Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium

A network security engineer is designing a security policy to allow internal users to access an external SaaS application. The application uses a dynamic set of IP addresses and well-known ports (HTTP/HTTPS). To ensure the policy remains accurate and requires minimal maintenance as the application's infrastructure changes, what is the most appropriate object type to use for the destination in the security policy rule?

  1. AIP Address Range Object
  2. BService Object
  3. CIP Address Object
  4. DFQDN Address Object
Show answer & explanation

Correct answer: D. FQDN Address Object

An FQDN Address Object is the most appropriate choice. It allows the firewall to resolve the application's domain name (e.g., 'saasapp.com') to its current IP addresses dynamically. This ensures the policy remains effective even if the application's underlying IP infrastructure changes, minimizing manual updates.

Why the other options are wrong

  • A. An IP Address Range Object is also static and would require frequent updates if the application's IP ranges change.
  • B. A Service Object defines the port and protocol, which is necessary, but it does not address the dynamic IP address requirement for the destination.
  • C. An IP Address Object would require constant manual updates if the SaaS application's IP addresses change.

FQDN Address Object

A Palo Alto Networks firewall object that defines a network destination or source using its Fully Qualified Domain Name (FQDN) instead of a static IP address. The firewall dynamically resolves the FQDN to IP addresses, which is ideal for applications with changing IP infrastructure.

  • Uses FQDN for address definition
  • Dynamically resolves to IP addresses
  • Reduces policy maintenance for dynamic IPs
  • Suitable for cloud/SaaS applications

Memory trick: Addresses: Define who and where for policy enforcement.

More Plan and Design questions