PCNSA · Question #299
By default, which action is assigned to the interzone-default rule?
The correct answer is B. Deny. By default, the interzone-default rule is configured to deny all traffic attempting to cross between different security zones unless explicitly permitted by a more specific rule.
Question
By default, which action is assigned to the interzone-default rule?
Options
- AAllow
- BDeny
- CReset-client
- DReset-server
How the community answered
(46 responses)- A4% (2)
- B93% (43)
- C2% (1)
Why each option
By default, the interzone-default rule is configured to deny all traffic attempting to cross between different security zones unless explicitly permitted by a more specific rule.
Allowing interzone traffic by default would pose a significant security risk, as it would expose internal networks to unauthorized access without specific policy enforcement.
The default security posture for firewalls is to deny interzone traffic, ensuring that only explicitly permitted communication can occur between distinct network segments, following a zero-trust principle.
While 'reset-client' is a possible action, it is not the default for the interzone-default rule, which typically performs a silent deny to avoid revealing network topology.
Similar to 'reset-client,' 'reset-server' is an action, but the default for the interzone-default rule is a silent denial of unpermitted traffic.
Concept tested: Default interzone firewall rule action
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rules.html
Topics
Community Discussion
No community discussion yet for this question.