nerdexam
Palo_Alto_Networks

PCNSA · Question #220

An administrator would like to determine the default deny action for the application dns-over- https. Which action would yield the information?

The correct answer is D. View the application details in Objects > Applications. An administrator can find the default deny action for a specific application like dns-over-https by viewing its detailed information within the Objects > Applications section of the firewall.

Submitted by tunde_lagos· Apr 18, 2026Managing Objects

Question

An administrator would like to determine the default deny action for the application dns-over- https. Which action would yield the information?

Options

  • AView the application details in beacon paloaltonetworks.com
  • BCheck the action for the Security policy matching that traffic
  • CCheck the action for the decoder in the antivirus profile
  • DView the application details in Objects > Applications

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    5% (1)
  • D
    90% (19)

Why each option

An administrator can find the default deny action for a specific application like dns-over-https by viewing its detailed information within the Objects > Applications section of the firewall.

AView the application details in beacon paloaltonetworks.com

beacon.paloaltonetworks.com is an external knowledge base for application information and threat intelligence, not for configuration-specific default actions on a local firewall.

BCheck the action for the Security policy matching that traffic

Security policies define actions for traffic that matches their criteria, but they do not define an application's inherent 'default deny' action when no policy matches.

CCheck the action for the decoder in the antivirus profile

Antivirus profiles are designed for detecting and preventing malware, not for defining the default traffic handling of legitimate applications like dns-over-https.

DView the application details in Objects > ApplicationsCorrect

The Objects > Applications section in the Palo Alto Networks firewall UI provides granular details for each application, including its inherent default action which determines how the firewall treats that application's traffic if no security policy explicitly permits or denies it.

Concept tested: Application object details and default action

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/applications/application-filters-and-groups/view-application-details

Topics

#Application Identification#Object Management#Firewall GUI#Application Details

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice