PCNSA · Question #321
Which rule type is appropriate for matching traffic occurring within a specified zone? How should the administrator configure the firewall to restrict users to specific email applications?
The correct answer is C. Create an application group and add the email applications to it. An Application Group is a static, manually defined collection of specific named applications (e.g., gmail, outlook-web, yahoo-mail). This is the right choice when you want to allow or deny a precise set of applications. An Application Filter is dynamic and matches applications…
Question
Which rule type is appropriate for matching traffic occurring within a specified zone? How should the administrator configure the firewall to restrict users to specific email applications?
Options
- ACreate an application filter and filter it on the collaboration category.
- BCreate an application filter and filter it on the collaboration category, email subcategory.
- CCreate an application group and add the email applications to it.
- DCreate an application group and add the email category to it.
How the community answered
(40 responses)- A5% (2)
- B8% (3)
- C73% (29)
- D15% (6)
Explanation
An Application Group is a static, manually defined collection of specific named applications (e.g., gmail, outlook-web, yahoo-mail). This is the right choice when you want to allow or deny a precise set of applications. An Application Filter is dynamic and matches applications based on attributes like category or subcategory - filtering on 'email' subcategory would capture all current and future applications in that subcategory, which may be too broad if the goal is to restrict to only specific approved email apps. For restriction to specific applications, the Application Group provides the necessary precision.
Topics
Community Discussion
No community discussion yet for this question.