Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A company is deploying a new application server in their DMZ and needs to ensure that only specific applications, such as HTTPS and SSH for management, are allowed to access it from the untrusted (Internet) zone. Which security policy configuration element should be used to precisely define the allowed applications?
- AApplication Object
- BApplication Filter
- CService Object
- DApplication Group
Show answer & explanationAnswer & explanation
Correct answer: A. Application Object
An Application Object (or 'application' field in a security policy rule) is used to explicitly specify which applications are allowed or denied based on Palo Alto Networks' App-ID technology, ensuring precise control over traffic regardless of the port used.
Why the other options are wrong
- B. Application Filters are dynamic queries for applications based on characteristics, not direct selection of specific applications for a rule.
- C. Service Objects define protocols and ports (e.g., TCP/443), but App-ID is more granular and protocol-aware.
- D. Application Groups are collections of Application Objects, useful for simplifying policies, but the fundamental element for defining 'HTTPS' or 'SSH' is the Application Object.
Application Object (App-ID)
An Application Object, powered by App-ID, represents a specific application recognized by the Palo Alto Networks firewall, allowing security policies to be based on actual application identity rather than just ports and protocols.
- Identifies applications regardless of port.
- Provides granular control over traffic.
- Used in security policy rules to permit or deny applications.
Memory trick: The 'Application Object' is the magnifying glass for specific traffic types.