Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy

A company is deploying a new web application and requires granular control over traffic based on the specific application being used, rather than just ports and protocols. They need to ensure only approved applications can access the web server. Which Palo Alto Networks firewall feature allows for this application-level control?

  1. AZone-based security policy
  2. BApplication-based security policy
  3. CPort-based security policy
  4. DService-based security policy
Show answer & explanation

Correct answer: B. Application-based security policy

Application-based security policy, utilizing App-ID, allows the firewall to identify and control applications regardless of the port or protocol they use, providing granular control.

Why the other options are wrong

  • A. Zone-based policies define security perimeters but do not provide application-level granularity within those zones.
  • C. Port-based policies are the most basic form of control and are insufficient for identifying specific applications.
  • D. Service-based policies rely on traditional port and protocol numbers, which can be easily bypassed by evasive applications.

App-ID

A Palo Alto Networks technology that identifies applications traversing the firewall, regardless of port, protocol, or evasive tactics.

  • Enables application-based security policies.
  • Uses multiple classification mechanisms (signatures, decryption, heuristics).
  • Provides granular control over application usage.
  • Continuously updated through content updates.

Memory trick: App-ID's eye, never lets an unauthorized byte fly!

More Deploy and Configure questions