PCNSA · Question #418
all other sites in the same category. Which object should the administrator create to use as a match condition for the security policy
The correct answer is C. URL category. URL Category lets a security policy match traffic based on the content classification of the destination site - so blocking one gambling site automatically blocks all sites Palo Alto's URL filtering database classifies as "gambling," without needing to enumerate individual…
Question
all other sites in the same category. Which object should the administrator create to use as a match condition for the security policy
Options
- AService
- BAddress
- CURL category
- DApplication group
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C86% (24)
- D4% (1)
Explanation
URL Category lets a security policy match traffic based on the content classification of the destination site - so blocking one gambling site automatically blocks all sites Palo Alto's URL filtering database classifies as "gambling," without needing to enumerate individual addresses.
- A (Service) is wrong because Service objects match on protocol/port (e.g., TCP/443), not site content or category.
- B (Address) is wrong because Address objects match specific IPs or FQDNs - you'd have to manually list every gambling site, which defeats the purpose.
- D (Application group) is wrong because Application groups match by application signature (e.g., "web-browsing," "ssl"), not by the content category of the destination.
Memory tip: Think "URL Category = content classification bucket." When the requirement says "this site and all others like it," that's a category-level match - only URL Category covers the whole bucket automatically.
Topics
Community Discussion
No community discussion yet for this question.