PCNSA · Question #369
An administrator would like to block traffic to all high risk audio streaming applications, including new App-IDs introduced with content updates. Which filter should the administrator configure in…
The correct answer is C. The subcategory is audio-streaming, and the risk is 5. To block high-risk audio streaming applications including future App-IDs, an administrator should create an application filter based on the subcategory "audio-streaming" and a risk level of "5".
Question
An administrator would like to block traffic to all high risk audio streaming applications, including new App-IDs introduced with content updates. Which filter should the administrator configure in the application filter object?
Options
- AThe category is media, and the characteristic includes Evasive.
- BThe subcategory is audio-streaming, and the risk is 1.
- CThe subcategory is audio-streaming, and the risk is 5.
- DThe category is media, and the tag is high risk.
How the community answered
(26 responses)- A8% (2)
- B12% (3)
- C77% (20)
- D4% (1)
Why each option
To block high-risk audio streaming applications including future App-IDs, an administrator should create an application filter based on the subcategory "audio-streaming" and a risk level of "5".
While "media" is a category, "Evasive" is a characteristic, not a risk level that would encompass all high-risk applications; this filter is too broad by category and too specific by characteristic.
A risk level of 1 typically indicates very low risk, not high risk, which is the opposite of the administrator's goal.
To block all high-risk audio streaming applications, including those newly introduced via content updates, the most effective filter combines the "subcategory is audio-streaming" with "risk is 5". Subcategory targets the specific type of application, and a risk level of 5 indicates the highest risk, ensuring that existing and future high-risk audio streaming applications are included.
While "media" is a category, "tag is high risk" is not a standard built-in filter option for App-ID risk classification; risk is a numerical value (1-5), not a tag.
Concept tested: Application filter configuration (App-ID, risk, subcategory)
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/use-application-filters.html
Topics
Community Discussion
No community discussion yet for this question.