Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium

A network security engineer is designing a new security policy for a critical application server that processes highly sensitive financial data. The server must only allow inbound connections on TCP port 443 from a specific set of public IP addresses provided by a third-party payment gateway. All other inbound and outbound traffic must be denied. Which two elements are most critical to define in the security policy rule to meet these requirements with the highest level of granularity?

  1. ASource Zone and Destination Zone
  2. BDestination Address and Application
  3. CApplication and Service
  4. DSource Address and Service
Show answer & explanation

Correct answer: D. Source Address and Service

To restrict inbound connections from specific public IP addresses and allow only TCP port 443, the Source Address must be defined for the allowed IPs, and the Service must be explicitly set to 'tcp/443'. This provides the necessary granularity.

Why the other options are wrong

  • A. Source Zone and Destination Zone define network segments but not the specific IP addresses or ports required for this granular control.
  • B. Destination Address is important for the server itself, but Application might not be granular enough for 'TCP port 443' if specific application signatures are not available or desired, and it doesn't control the source of traffic.
  • C. While Application and Service are important, 'Application' alone might be too broad if the specific payment gateway uses a custom application, and 'Service' is only one part of the required restriction.

Security Policy Rule Granularity

Defining security policy rules with specific parameters (source, destination, application, service, user) to allow or deny traffic with the highest precision.

  • Minimizes attack surface by allowing only essential traffic.
  • Reduces the risk of unauthorized access.
  • Requires detailed understanding of application and network flows.

Memory trick: Specific Sources, Destinations, Apps, and Services make a secure tapestry.

More Plan and Design questions