Courseiva

PCNSA Device Management and Services Practice Question

An administrator modifies a security policy but the change does not take effect. What must the administrator do?

⚠ Common exam trap

Palo Alto Networks often tests the misconception that saving a configuration (e.g., via 'save config' or clicking Save) is sufficient to apply changes, but in Palo Alto firewalls, a commit is mandatory to move changes from candidate to active state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Commit the configuration.

In Palo Alto Networks firewalls, configuration changes are made in a candidate configuration that is not active until explicitly committed. The administrator must commit the configuration to apply the changes to the running configuration and enforce the new security policy. Without a commit, the modification remains pending and does not affect traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Commit the configuration.

    Why this is correct

    Palo Alto Networks firewalls use a candidate configuration; policy edits stay pending until committed to the running configuration. Committing pushes the modified security policy into enforcement, which is why the change appeared ineffective beforehand. Without a commit, the firewall continues evaluating traffic against the previous ruleset.

  • ✗

    Import the configuration.

    Why it's wrong here

    Importing overwrites the running configuration with a previously exported file, discarding the pending edit rather than activating it. It is used to restore settings onto a replacement or freshly reset firewall. Here the change already exists in the candidate configuration, so importing would erase the very policy the administrator wants applied.

  • ✗

    Save the configuration.

    Why it's wrong here

    Committing the candidate configuration is required before a policy change takes effect; saving alone leaves it uncommitted. The option tempts because saving feels like the final step, but on PAN-OS the candidate must be committed. Saving is correct only when preserving edits without activating them.

  • ✗

    Reboot the firewall.

    Why it's wrong here

    Rebooting reloads the last committed configuration from disk, so any uncommitted policy edit is lost rather than applied. Rebooting is used to clear stuck processes or apply a pending software upgrade. The scenario needs a commit, which activates the candidate configuration without interrupting traffic or discarding the change.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.