ExamGecko
Question list
Search
Search

Question 203 - PCNSA discussion

Report
Export

The compliance officer requests that all evasive applications need to be blocked on all perimeter firewalls out to the internet The firewall is configured with two zones; 1. trust for internal networks 2. untrust to the internet Based on the capabilities of the Palo Alto Networks NGFW, what are two ways to configure a security policy using App-ID to comply with this request? (Choose two )

A.
Create a deny rule at the top of the policy from trust to untrust over any service and select evasive as the application
Answers
A.
Create a deny rule at the top of the policy from trust to untrust over any service and select evasive as the application
B.
Create a deny rule at the top of the policy from trust to untrust with service application-default and select evasive as the application.
Answers
B.
Create a deny rule at the top of the policy from trust to untrust with service application-default and select evasive as the application.
C.
Create a deny rule at the top of the policy from trust to untrust over any service and add an application filter with the evasive characteristic.
Answers
C.
Create a deny rule at the top of the policy from trust to untrust over any service and add an application filter with the evasive characteristic.
D.
Create a deny rule at the top of the policy from trust to untrust with service application-default and add an application filter with the evasive characteristic
Answers
D.
Create a deny rule at the top of the policy from trust to untrust with service application-default and add an application filter with the evasive characteristic
Suggested answer: A, D
asked 23/09/2024
Sonjoy Kanwal
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first