PCNSA Device Management and Services Practice Question
A network admin needs to push a security policy change to firewall-01 and firewall-02. Both firewalls have different interface configurations but should share the same security rules. What is the best way to achieve this using Panorama?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a single device group containing both firewalls and configure security policies there.
The best way to share security policies across firewalls with different interface configurations is to use a single device group containing both firewalls. Device groups are designed to manage security policies centrally, while templates handle device-specific settings like interface configurations. Option B is correct because it allows policy consistency without duplicating effort. Option A (separate device groups) would require manual duplication. Option C (templates) is incorrect because templates are for device-level configuration, not security policies. Option D (Shared policy with overrides) is not a standard or efficient approach for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create separate device groups for each firewall and configure identical policies manually.
Why it's wrong here
Separate device groups with manually duplicated policies create two divergent rule sets that drift apart, defeating the shared-rules requirement. It is tempting because device groups scope policy per firewall, and this would fit firewalls needing genuinely different rule sets.
- ✓
Create a single device group containing both firewalls and configure security policies there.
Why this is correct
A device group containing both firewalls lets you author security policies once and push them to both devices, while each firewall retains its own interface configuration in separate templates. This satisfies the requirement for shared rules despite differing interface setups.
- ✗
Use templates to define security policies and assign to both firewalls.
Why it's wrong here
Templates push device and network configuration, not security policy; rules placed there never reach the policy rulebase. It is tempting because templates handle per-firewall interface differences, and they would be correct for deploying interface or zone settings.
- ✗
Use the Shared policy and override for interfaces.
Why it's wrong here
Shared policy applies rules globally, but interface overrides only adjust interface-level settings, not the per-firewall interface configurations the scenario requires. It is tempting because Shared is the natural home for common rules, and it would fit firewalls sharing identical interfaces.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.