Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A network engineer is configuring a firewall to block all traffic originating from a specific range of IP addresses known to be associated with malicious activity. Which of the following firewall rule components would be used to define this source of traffic?
- ADestination Port
- BSource IP Address
- CSource Zone
- DService
Show answer & explanationAnswer & explanation
Correct answer: B. Source IP Address
To block traffic 'originating from a specific range of IP addresses', the firewall rule must specify the 'Source IP Address' as the criterion for matching and blocking.
Why the other options are wrong
- A. Destination Port defines the service the traffic is trying to reach, not its origin.
- C. Source Zone defines the logical network segment the traffic is coming from, which is broader than specific IP ranges.
- D. Service defines the application protocol (e.g., HTTP, FTP), not the source IP.
Firewall Rule Components
The individual criteria or parameters that define how a firewall processes network traffic, determining whether to permit or deny it.
- Typically include Source/Destination IP, Source/Destination Port, Protocol.
- Can also include User, Application, URL, Time, and Action.
- Rules are processed in order, from top to bottom.
- A 'deny all' implicit rule is usually at the bottom.
Memory trick: Firewall rules are like bouncers at a club: they check IDs, what you're doing, and where you're going.