nerdexam
Palo_Alto_Networks

PCNSE · Question #93

Which three rule types are available when defining policies in Panorama? (Choose three.)

The correct answer is A. Pre Rules B. Post Rules C. Default Rules. In Panorama, policies are organized into three rule types that are evaluated in a specific order: Pre Rules (A) are defined in Panorama and pushed to managed devices, evaluated before any locally-defined device group rules. Post Rules (B) are also Panorama-defined but evaluated a

Submitted by tunde_lagos· Apr 18, 2026Deploy and Configure

Question

Which three rule types are available when defining policies in Panorama? (Choose three.)

Options

  • APre Rules
  • BPost Rules
  • CDefault Rules
  • DStealth Rules
  • EClean Up Rules

How the community answered

(27 responses)
  • A
    96% (26)
  • E
    4% (1)

Explanation

In Panorama, policies are organized into three rule types that are evaluated in a specific order: Pre Rules (A) are defined in Panorama and pushed to managed devices, evaluated before any locally-defined device group rules. Post Rules (B) are also Panorama-defined but evaluated after local rules. Default Rules (C) are the built-in system rules at the bottom of the policy table, such as the implicit deny-all rule. Together, these three types create a layered policy hierarchy: Pre Rules → Local Device Rules → Post Rules → Default Rules. 'Stealth Rules' and 'Clean Up Rules' are informal naming conventions used in security best practices, not official Panorama rule type categories.

Topics

#Panorama Policy#Security Rules#Rule Hierarchy

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice