PSE-STRATA · Question #77
What is a best practice when configuring a security policy to completely block a specific application?
The correct answer is A. One the Service/URL. Category tab, set the service to any. Any: This option covers all ports from 1 to 65535, whether they use TCP or UDP protocol. When you choose this option, the selected applications will be allowed or denied on any protocol or port. Application-Default: this means that the selected applications will be allowed or…
Question
What is a best practice when configuring a security policy to completely block a specific application?
Options
- AOne the Service/URL. Category tab, set the service to any
- BOn the Actions tab, configure a file blocking security profile
- COn the Service/URL. Category tab, set the service to application-default
- DOn the Service/URL. Category tab, manually specify a port/service
How the community answered
(14 responses)- A79% (11)
- C14% (2)
- D7% (1)
Explanation
Any: This option covers all ports from 1 to 65535, whether they use TCP or UDP protocol. When you choose this option, the selected applications will be allowed or denied on any protocol or port. Application-Default: this means that the selected applications will be allowed or denied only on their default ports as defined by Palo Alto Networks. This option is recommended for allow policies because it prevents applications from running on unusual ports and protocols. If an application tries to use a port or protocol other than its default, it could indicate unexpected behavior or unauthorized usage. That way, this option helps maintain control and security.
Topics
Community Discussion
No community discussion yet for this question.