Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy
A company is integrating a new cloud-based HR application. The application developers require outbound access from their internal network to specific FQDNs for API calls and updates. The network security team needs to ensure that only traffic destined for these FQDNs is allowed, and no direct IP address access, as the cloud provider's IPs may change frequently. Which type of object should be used in the security policy to achieve this granular control?
- ADynamic Address Group
- BIP Address Object
- CAddress Group
- DFQDN Address Object
Show answer & explanationAnswer & explanation
Correct answer: D. FQDN Address Object
An FQDN Address Object allows you to specify destinations using their fully qualified domain names. This is crucial when IP addresses are dynamic or unknown, ensuring that policy enforcement remains effective even if the underlying IP addresses change, precisely matching the requirement for cloud-based services.
Why the other options are wrong
- A. Dynamic Address Groups are primarily used for tagging based on virtual machine attributes in virtualized environments, not directly for FQDN resolution in security policies for outbound access.
- B. IP Address Objects are static and not suitable for dynamic cloud IPs.
- C. Address Groups combine static IP Address Objects or other Address Groups, still not dynamic by FQDN.
FQDN Address Object
An FQDN Address Object in Palo Alto Networks firewalls resolves a Fully Qualified Domain Name to its corresponding IP address(es) dynamically for use in security policies.
- Uses DNS resolution to determine IP addresses.
- Automatically updates when DNS records change.
- Essential for controlling access to cloud services or hosts with dynamic IP addresses.
Memory trick: FQDN Address Objects are the best for dynamic cloud connections.