Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A company is implementing a new network segment for IoT devices. The security policy dictates that these devices should only be allowed to communicate with a specific MQTT broker server located in the DMZ, and no other internal or external resources. The IoT devices are in the 'IoT-Zone' and the MQTT broker is in the 'DMZ-Zone'. Which combination of security policy rules and settings would best enforce this requirement?

  1. AOne allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.
  2. BTwo allow rules: 1) Source=IoT-Zone, Destination=DMZ-Zone, Application=any, Service=any, Destination Address=MQTT_Broker_IP. 2) Source=IoT-Zone, Destination=any, Application=MQTT, Service=application-default. Followed by a deny-all rule for IoT-Zone.
  3. COne allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=any. Followed by a deny-all rule for IoT-Zone.
  4. DOne allow rule: Source=any, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.
Show answer & explanation

Correct answer: A. One allow rule: Source=IoT-Zone, Destination=DMZ-Zone, Application=MQTT, Service=application-default, Destination Address=MQTT_Broker_IP. Followed by a deny-all rule for IoT-Zone.

To strictly allow communication only to the specific MQTT broker, the allow rule must specify the IoT-Zone as the source, the DMZ-Zone as the destination, the MQTT application, and crucially, the specific IP address of the MQTT broker. A subsequent deny-all rule for the IoT-Zone ensures no other traffic is permitted.

Why the other options are wrong

  • B. The first rule is too broad (Application=any, Service=any), allowing any traffic to the MQTT broker. The second rule is too broad on destination. This does not meet the 'only communicate with a specific MQTT broker' requirement.
  • C. This rule uses 'Destination Address=any', which would allow IoT devices to communicate with any device in the DMZ-Zone using MQTT, not just the specific broker.
  • D. This rule uses 'Source=any', which would allow any source to communicate with the MQTT broker, not just the IoT devices, and doesn't explicitly restrict IoT devices from reaching other destinations.

Least Privilege Security Policy

A security principle that dictates that a user, program, or process should be given only the minimum privileges necessary to perform its function, often implemented with specific allow rules followed by a general deny rule.

  • Grant only necessary access.
  • Minimize attack surface.
  • Often implemented with specific 'allow' rules and broad 'deny' rules.

Memory trick: IoT rules: Specific Source, Specific Dest, Specific App, Specific IP, then DENY ALL.

More Manage and Operate questions