Courseiva
Device Management and ServicesmediumMultiple ChoiceObjective-mapped

PCNSA Device Management and Services Practice Question

A security administrator manages a Palo Alto Networks firewall with multiple virtual systems (vsys). The firewall is configured to use Panorama for centralized management. The administrator notices that after committing a configuration change on Panorama, the firewall's vsys2 is not receiving the updated configuration. The firewall can reach Panorama, and other vsys are updated correctly. The administrator verifies that Panorama's device group hierarchy includes the firewall and that the vsys2 template stack is correctly assigned. What is the most likely cause of this issue?

⚠ Common exam trap

Watch out — candidates often confuse device group membership with template stack assignment, assuming both are required for configuration push, but only device group membership controls policy delivery to specific vsys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The vsys2 is not included in the device group on Panorama.

Panorama pushes configuration to firewalls based on device group membership. If vsys2 is not included in the device group assigned to the firewall, Panorama will not push the updated configuration to that virtual system, even if the firewall itself is reachable and other vsys are updated. The administrator verified the template stack assignment, but the device group inclusion is a separate prerequisite for configuration delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The commit on Panorama failed for vsys2 due to a validation error.

    Why it's wrong here

    If the commit failed, Panorama would indicate a failure. The administrator did not mention any error.

  • The admin user does not have sufficient privileges to push configuration to vsys2.

    Why it's wrong here

    The admin user role affects the ability to modify configurations, but Panorama pushes regardless of the role that committed.

  • The vsys2 is not included in the device group on Panorama.

    Why this is correct

    For Panorama to push configuration to a specific vsys, that vsys must be part of the device group. If vsys2 is omitted, it won't receive the update.

  • The firewall's serial number is not registered correctly in Panorama for vsys2.

    Why it's wrong here

    The serial number is used for authentication at the firewall level, not for targeting specific vsys.

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.