Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy
A network security engineer is designing a new security policy for a critical application server that only allows specific services. The application server resides in the 'DMZ' zone and needs to be accessed by users in the 'Internal' zone. The security policy should be as granular as possible, permitting only HTTP and HTTPS traffic on their standard ports. Which of the following policy configurations best meets this requirement?
- ASource Zone: Internal, Destination Zone: DMZ, Application: any, Service: application-default, Action: Allow
- BSource Zone: Internal, Destination Zone: DMZ, Application: any, Service: tcp/80, tcp/443, Action: Allow
- CSource Zone: Internal, Destination Zone: DMZ, Application: web-browsing, Service: service-http, service-https, Action: Allow
- DSource Zone: Internal, Destination Zone: DMZ, Application: web-browsing, Service: application-default, Action: Allow
Show answer & explanationAnswer & explanation
Correct answer: C. Source Zone: Internal, Destination Zone: DMZ, Application: web-browsing, Service: service-http, service-https, Action: Allow
To meet the requirement of allowing only HTTP and HTTPS traffic on their standard ports, the best practice is to specify the application as 'web-browsing' and the services as 'service-http' and 'service-https'. This ensures that the policy uses application identification for better security and also restricts the services to the standard ports.
Why the other options are wrong
- A. Using 'any' for application and 'application-default' for service is too broad and does not meet the granularity requirement for specific services.
- B. Using 'any' for application is less secure than using application identification, even if the ports are specified.
- D. Using 'application-default' for service allows any port if the application is identified, which is less granular than specifying standard ports.
Granular Security Policy
A granular security policy restricts traffic based on specific applications, services, users, and zones, adhering to the principle of least privilege.
- Uses App-ID for application identification.
- Specifies exact services and ports.
- Limits source and destination zones/users/IPs.
Memory trick: Granular policies always 'APP'ly the 'SERVICE' to the 'ZONE' for the 'ACTION'.