nerdexam
Palo_Alto_Networks

PCNSA · Question #388

Which two statements correctly describe how pre-rules and local device rules are viewed and modified? (Choose two.)

The correct answer is C. Pre-rules can be viewed on managed firewalls. D. Pre-rules are modified in Panorama only, and local device rules are modified on local firewalls. Pre-rules are centrally managed and modified exclusively through Panorama but are visible on the managed firewalls; in contrast, local device rules are configured and modified directly on the individual firewalls. This separation ensures centralized control for global policies…

Submitted by fatema_kw· Apr 18, 2026Policy Evaluation and Management

Question

Which two statements correctly describe how pre-rules and local device rules are viewed and modified? (Choose two.)

Options

  • APre-rules can be modified by the local administrator or by a Panorama administrator who has
  • BPre-rules and local device rules can be modified in Panorama.
  • CPre-rules can be viewed on managed firewalls.
  • DPre-rules are modified in Panorama only, and local device rules are modified on local firewalls

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    88% (29)

Why each option

Pre-rules are centrally managed and modified exclusively through Panorama but are visible on the managed firewalls; in contrast, local device rules are configured and modified directly on the individual firewalls. This separation ensures centralized control for global policies and local flexibility for device-specific needs.

APre-rules can be modified by the local administrator or by a Panorama administrator who has

Pre-rules are managed by Panorama administrators for centralized policy enforcement and typically cannot be modified by local firewall administrators to maintain consistent global policy.

BPre-rules and local device rules can be modified in Panorama.

Local device rules are, by definition, created and modified on the local firewall itself, not through Panorama, which manages pre-rules and post-rules for device groups.

CPre-rules can be viewed on managed firewalls.Correct

Pre-rules, though configured and pushed from Panorama, are visible on the managed firewalls, allowing local administrators to see the complete rule set that applies to their device for understanding policy enforcement.

DPre-rules are modified in Panorama only, and local device rules are modified on local firewallsCorrect

Pre-rules are designed for centralized management and can only be modified within Panorama, while local device rules are specifically created and modified directly on the individual firewalls to address unique local requirements.

Concept tested: Panorama pre-rules vs. local device rules management

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/policy-overview-for-firewalls-in-a-device-group/device-group-policy-overview

Topics

#Panorama#Pre-rules#Local device rules#Rule management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice