PCNSA · Question #186
Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?
The correct answer is B. source address. An External Dynamic List (EDL) of Known Malicious IP Addresses contains IPs that are initiating malicious traffic toward your network. Since these IPs are the originators of the threat, they appear as the source of inbound connections. To block traffic coming FROM these…
Question
Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?
Options
- Adestination address
- Bsource address
- Cdestination zone
- Dsource zone
How the community answered
(71 responses)- A3% (2)
- B93% (66)
- C1% (1)
- D3% (2)
Explanation
An External Dynamic List (EDL) of Known Malicious IP Addresses contains IPs that are initiating malicious traffic toward your network. Since these IPs are the originators of the threat, they appear as the source of inbound connections. To block traffic coming FROM these malicious IPs, you reference the EDL in the 'source address' match condition of a Security policy rule with a Deny action. Using 'destination address' would block traffic going TO those IPs, which is a different use case. Zones do not directly reference IP-based EDLs.
Topics
Community Discussion
No community discussion yet for this question.