Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

An administrator is deploying a PA-5220 firewall in a data center. The security team requires that all management access to the firewall's web interface and SSH be restricted to a dedicated out-of-band management network. The management interface (MGT) is currently configured with IP address 10.0.0.1/24 and default gateway 10.0.0.254. Which configuration step is required to allow only hosts on the 10.0.0.0/24 network to access the management interface?

⚠ Common exam trap

The trap here is assuming that security policy rules or static routes control management interface access, when in fact an Interface Management profile is the correct mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.

Management access on Palo Alto Networks firewalls is controlled by Interface Management profiles, which specify allowed services and permitted source IP addresses. Assigning such a profile to the MGT interface ensures only hosts in 10.0.0.0/24 can reach the web interface and SSH. Security policies and static routes do not govern management plane traffic, and the global permitted IP list is less granular.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Permitted IP Addresses' setting under Device > Setup > Management and enter 10.0.0.0/24.

    Why it's wrong here

    The 'Permitted IP Addresses' setting under Device > Setup > Management is used for firewall administration from specific IP addresses, but it applies globally to all management interfaces, not per-interface. The question requires restricting access on the MGT interface specifically. While it could work, the more precise and intended method is an Interface Management profile assigned to that interface.

  • ✗

    Add a static route for 10.0.0.0/24 pointing to the MGT interface and enable strict routing.

    Why it's wrong here

    Static routes control dataplane traffic forwarding, not management plane access. Adding a route for the local subnet does not restrict who can connect to the management interface. Management access filtering requires an Interface Management profile. Strict routing is not a feature that enforces source-based management access control, so this option does not meet the requirement.

  • ✓

    Configure an Interface Management profile with permitted IP addresses 10.0.0.0/24 and assign it to the MGT interface.

    Why this is correct

    An Interface Management profile defines which management services (HTTPS, SSH, etc.) are enabled and from which source networks they are reachable. Assigning it to the MGT interface with permitted IP addresses 10.0.0.0/24 restricts management access to that subnet. This is the correct method to limit management access on a Palo Alto Networks firewall.

  • ✗

    Create a security policy rule from the management zone to the management zone allowing only the 10.0.0.0/24 subnet.

    Why it's wrong here

    Security policy rules on Palo Alto Networks firewalls apply to traffic transiting dataplane interfaces, not to traffic destined to the management interface itself. Management plane access is controlled by Management Interface settings and an Interface Management profile. A security rule in the management zone does not filter management access, so this approach fails to restrict administrative sessions.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.