Palo_Alto_Networks
ACE · Question #167
When configuring a Security Policy Rule based on FQDN Address Objects, which of the following statements is True?
The correct answer is B. The firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again at DNS TTL expiration. See the full explanation below for the reasoning.
Question
When configuring a Security Policy Rule based on FQDN Address Objects, which of the following statements is True?
Options
- AThe firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again each time Security Profiles are evaluated.
- BThe firewall resolves the FQDN first when the policy is committed, and resolves the FQDN again at DNS TTL expiration.
- CIn order to create FQDN-based objects, you need to manually define a list of associated IP addresses.
How the community answered
(59 responses)- A8% (5)
- B75% (44)
- C17% (10)
Community Discussion
No community discussion yet for this question.