nerdexam
Palo_Alto_Networks

PCNSE · Question #750

A security engineer wants to upgrade the company's deployed firewalls from PAN-OS 10.1 to 11.0.x to take advantage of the newTLSv1.3 support for management access. What is the recommended upgrade path

The correct answer is B. Optional: Download and install the latest preferred PAN-OS 10.1 release.. Palo Alto Networks requires a sequential upgrade path across major versions. Going from PAN-OS 10.1 directly to 11.0.x is not supported; 10.2 must be used as a mandatory stepping stone. Upgrading to the latest 10.1 maintenance release first is recommended best practice but is tec

Submitted by haruto_sh· Apr 18, 2026Deploy and Configure

Question

A security engineer wants to upgrade the company's deployed firewalls from PAN-OS 10.1 to 11.0.x to take advantage of the newTLSv1.3 support for management access. What is the recommended upgrade path procedure from PAN-OS 10.1 to 11.0.x?

Options

  • ARequired: Download and install the latest preferred PAN-OS 10.1 maintenance release and
  • BOptional: Download and install the latest preferred PAN-OS 10.1 release.
  • CRequired: Download PAN-OS 10.2.0 or earlier release that is not EOL.
  • DRequired: Download and install the latest preferred PAN-OS 10.1 maintenance release and

How the community answered

(32 responses)
  • B
    91% (29)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Palo Alto Networks requires a sequential upgrade path across major versions. Going from PAN-OS 10.1 directly to 11.0.x is not supported; 10.2 must be used as a mandatory stepping stone. Upgrading to the latest 10.1 maintenance release first is recommended best practice but is technically optional - hence Option B correctly marks it as 'Optional.' Options A and D describe the 10.1 maintenance release step as 'Required,' which is inaccurate per Palo Alto's documented upgrade path. Option C addresses 10.2 but the distinction between the choices rests on whether the 10.1 update is required or optional.

Topics

#PAN-OS upgrade#Upgrade path#Maintenance release#Best practices

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice