Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium
A network administrator is configuring a new firewall for a data center. The policy states that all incoming and outgoing network traffic must be explicitly allowed; anything not specifically permitted will be blocked by default. Which firewall policy approach is being implemented?
- ADefault Open
- BPermissive Filtering
- CImplicit Allow
- DImplicit Deny
Show answer & explanationAnswer & explanation
Correct answer: D. Implicit Deny
The policy stating that 'anything not specifically permitted will be blocked by default' is the definition of an implicit deny rule, a fundamental principle of secure firewall configurations.
Why the other options are wrong
- A. Default Open is another term for Implicit Allow, which is less secure.
- B. Permissive Filtering implies a more open policy, allowing more traffic by default.
- C. Implicit Allow means that unless explicitly blocked, traffic is allowed, which is the opposite of the scenario.
Implicit Deny
A fundamental security principle in firewalls and access control lists (ACLs) where any traffic or access not explicitly permitted by a rule is automatically blocked.
- Considered a security best practice.
- Reduces the attack surface by only allowing necessary traffic.
- Often the last rule in a firewall's rule set.
Memory trick: What's not allowed, is denied by default.