Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignHard
An organization is deploying a Palo Alto Networks firewall to protect a demilitarized zone (DMZ) containing web servers and application servers. The security policy design requires that specific web applications (e.g., 'web-browsing', 'ssl') are allowed from the internet to the web servers, but only 'ms-rdp' and 'ssh' are allowed from a jump host in the management zone to the application servers. All other traffic should be denied. What is the most effective approach to structure these security policies?
- ACreate specific allow rules for each required application and zone pair, followed by a final deny-all rule.
- BUse application groups to combine all allowed applications into one group for all traffic flows.
- CConfigure a default allow policy for all zones and rely on threat prevention profiles to block unwanted applications.
- DCreate a single policy rule allowing all traffic from the internet to the DMZ and then use a block rule for specific applications.
Show answer & explanationAnswer & explanation
Correct answer: A. Create specific allow rules for each required application and zone pair, followed by a final deny-all rule.
The most effective and secure approach is to create specific allow rules for each required application and zone pair, followed by a final deny-all rule. This implements a 'least privilege' model, ensuring only explicitly permitted traffic flows, which is a fundamental security best practice.
Why the other options are wrong
- B. While application groups can simplify policy management, combining all allowed applications into one group for all traffic flows would violate the principle of least privilege by over-permitting access between zones.
- C. Relying solely on threat prevention profiles for blocking unwanted applications is insufficient; security policies define what traffic is allowed to be inspected in the first place.
- D. Allowing all traffic initially and then blocking specific applications is a 'default allow' model, which is less secure and harder to manage than a 'default deny' approach.
Security Policy Best Practice (Least Privilege)
The principle of granting only the necessary permissions or access to users, programs, or processes to perform their required tasks. In firewall policy design, this translates to explicitly allowing only required traffic and implicitly denying everything else.
- Explicitly allow necessary traffic
- Implicitly deny all other traffic
- Enhances security posture
- Reduces attack surface
Memory trick: Policies: Define what's allowed, deny the rest.