nerdexam
Palo_Alto_Networks

PCNSE · Question #456

To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?

The correct answer is A. Add the policy in the shared device group as a pre-rule. To ensure a Security policy has the absolute highest priority in a Panorama device group hierarchy, it must be configured as a pre-rule within the Shared device group.

Submitted by paula_co· Apr 18, 2026Deploy and Configure

Question

To ensure that a Security policy has the highest priority, how should an administrator configure a Security policy in the device group hierarchy?

Options

  • AAdd the policy in the shared device group as a pre-rule
  • BReference the targeted device's templates in the target device group
  • CAdd the policy to the target device group and apply a master device to the device group
  • DClone the security policy and add it to the other device groups

How the community answered

(21 responses)
  • A
    76% (16)
  • B
    14% (3)
  • C
    5% (1)
  • D
    5% (1)

Why each option

To ensure a Security policy has the absolute highest priority in a Panorama device group hierarchy, it must be configured as a pre-rule within the Shared device group.

AAdd the policy in the shared device group as a pre-ruleCorrect

Policies configured as pre-rules in the Shared device group are evaluated first in the policy rulebase processing order, granting them the highest possible priority across the entire hierarchy.

BReference the targeted device's templates in the target device group

Referencing templates is a mechanism for deploying configuration to firewalls, not for defining the priority order of security policies.

CAdd the policy to the target device group and apply a master device to the device group

Adding a policy to a target device group or applying a master device doesn't automatically assign the highest priority; the priority depends on whether it's a pre-rule or post-rule and its specific position.

DClone the security policy and add it to the other device groups

Cloning security policies to multiple device groups is inefficient and does not guarantee the highest priority; policy priority is determined by its position and type (pre-rule/post-rule) within the device group hierarchy.

Concept tested: Panorama policy evaluation order and device group hierarchy

Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/panorama/manage-firewalls-with-device-groups/how-device-groups-affect-policy-and-object-inheritance.html

Topics

#Security Policy#Policy Priority#Panorama Device Groups#Rule Order

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice