nerdexam
Palo_Alto_Networks

PCNSA · Question #246

An administrator would like to apply a more restrictive Security profile to traffic for file sharing applications. The administrator does not want to update the Security policy or object when new appl

The correct answer is D. an application filter for applications whose subcategory is file-sharing. To dynamically apply Security profiles to file-sharing applications without manual updates, the administrator should use an application filter. This filter can be configured to match applications based on their subcategory, such as "file-sharing," automatically including new appl

Submitted by priya_blr· Apr 18, 2026Managing Objects

Question

An administrator would like to apply a more restrictive Security profile to traffic for file sharing applications. The administrator does not want to update the Security policy or object when new applications are released. Which object should the administrator use as a match condition in the Security policy?

Options

  • Athe Content Delivery Networks URL category
  • Bthe Online Storage and Backup URL category
  • Can application group containing all of the file-sharing App-IDs reported in the traffic logs
  • Dan application filter for applications whose subcategory is file-sharing

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    11% (7)
  • D
    81% (50)

Why each option

To dynamically apply Security profiles to file-sharing applications without manual updates, the administrator should use an application filter. This filter can be configured to match applications based on their subcategory, such as "file-sharing," automatically including new applications as they are released and classified.

Athe Content Delivery Networks URL category

The Content Delivery Networks URL category classifies websites, not applications, and would not target file-sharing applications directly.

Bthe Online Storage and Backup URL category

The Online Storage and Backup URL category classifies websites related to cloud storage, which is different from App-IDs for file-sharing applications.

Can application group containing all of the file-sharing App-IDs reported in the traffic logs

An application group requires manual addition of specific App-IDs, meaning it would need to be updated whenever new file-sharing applications are released, which goes against the requirement of not updating the object.

Dan application filter for applications whose subcategory is file-sharingCorrect

An application filter allows you to create dynamic groups of applications based on attributes like category, subcategory, or technology. By creating an application filter for applications with the "file-sharing" subcategory, any new file-sharing applications released by Palo Alto Networks will automatically be included, eliminating the need for manual updates to the security policy or object.

Concept tested: Dynamic application matching with application filters

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/application-filters

Topics

#Application Filter#Security Policy#App-ID#Dynamic Matching

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice