Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignHard

A large enterprise with multiple business units needs to deploy Palo Alto Networks firewalls. Each business unit requires administrative separation, allowing their respective IT teams to manage their own security policies and objects, but the central security team needs overarching visibility and the ability to enforce global security policies. Which Panorama feature enables this administrative delegation and multi-tenancy?

  1. ATemplates
  2. BVirtual Systems (vSys)
  3. CRole-Based Access Control (RBAC)
  4. DDevice Groups
Show answer & explanation

Correct answer: C. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) in Panorama is the feature that allows for granular administrative delegation, enabling different administrative roles with specific permissions. This allows business unit IT teams to manage their own policies and objects within defined scopes while the central security team maintains global control and visibility.

Why the other options are wrong

  • A. Templates are used for standardizing configurations across firewalls, not for delegating administrative responsibilities.
  • B. Virtual Systems (vSys) are used to logically segment a single physical firewall into multiple virtual firewalls, which is a different concept than delegating administrative rights over a set of physical firewalls.
  • D. Device Groups are used for grouping firewalls and applying policies/objects to them, but they don't directly provide administrative delegation for different teams.

Panorama Role-Based Access Control (RBAC)

A security mechanism in Panorama that assigns specific permissions to administrative users based on their roles, enabling granular control over which features, device groups, and templates they can view, modify, or deploy. This facilitates administrative delegation and multi-tenancy.

  • Granular administrative delegation
  • Defines user roles and permissions
  • Controls access to features and objects
  • Supports multi-tenancy environments

Memory trick: RBAC: Roles grant access, not just anyone.

More Plan and Design questions