nerdexam
Palo_Alto_Networks

PCNSC · Question #63

A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny". Which action will this configuration cause on the matched traffic?

The correct answer is D. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured. "Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/security-profiles.html#

Security Policy and Application Identification

Question

A Security policy rule is configured with a Vulnerability Protection Profile and an action of Deny". Which action will this configuration cause on the matched traffic?

Options

  • AThe configuration is invalid. The Profile Settings section will be grayed out when the Action is set
  • BThe configuration will allow the matched session unless a vulnerability is detected. The "Deny"
  • CThe configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will
  • DThe configuration is valid. It will cause the firewall to deny the matched sessions. Any configured

How the community answered

(15 responses)
  • B
    13% (2)
  • C
    7% (1)
  • D
    80% (12)

Explanation

"Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/policy/security-profiles.html#

Topics

#Security policy#Vulnerability Protection Profile#deny action#profile interaction

Community Discussion

No community discussion yet for this question.

Full PCNSC Practice