PCNSE · Question #29
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the com
The correct answer is A. A report can be created that identifies unclassified traffic on the network. D. Separate Log Forwarding profiles can be applied to rules 2 and 3.. Having separate security rules allows for identifying unclassified traffic and applying distinct logging profiles.
Question
A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's firewall. Which interface configuration will accept specific VLAN IDs? Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)
Options
- AA report can be created that identifies unclassified traffic on the network.
- BDifferent security profiles can be applied to traffic matching rules 2 and 3.
- CRule 2 and 3 apply to traffic on different ports.
- DSeparate Log Forwarding profiles can be applied to rules 2 and 3.
How the community answered
(47 responses)- A60% (28)
- B28% (13)
- C13% (6)
Why each option
Having separate security rules allows for identifying unclassified traffic and applying distinct logging profiles.
By having a distinct rule (e.g., Rule 3, a catch-all deny-all) with logging enabled, traffic that doesn't match known applications can be identified and logged as 'unknown' or 'insufficient-data', facilitating reporting on unclassified traffic for App-ID discovery.
While different security profiles can be applied to different rules, this is a general capability, and the specific benefit related to identifying unclassified traffic and granular logging is more direct for the scenario.
Security policy rules are primarily based on applications, not just ports, and the ability to specify ports is a general rule characteristic, not a specific benefit gained by these two rules in this context.
Separate Log Forwarding profiles can be applied to individual rules, allowing administrators to customize where and how logs from 'good' applications (Rule 2) and 'unclassified' traffic (Rule 3) are sent, such as to different syslog servers or with varying severity levels.
Concept tested: Palo Alto Networks Security Policy design and logging
Source: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/app-id/monitor-new-applications-on-your-network
Topics
Community Discussion
No community discussion yet for this question.