nerdexam
Palo_Alto_Networks

PCNSE · Question #29

A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the com

The correct answer is A. A report can be created that identifies unclassified traffic on the network. D. Separate Log Forwarding profiles can be applied to rules 2 and 3.. Having separate security rules allows for identifying unclassified traffic and applying distinct logging profiles.

Submitted by yuki_2020· Apr 18, 2026Operate

Question

A company has a policy that denies all applications it classifies as bad and permits only application it classifies as good. The firewall administrator created the following security policy on the company's firewall. Which interface configuration will accept specific VLAN IDs? Which two benefits are gained from having both rule 2 and rule 3 presents? (choose two)

Options

  • AA report can be created that identifies unclassified traffic on the network.
  • BDifferent security profiles can be applied to traffic matching rules 2 and 3.
  • CRule 2 and 3 apply to traffic on different ports.
  • DSeparate Log Forwarding profiles can be applied to rules 2 and 3.

How the community answered

(47 responses)
  • A
    60% (28)
  • B
    28% (13)
  • C
    13% (6)

Why each option

Having separate security rules allows for identifying unclassified traffic and applying distinct logging profiles.

AA report can be created that identifies unclassified traffic on the network.Correct

By having a distinct rule (e.g., Rule 3, a catch-all deny-all) with logging enabled, traffic that doesn't match known applications can be identified and logged as 'unknown' or 'insufficient-data', facilitating reporting on unclassified traffic for App-ID discovery.

BDifferent security profiles can be applied to traffic matching rules 2 and 3.

While different security profiles can be applied to different rules, this is a general capability, and the specific benefit related to identifying unclassified traffic and granular logging is more direct for the scenario.

CRule 2 and 3 apply to traffic on different ports.

Security policy rules are primarily based on applications, not just ports, and the ability to specify ports is a general rule characteristic, not a specific benefit gained by these two rules in this context.

DSeparate Log Forwarding profiles can be applied to rules 2 and 3.Correct

Separate Log Forwarding profiles can be applied to individual rules, allowing administrators to customize where and how logs from 'good' applications (Rule 2) and 'unclassified' traffic (Rule 3) are sent, such as to different syslog servers or with varying severity levels.

Concept tested: Palo Alto Networks Security Policy design and logging

Source: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/app-id/monitor-new-applications-on-your-network

Topics

#Security Policy Management#Logging and Reporting#App-ID#Operational Visibility

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice