Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy

A network architect is designing a new network segment for guest wireless users. These users should only have internet access and be prevented from accessing any internal corporate resources. Which design principle should be applied to the security policy for this segment?

  1. ADeny all, then allow specific internet access.
  2. BAllow all internet traffic, then deny all other traffic.
  3. CUse a default 'permit any-any' rule at the bottom.
  4. DAllow all, then deny specific internal resources.
Show answer & explanation

Correct answer: A. Deny all, then allow specific internet access.

The principle of least privilege dictates that you should deny all traffic by default and then explicitly allow only the necessary traffic. For guest users, this means denying all access first, then specifically allowing internet access.

Why the other options are wrong

  • B. While it achieves the goal, 'Allow all internet traffic' might be too broad if not carefully defined, and 'deny all other traffic' should be the implicit default, not an explicit rule after an 'allow all'.
  • C. A default 'permit any-any' rule is a significant security risk and directly contradicts the principle of least privilege.
  • D. This 'allow then deny' approach is less secure as it creates a larger attack surface by default.

Least Privilege Security Policy

A security principle where users, programs, or processes are granted only the minimum necessary permissions to perform their legitimate functions.

  • Reduces the attack surface.
  • Minimizes the impact of a security breach.
  • Implemented by 'deny all by default' and explicit allow rules.

Memory trick: Close the door, then open a window.

More Plan and Design questions