PCNSA Device Management and Services Practice Question
Exhibit
<devices> <name>PA-220</name> <vlan>none</vlan> <ip>10.0.0.1/24</ip> <management-profile>allow-ping</management-profile> </devices>
Refer to the exhibit. What is the effect of this configuration?
⚠ Common exam trap
Palo Alto Networks often tests the confusion between management plane services (like ping to the firewall) and data plane transit traffic (like ping through the firewall), leading candidates to incorrectly assume a management profile affects traffic forwarding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall responds to pings on the management interface.
The configuration shown is a management profile applied to an interface. The 'ping' service is enabled under the management profile, which allows the firewall to respond to ICMP echo requests (pings) on that specific interface. This does not permit transit ping traffic through the firewall, nor does it enable SSH or allow the firewall to initiate pings. Therefore, option C is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall allows ping traffic through all interfaces.
Why it's wrong here
A management profile applies to the interface's own administrative services, so it cannot permit ping across every interface. It is tempting because ping is listed among management-profile protocols, but that setting governs responses to the firewall itself, not transit ICMP through the device.
- ✗
The management profile allows SSH access.
Why it's wrong here
The management profile governs administrative access to the firewall itself, not transit traffic. It is tempting because management profiles do control protocols like SSH and HTTPS, but the exhibit concerns a security policy's application or service settings, which determine forwarded traffic.
- ✓
The firewall responds to pings on the management interface.
Why this is correct
The management interface permits ICMP, so the firewall replies to ping requests arriving on it. This satisfies the exhibit's effect: management-plane access is allowed for troubleshooting, while data-plane interfaces remain governed by their own security policies.
- ✗
The firewall cannot ping others.
Why it's wrong here
A management profile's ping setting affects only whether the firewall responds to pings on its own interfaces, not whether it can initiate pings elsewhere. It is tempting because ping appears in management profiles, but outbound ping depends on the firewall's own outbound policy and source interface.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.