Drag steps to the numbered slots on the right, or tap a step then tap a slot.
PCNSE Manage, Monitor and Operate Practice Question
Arrange the steps to configure a new administrator account with role-based access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Navigate to Device > Administrators and click Add. Step 2: Enter username and password. Step 3: Select the role. Step 4: Commit.
To configure a new administrator with role-based access on a Palo Alto firewall, you must first create the administrator account by navigating to Device > Administrators and clicking Add. Then enter the username and password. Next, assign a role (e.g., Superuser, Read‑Only, or a custom role) to define the access level. Finally, commit the changes to apply the configuration. This sequence ensures the account is fully defined before committing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Navigate to Device > Administrators and click Add. Step 2: Enter username and password. Step 3: Select the role. Step 4: Commit.
Why this is correct
This order ensures the administrator account is created with credentials and role before committing, making the configuration consistent.
- ✗
Step 1: Enter username and password. Step 2: Navigate to Device > Administrators and click Add. Step 3: Select the role. Step 4: Commit.
Why it's wrong here
Incorrect because you must first add the administrator object before entering credentials; the Add operation creates the container for the credentials.
- ✗
Step 1: Navigate to Device > Administrators and click Add. Step 2: Select the role. Step 3: Enter username and password. Step 4: Commit.
Why it's wrong here
Incorrect because you need to enter the username and password before selecting the role; the role is assigned to a specific user account.
- ✗
Step 1: Navigate to Device > Administrators and click Add. Step 2: Enter username and password. Step 3: Commit. Step 4: Select the role.
Why it's wrong here
Incorrect because committing before selecting the role would leave the administrator without an assigned role, which may result in access issues.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.