NETSEC-ANALYST · Question #321
Which rule type is appropriate for matching traffic occurring within a specified zone? How should the administrator configure the firewall to restrict users to specific email applications?
The correct answer is C. Create an application group and add the email applications to it.. An application group is an object that contains applications that you want to treat similarly in policy. Application groups are useful for enabling access to applications that you explicitly sanction for use within your organization. Grouping sanctioned applications simplifies ad
Question
Which rule type is appropriate for matching traffic occurring within a specified zone? How should the administrator configure the firewall to restrict users to specific email applications?
Options
- ACreate an application filter and filter it on the collaboration category.
- BCreate an application filter and filter it on the collaboration category, email subcategory.
- CCreate an application group and add the email applications to it.
- DCreate an application group and add the email category to it.
How the community answered
(39 responses)- A8% (3)
- B13% (5)
- C74% (29)
- D5% (2)
Explanation
An application group is an object that contains applications that you want to treat similarly in policy. Application groups are useful for enabling access to applications that you explicitly sanction for use within your organization. Grouping sanctioned applications simplifies administration of your rulebases. Instead of having to update individual policy rules when there is a change in the applications you support, you can update only the affected application groups. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/use-application-objects-in- policy/create-an-application-group
Topics
Community Discussion
No community discussion yet for this question.