Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium

A network architect is designing a security policy for a web application hosted on a server in the 'DMZ' zone. The application needs to access a specific database server in the 'DB' zone. The policy must strictly adhere to the principle of least privilege, allowing only the necessary application and port. Which security policy configuration best embodies the principle of least privilege for this communication?

  1. ASource Zone: DMZ, Destination Zone: DB, Application: mysql, Service: application-default, Action: Allow
  2. BSource Zone: DMZ, Destination Zone: DB, Application: any, Service: application-default, Action: Allow
  3. CSource Zone: DMZ, Destination Zone: DB, Application: web-browsing, Service: tcp/3306, Action: Allow
  4. DSource Zone: DMZ, Destination Zone: DB, Application: any, Service: any, Action: Allow
Show answer & explanation

Correct answer: A. Source Zone: DMZ, Destination Zone: DB, Application: mysql, Service: application-default, Action: Allow

The principle of least privilege dictates that only the absolutely necessary access is granted. For a web application accessing a MySQL database, identifying the specific application as 'mysql' and using 'application-default' for the service ensures that only MySQL traffic is allowed, and on its standard port (3306) if not overridden, without opening up broader access.

Why the other options are wrong

  • B. Using 'any' for application is too broad and violates least privilege.
  • C. Using 'web-browsing' for a database connection is incorrect application identification and 'tcp/3306' is a port, not the application-default service for MySQL.
  • D. Using 'any' for both application and service is the antithesis of the principle of least privilege, granting maximum access.

Least Privilege Security Policy

A least privilege security policy grants only the minimum necessary access rights or permissions to a user, process, or program, reducing the attack surface and potential damage from compromise.

  • Uses App-ID for specific applications.
  • Specifies exact services/ports when needed.
  • Limits source/destination zones, addresses, and users.
  • Denies all other traffic by default.

Memory trick: Least privilege: 'ONLY' the 'ESSENTIAL' 'APP' and 'SERVICE'.

More Plan and Design questions