Courseiva

PCNSE Core Concepts and Architecture Practice Question

A security administrator configures a new network template in Panorama and assigns it to a template stack. The template stack is associated with a device group containing several firewalls. After committing the Panorama configuration and pushing to devices, some firewalls in the device group do not have the new template settings. What is the most likely cause?

⚠ Common exam trap

Test-takers frequently confuse device groups (which manage policy) with template stacks (which manage network configuration), assuming that membership in a device group automatically applies all associated templates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewalls that are not receiving the template are not included in the same template stack.

In Panorama, templates are assigned to template stacks, and template stacks are then assigned to specific firewalls. If a firewall does not belong to the template stack that contains the new template, it will not receive those settings, regardless of its membership in the device group. Device groups manage policy objects and rules, not network configuration templates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The firewalls that are not receiving the template are not included in the same template stack.

    Why this is correct

    Template settings only reach firewalls that are members of the template stack. Firewalls in the device group but absent from that stack receive no template configuration, explaining why only some devices show the new settings.

  • ✗

    The device group has not been committed.

    Why it's wrong here

    Template settings are pushed through template stacks, not device groups; committing the device group publishes policy rules, leaving the network template unapplied. It is tempting because device group commits are a routine Panorama step, and they are the correct remedy when policy objects, not template settings, fail to reach firewalls.

  • ✗

    The firewalls are not licensed for Panorama management.

    Why it's wrong here

    Panorama management licensing governs whether a firewall can be onboarded and managed at all; unlicensed devices would not appear in the device group or receive any pushed configuration. It is tempting because licensing genuinely blocks Panorama onboarding, but it cannot explain partial delivery to already-managed firewalls.

  • ✗

    The template is in 'preview' mode.

    Why it's wrong here

    Panorama templates have no preview mode; configuration is staged in the candidate config and applied only after commit and push. It is tempting because preview-style validation exists elsewhere in the product, and it would explain settings not taking effect if such a state existed for templates.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.