SSE-ENGINEER · Question #4
An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch t
The correct answer is D. The traffic is matching a Security policy in the Prisma Access configuration scope.. In Prisma Access, security policies are evaluated based on their configuration scope. If the engineer configured a Security policy under the Remote Networks scope, but traffic from the branch locations is instead matching a Security policy under the Prisma Access configuration sc
Question
An engineer configures a Security policy for traffic originating at branch locations in the Remote Networks configuration scope. After committing the configuration and reviewing the logs, the branch traffic is not matching the Security policy. Which statement explains the branch traffic behavior?
Options
- AThe source address was configured with an address object including the branch location prefixes.
- BThe source zone was configured as "Trust."
- CThe Security policy did not meet best practice standards and was automatically removed.
- DThe traffic is matching a Security policy in the Prisma Access configuration scope.
How the community answered
(37 responses)- A5% (2)
- B3% (1)
- C16% (6)
- D76% (28)
Explanation
In Prisma Access, security policies are evaluated based on their configuration scope. If the engineer configured a Security policy under the Remote Networks scope, but traffic from the branch locations is instead matching a Security policy under the Prisma Access configuration scope, the intended policy will not take effect. This happens because Prisma Access evaluates security rules based on the highest-level applicable configuration first, which can override more specific Remote Networks policies.
Topics
Community Discussion
No community discussion yet for this question.