PCNSE · Question #773
Which two items must be configured when implementing application override and allowing traffic through the firewall? (Choose two.)
The correct answer is B. Application override policy rule C. Security policy rule. Implementing application override requires both an application override policy rule to reclassify traffic and a security policy rule to permit the newly classified traffic.
Question
Which two items must be configured when implementing application override and allowing traffic through the firewall? (Choose two.)
Options
- AApplication filter
- BApplication override policy rule
- CSecurity policy rule
- DCustom app
How the community answered
(50 responses)- A10% (5)
- B84% (42)
- D6% (3)
Why each option
Implementing application override requires both an application override policy rule to reclassify traffic and a security policy rule to permit the newly classified traffic.
Application filters are used to group applications for use in security policies, but they are not a mandatory configuration element for the act of *implementing* an application override itself.
An application override policy rule is necessary to instruct the firewall to identify specific traffic (based on port and protocol) as a particular application, overriding App-ID's default classification. This forces a specific application interpretation.
Even after an application override rule reclassifies traffic, a corresponding security policy rule is still required to explicitly allow the traffic identified by the overridden application. The security policy acts on the application identity to permit or deny the flow.
While a custom application might be used as the target for an override if a standard application doesn't fit, it's not strictly *required* for every application override scenario; you can override to an existing application.
Concept tested: Application override configuration requirements
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/application-override.html
Topics
Community Discussion
No community discussion yet for this question.