PCNSE Deploy and Configure Firewalls Practice Question
An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?
⚠ Common exam trap
The trap here is assuming that security policy rules or static routes control management interface access, when in fact an Interface Management profile is the correct mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.
Management access on Palo Alto Networks firewalls is controlled by Interface Management profiles, which specify allowed services and permitted source IP addresses. Assigning such a profile to the MGT interface ensures only hosts in 10.0.0.0/24 can reach the web interface and SSH. Security policies and static routes do not govern management plane traffic, and the global permitted IP list is less granular.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'Permitted IP Addresses' setting under Device > Setup > Management and enter 10.0.0.0/24.
Why it's wrong here
The 'Permitted IP Addresses' setting under Device > Setup > Management is used for firewall administration from specific IP addresses, but it applies globally to all management interfaces, not per-interface. The question requires restricting access on the MGT interface specifically. While it could work, the more precise and intended method is an Interface Management profile assigned to that interface.
- ✗
Add a static route for 10.0.0.0/24 pointing to the MGT interface and enable strict routing.
Why it's wrong here
Static routes control dataplane traffic forwarding, not management plane access. Adding a route for the local subnet does not restrict who can connect to the management interface. Management access filtering requires an Interface Management profile. Strict routing is not a feature that enforces source-based management access control, so this option does not meet the requirement.
- ✓
Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.
Why this is correct
An Interface Management profile defines which management services (HTTPS, SSH, etc.) are enabled and from which source networks they are reachable. Assigning it to the MGT interface with permitted IP addresses 10.0.0.0/24 restricts management access to that subnet. This is the correct method to limit management access on a Palo Alto Networks firewall.
- ✗
Create a security policy rule from the management zone to the management zone allowing only the 10.0.0.0/24 subnet.
Why it's wrong here
Security policy rules on Palo Alto Networks firewalls apply to traffic transiting dataplane interfaces, not to traffic destined to the management interface itself. Management plane access is controlled by Management Interface settings and an Interface Management profile. A security rule in the management zone does not filter management access, so this approach fails to restrict administrative sessions.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.