Courseiva
Manage, Monitor and OperatehardMultiple SelectObjective-mapped

PCNSE Manage, Monitor and Operate Practice Question

A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure role-based access on Panorama.

To restrict commit permissions to specific administrators, two actions are required: configuring role-based access on Panorama (B) and creating an admin role with commit scope limited to specific device groups (C). Role-based access allows fine-grained control over admin privileges on Panorama. By creating a custom admin role with a commit scope limited to specific device groups, you ensure that administrators can only commit changes to devices within their assigned groups. Option A (MFA) enhances authentication but does not restrict commit permissions. Option D (template stacks) is used for template management, not commit control. Option E (commit approval) is not a built-in Panorama feature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Multi-Factor Authentication for all admins.

    Why it's wrong here

    MFA enhances authentication security but does not restrict commit permissions.

  • Configure role-based access on Panorama.

    Why this is correct

    Panorama RBAC defines which administrators can commit changes to which device groups.

  • Create an admin role with commit scope limited to specific device groups.

    Why this is correct

    This restricts commit permissions to specific devices within device groups.

  • Use template stacks to restrict commit permissions.

    Why it's wrong here

    Template stacks are for managing configuration templates, not commit permissions.

  • Set the firewall to require approval for commits.

    Why it's wrong here

    The firewall does not have a native commit approval feature; this would need external workflow.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.