PCNSA · Question #291
An organization has some applications that are restricted for access by the Human Resources Department only, and other applications that are available for any known user in the organization. What…
The correct answer is A. Application Group. An Application Group is the most suitable object for organizing multiple applications into a single logical entity to apply consistent security policies, like restricting access for specific departments.
Question
An organization has some applications that are restricted for access by the Human Resources Department only, and other applications that are available for any known user in the organization. What object is best suited for this configuration?
Options
- AApplication Group
- BTag
- CExternal Dynamic List
- DApplication Filter
How the community answered
(46 responses)- A91% (42)
- B2% (1)
- C2% (1)
- D4% (2)
Why each option
An Application Group is the most suitable object for organizing multiple applications into a single logical entity to apply consistent security policies, like restricting access for specific departments.
An Application Group allows administrators to combine multiple specific applications into a single logical object, which can then be used in security policies to simplify management by enabling a single rule to control access to all applications within the group for specific user groups.
Tags are used for grouping address objects (IPs) or virtual machines, not directly for grouping applications themselves in a policy.
An External Dynamic List (EDL) is used for external lists of IP addresses, URLs, or domains, not for grouping internal applications managed by App-ID.
An Application Filter creates a dynamic selection of applications based on attributes (e.g., category, subcategory, risk), but an Application Group provides explicit control over a predefined set of applications for policy application.
Concept tested: Application Groups for policy enforcement
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/applications/application-groups
Topics
Community Discussion
No community discussion yet for this question.