Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A company is concerned about employees installing unauthorized applications that consume excessive bandwidth and pose security risks. The IT department wants to implement a solution that identifies and controls specific applications, regardless of the port or protocol they use, to enforce corporate usage policies. What network security technology is best suited for this requirement?

  1. AVirtual Private Network (VPN)
  2. BPort-based Firewall
  3. CApplication Control
  4. DIntrusion Detection System (IDS)
Show answer & explanation

Correct answer: C. Application Control

Application Control technology identifies and manages specific applications based on their unique signatures, rather than just port numbers, allowing granular control over application usage and preventing unauthorized software.

Why the other options are wrong

  • A. VPNs provide secure remote access or site-to-site connectivity but do not control individual application usage within the network.
  • B. Port-based firewalls only block or allow traffic based on port numbers, which can be easily bypassed by applications using non-standard ports.
  • D. IDS monitors for malicious activity but doesn't actively prevent or control application usage based on policy.

Application Control

A network security feature that identifies and manages specific applications, regardless of the port or protocol used, to enforce security policies.

  • Goes beyond port/protocol-based filtering.
  • Allows granular control (allow, block, limit bandwidth) over applications.
  • Often integrated into Next-Generation Firewalls (NGFWs).

Memory trick: Application Control: A specific app, a specific rule.

More Network Security questions