PCNSE Manage, Monitor and Operate Practice Question
A firewall is part of a Panorama-managed environment. The administrator needs to ensure that only specific administrators can commit changes to devices. Which TWO actions are required? (Choose two.)
⚠ Common exam trap
The trap is confusing authentication (MFA) with authorization (RBAC); MFA does not restrict what an admin can do after login, only how they log in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure role-based access on Panorama.
Option B is correct because Panorama's role-based access control (RBAC) is the mechanism that defines what each administrator account is allowed to do, including whether they can push commits to managed devices; without configuring roles on Panorama, no granular restriction of commit rights is possible. Option C is correct because an admin role can be scoped with a commit scope limited to specific device groups (and templates), so administrators assigned that role can only commit changes to those device groups rather than to all managed firewalls. Option A is not required because MFA strengthens authentication but does not restrict which devices an admin can commit to. Option D is incorrect because template stacks are configuration containers for pushing settings to firewalls, not a permission-control feature. Option E is incorrect because firewalls in a Panorama-managed environment do not have a per-device 'require approval for commits' setting that governs administrator commit permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Multi-Factor Authentication for all admins.
Why it's wrong here
MFA strengthens authentication of administrator logins but does not differentiate commit privileges between administrators; every authenticated admin retains the same rights. It is tempting because MFA is a genuine access-control hardening measure, and it would be correct where the requirement is to prevent credential compromise rather than to partition commit permissions by role.
- ✓
Configure role-based access on Panorama.
Why this is correct
Role-based access control on Panorama assigns administrative roles defining which device groups, templates and actions each administrator may use. This satisfies the requirement that only specific administrators can commit changes to devices, because commit rights derive from the assigned role's permissions.
- ✓
Create an admin role with commit scope limited to specific device groups.
Why this is correct
A custom admin role scoped to specific device groups restricts commit operations to those groups, so administrators cannot push configuration to other managed firewalls. This satisfies the requirement that only specific administrators can commit changes to devices, enforcing least privilege at the commit boundary.
- ✗
Use template stacks to restrict commit permissions.
Why it's wrong here
Template stacks are configuration containers that determine which device groups and templates a firewall inherits; they carry no permission semantics whatsoever. It is tempting because template stacks are central to structuring Panorama-managed deployments, and they would be the right answer where the requirement is to standardise configuration across device groups.
- ✗
Set the firewall to require approval for commits.
Why it's wrong here
Commit approval is configured on Panorama, not on the managed firewall, and it gates commits made from Panorama rather than restricting which individual administrators hold commit rights. It is tempting because approval workflows do control who can push configuration changes, but they apply to Panorama commit operations, not firewall-level RBAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.