Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A network administrator is configuring a new firewall and needs to block all traffic originating from a specific range of IP addresses known to be associated with malicious activity. Which firewall rule component would be used to define this source?

  1. ADestination Zone
  2. BApplication
  3. CService
  4. DSource Address
Show answer & explanation

Correct answer: D. Source Address

In firewall rules, the 'Source Address' component specifies the origin IP addresses or networks from which traffic is either allowed or denied.

Why the other options are wrong

  • A. Destination Zone defines the network segment or zone the traffic is intended for.
  • B. Application specifies the type of application or protocol the traffic belongs to (e.g., HTTP, FTP).
  • C. Service specifies the port and protocol used by the traffic (e.g., TCP port 80 for HTTP).

Firewall Rule Components

Firewall rules are sets of instructions that specify what traffic is allowed or denied based on various criteria, including source, destination, application, and service.

  • Evaluate traffic against defined criteria.
  • Typically processed in order from top to bottom.
  • An implicit 'deny all' is often the last rule.

Memory trick: Firewalls use zones, addresses, apps, and services to direct traffic.

More Cybersecurity Fundamentals questions