nerdexam
Palo_Alto_Networks

PCNSE · Question #765

A firewall engineer needs to update a company's Panorama-managed firewalls to the latest version of PAN-OS. Strict security requirements are blocking internet access to Panorama and to the…

The correct answer is A. Upload the image to Panorama > Device Deployment > Software menu, and deploy it to the. To deploy PAN-OS images to Panorama-managed firewalls without internet access, upload them to Panorama's Device Deployment > Software menu.

Submitted by tyler.j· Apr 18, 2026Deploy and Configure

Question

A firewall engineer needs to update a company's Panorama-managed firewalls to the latest version of PAN-OS. Strict security requirements are blocking internet access to Panorama and to the firewalls. The PAN-OS images have previously been downloaded to a secure host on the network. Which path should the engineer follow to deploy the PAN-OS images to the firewalls?

Options

  • AUpload the image to Panorama > Device Deployment > Software menu, and deploy it to the
  • BUpload the image to Panorama > Device Deployment > Dynamic Updates menu, and deploy it to
  • CUpload the image to Panorama > Software menu, and deploy it to the firewalls.
  • DUpload the image to Panorama > Dynamic Updates menu, and deploy it to the firewalls.

How the community answered

(63 responses)
  • A
    87% (55)
  • B
    5% (3)
  • C
    6% (4)
  • D
    2% (1)

Why each option

To deploy PAN-OS images to Panorama-managed firewalls without internet access, upload them to Panorama's Device Deployment > Software menu.

AUpload the image to Panorama > Device Deployment > Software menu, and deploy it to theCorrect

When Panorama and its managed firewalls lack internet access, PAN-OS software images must be manually uploaded to the Panorama device. The `Device Deployment > Software` menu in Panorama is the designated interface for uploading these images and subsequently deploying them to managed firewalls.

BUpload the image to Panorama > Device Deployment > Dynamic Updates menu, and deploy it to

The `Dynamic Updates` menu in Panorama is specifically used for managing content updates such as applications, threats, antivirus definitions, and WildFire updates, not for PAN-OS software images.

CUpload the image to Panorama > Software menu, and deploy it to the firewalls.

The full and correct path for deploying software to *managed firewalls* via Panorama is `Device Deployment > Software`, making the simpler `Panorama > Software` incomplete and potentially misleading as it might refer to Panorama's own software.

DUpload the image to Panorama > Dynamic Updates menu, and deploy it to the firewalls.

The `Dynamic Updates` menu is intended for content updates (applications, threats, etc.), not for uploading and deploying PAN-OS operating system images.

Concept tested: Panorama offline PAN-OS software deployment

Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/manage-firewall-licenses-and-updates/download-and-install-pan-os-software-updates.html

Topics

#PAN-OS Update#Panorama Management#Offline Updates#Software Deployment

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice