SSE-ENGINEER · Question #45
An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users…
The correct answer is D. The rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule. Prisma Access applies security rules in a hierarchical order, where rules at higher levels take precedence over those at lower levels. If a more permissive rule is placed higher in the hierarchy, it may allow traffic before the restrictive Web Security rule is evaluated. To…
Question
An engineer has configured a Web Security rule that restricts access to certain web applications for a specific user group. During testing, the rule does not take effect as expected, and the users can still access blocked web applications. What is a reason for this issue?
Options
- AThe rule was created with improper threat management settings.
- BThe rule was created in the wrong scope, affecting only GlobalProtect users instead of all users.
- CThe rule was created at a higher level in the rule hierarchy, giving priority to a lower-level rule.
- DThe rule was created at a lower level in the rule hierarchy, giving priority to a higher-level rule.
How the community answered
(21 responses)- A33% (7)
- B14% (3)
- C5% (1)
- D48% (10)
Explanation
Prisma Access applies security rules in a hierarchical order, where rules at higher levels take precedence over those at lower levels. If a more permissive rule is placed higher in the hierarchy, it may allow traffic before the restrictive Web Security rule is evaluated. To resolve this, the engineer should reorder the rules to ensure the restrictive Web Security rule is positioned higher in the hierarchy so it is applied before any broader or conflicting rules.
Topics
Community Discussion
No community discussion yet for this question.