator Type = Device Group and Template AdminCorrect

The 'Device Group and Template Admin' type is specifically designed for Panorama to create administrator roles that can be scoped to specific device groups and templates with defined read-only or read-write permissions, directly matching the requirement for regional read-only access to EMEA resources.

BAdministrator Type = Dynamic -

'Dynamic' is not a standard, complete Administrator Type in Panorama for this purpose; it's likely a placeholder or incomplete option.

CAdministrator Type = Dynamic -

'Dynamic' is not a standard, complete Administrator Type in Panorama for this purpose; it's likely a placeholder or incomplete option.

DAdministrator Type = Custom Panorama Admin

A 'Custom Panorama Admin' allows for fine-grained control over various Panorama functions, but 'Device Group and Template Admin' is a more direct and appropriate type when the primary scope is limited access to specific device groups and templates.

Concept tested: Panorama administrator roles and access control

Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/manage-administrator-accounts/configure-an-administrator-account#id7071f11e-28c1-46bb-9ee8-16447c211119

Topics

#Panorama Administration#Administrator Profiles#Role-Based Access Control (RBAC)#Device Groups#Templates

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice