PCNSA · Question #382
Which statement applies to the Intrazone Security policy rule?
The correct answer is D. It applies to all matching traffic within the specified source security zones.. An Intrazone Security policy rule governs traffic flow between interfaces that are assigned to the same security zone, applying to all matching traffic within the specified source security zones.
Question
Which statement applies to the Intrazone Security policy rule?
Options
- AThe traffic within the same security zone will not be allowed.
- BIt requires a Zone Protection profile to be applied.
- CIt applies regardless of whether it is from the same security zone or a different one.
- DIt applies to all matching traffic within the specified source security zones.
How the community answered
(66 responses)- A3% (2)
- B6% (4)
- C2% (1)
- D89% (59)
Why each option
An Intrazone Security policy rule governs traffic flow between interfaces that are assigned to the same security zone, applying to all matching traffic within the specified source security zones.
By default, traffic within the same security zone *is* allowed; an intrazone rule can be used to deny it, but the statement 'will not be allowed' is not universally true.
Zone Protection profiles protect the zone from various attacks (e.g., flood attacks), but they are not a prerequisite for or directly linked to the application of Intrazone Security policy rules.
This statement describes an interzone policy rule, which applies to traffic *between* different security zones, not an intrazone rule.
An Intrazone Security policy rule explicitly applies to traffic that originates from and is destined for the same security zone, affecting all traffic that matches the criteria within that specified zone. By default, intrazone traffic is allowed unless explicitly denied by an intrazone policy.
Concept tested: Intrazone security policy rule application
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rules.html
Topics
Community Discussion
No community discussion yet for this question.