Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A network engineer is configuring a firewall to block all traffic originating from a specific range of IP addresses known to be associated with malicious activity. Which of the following firewall rule components would be used to define this source of traffic?

  1. ADestination Port
  2. BSource IP Address
  3. CSource Zone
  4. DService
Show answer & explanation

Correct answer: B. Source IP Address

To block traffic 'originating from a specific range of IP addresses', the firewall rule must specify the 'Source IP Address' as the criterion for matching and blocking.

Why the other options are wrong

  • A. Destination Port defines the service the traffic is trying to reach, not its origin.
  • C. Source Zone defines the logical network segment the traffic is coming from, which is broader than specific IP ranges.
  • D. Service defines the application protocol (e.g., HTTP, FTP), not the source IP.

Firewall Rule Components

The individual criteria or parameters that define how a firewall processes network traffic, determining whether to permit or deny it.

  • Typically include Source/Destination IP, Source/Destination Port, Protocol.
  • Can also include User, Application, URL, Time, and Action.
  • Rules are processed in order, from top to bottom.
  • A 'deny all' implicit rule is usually at the bottom.

Memory trick: Firewall rules are like bouncers at a club: they check IDs, what you're doing, and where you're going.

More Network Security questions