PCNSA · Question #283
The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should be able to…
The correct answer is A. Administrator Type = Device Group and Template Admin. To create an administrator profile with read-only access limited to specific device groups and templates, the 'Device Group and Template Admin' type should be selected, allowing for granular privilege assignment.
Question
The NetSec Manager asked to create a new EMEA Regional Panorama Administrator profile with customized privileges. In particular, the new EMEA Regional Panorama Administrator should be able to:
- Access only EMEA-Regional device groups with read-only privileges
- Access only EMEA-Regional templates with read-only privileges
What is the correct configuration for the new EMEA Regional Panorama Administrator profile?
Options
- AAdministrator Type = Device Group and Template Admin
- BAdministrator Type = Dynamic -
- CAdministrator Type = Dynamic -
- DAdministrator Type = Custom Panorama Admin
How the community answered
(29 responses)- A76% (22)
- B3% (1)
- C14% (4)
- D7% (2)
Why each option
To create an administrator profile with read-only access limited to specific device groups and templates, the 'Device Group and Template Admin' type should be selected, allowing for granular privilege assignment.
The 'Device Group and Template Admin' type is specifically designed for Panorama to create administrator roles that can be scoped to specific device groups and templates with defined read-only or read-write permissions, directly matching the requirement for regional read-only access to EMEA resources.
'Dynamic' is not a standard, complete Administrator Type in Panorama for this purpose; it's likely a placeholder or incomplete option.
'Dynamic' is not a standard, complete Administrator Type in Panorama for this purpose; it's likely a placeholder or incomplete option.
A 'Custom Panorama Admin' allows for fine-grained control over various Panorama functions, but 'Device Group and Template Admin' is a more direct and appropriate type when the primary scope is limited access to specific device groups and templates.
Concept tested: Panorama administrator roles and access control
Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/manage-administrator-accounts/configure-an-administrator-account#id7071f11e-28c1-46bb-9ee8-16447c211119
Topics
Community Discussion
No community discussion yet for this question.