PCNSA · Question #94
Based on the shown security policy, which Security policy rule would match all FTP traffic from the inside zone to the outside zone?
The correct answer is B. engress outside. To match all FTP traffic originating from the "inside" zone and destined for the "outside" zone, the security policy rule named "engress outside" is the most appropriate choice.
Question
Based on the shown security policy, which Security policy rule would match all FTP traffic from the inside zone to the outside zone?
Exhibit
Options
- Ainternal-inside-dmz
- Bengress outside
- Cinside-portal
- Dinterzone-default
How the community answered
(45 responses)- A2% (1)
- B87% (39)
- C9% (4)
- D2% (1)
Why each option
To match all FTP traffic originating from the "inside" zone and destined for the "outside" zone, the security policy rule named "engress outside" is the most appropriate choice.
"internal-inside-dmz" implies traffic flow between an internal zone and a DMZ, not to an outside zone.
A rule named "engress outside" typically implies traffic exiting the internal network. Given the requirement for FTP traffic from the "inside" zone to the "outside" zone, this rule explicitly matches the source and destination zones and would be configured to allow FTP application traffic.
"inside-portal" suggests traffic related to a portal from the inside zone, which doesn't directly correspond to general FTP traffic to an outside zone.
"interzone-default" is typically a default rule that might catch traffic not explicitly matched by others, but it wouldn't be the specific rule tailored for "all FTP traffic" from inside to outside.
Concept tested: Palo Alto Networks Security Policy Rule Matching and Traffic Flow
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rules-overview
Topics
Community Discussion
No community discussion yet for this question.
