Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy
A network administrator needs to ensure that only approved applications can traverse the firewall, regardless of the port or protocol they attempt to use. Which security policy action is most effective for achieving this goal while preventing unknown or unapproved applications?
- ADrop
- BReset-Server
- CAllow
- DDeny
Show answer & explanationAnswer & explanation
Correct answer: A. Drop
The 'Drop' action silently discards traffic without sending a response to the sender, effectively blocking unwanted applications without revealing the firewall's presence or the reason for the block. This is ideal for preventing unknown applications from traversing the firewall.
Why the other options are wrong
- B. Reset-Server sends a TCP RST from the firewall to the server, indicating a refusal to connect.
- C. Allow permits the traffic, which is contrary to preventing unapproved applications.
- D. Deny sends a TCP RST or ICMP unreachable, which informs the sender of the block.
Security Policy Action: Drop
The 'Drop' action in a Palo Alto Networks security policy silently discards traffic without sending any notification to the sender or receiver.
- Traffic is discarded without a response (no TCP RST or ICMP unreachable).
- Effective for silently blocking unwanted traffic and preventing port scanning.
- Does not reveal the presence of the firewall to the sender.
Memory trick: Always choose the silent 'Drop' to make unwanted traffic stop.