ExamGecko
Question list
Search
Search

Question 349 - PCNSA discussion

Report
Export

What Policy Optimizer policy view differ from the Security policy do?

A.
It shows rules that are missing Security profile configurations.
Answers
A.
It shows rules that are missing Security profile configurations.
B.
It indicates rules with App-ID that are not configured as port-based.
Answers
B.
It indicates rules with App-ID that are not configured as port-based.
C.
It shows rules with the same Source Zones and Destination Zones.
Answers
C.
It shows rules with the same Source Zones and Destination Zones.
D.
It indicates that a broader rule matching the criteria is configured above a more specific rule.
Answers
D.
It indicates that a broader rule matching the criteria is configured above a more specific rule.
Suggested answer: B

Explanation:

Policy Optimizer policy view differs from the Security policy view in several ways. One of them is that it indicates rules with App-ID that are not configured as port-based. These are rules that have the application set to ''any'' instead of a specific application or group of applications. These rules are overly permissive and can introduce security gaps, as they allow any application traffic on the specified ports.Policy Optimizer helps you convert these rules to application-based rules that follow the principle of least privilege access12.You can use Policy Optimizer to discover and convert port-based rules to application-based rules, and also to remove unused applications, eliminate unused rules, and discover new applications that match your policy criteria3.Reference:

Policy Optimizer Best Practices - Palo Alto Networks

Manage: Policy Optimizer - Palo Alto Networks | TechDocs

Why use Security Policy Optimizer and what are the benefits?

asked 23/09/2024
Geoffrey Vd Molen
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first