PCNSC · Question #63
A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny". Which action will this configuration cause on the matched traffic?
The correct answer is D. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured. "Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/security-profiles.html#
Question
A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny". Which action will this configuration cause on the matched traffic?
Options
- AThe configuration is invalid. The Profile Settings section will be grayed out when the Action is set
- BThe configuration will allow the matched session unless a vulnerability is detected. The "Deny"
- CThe configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will
- DThe configuration is valid. It will cause the firewall to deny the matched sessions. Any configured
How the community answered
(15 responses)- B13% (2)
- C7% (1)
- D80% (12)
Explanation
"Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/security-profiles.html#
Topics
Community Discussion
No community discussion yet for this question.