Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy
A network security administrator is configuring a new Palo Alto Networks firewall and is setting up a security policy rule. The administrator wants to ensure that specific applications, such as 'facebook-base' and 'youtube-base', are allowed, but only during business hours. Which of the following components should be configured in the security policy rule to achieve this granular control?
- AService/URL Category
- BUser-ID/User Group
- CApplication/Application Group
- DZone/Interface
Show answer & explanationAnswer & explanation
Correct answer: C. Application/Application Group
To control traffic based on specific applications like 'facebook-base' and 'youtube-base', the 'Application' or 'Application Group' component within the security policy rule must be used. This allows for granular control over application usage.
Why the other options are wrong
- A. Service/URL Category is used for port-based control or web filtering, not specific application identification.
- B. User-ID/User Group is used to identify and control traffic based on users or user groups, not applications.
- D. Zone/Interface defines the ingress and egress points for traffic, not the application itself.
Palo Alto Networks Application-ID
Application-ID is a core technology in Palo Alto Networks firewalls that accurately identifies applications traversing the network, regardless of port, protocol, evasive techniques, or encryption.
- Identifies applications using multiple techniques (signatures, decryption, protocol decoding).
- Enables granular policy control based on actual application usage.
- Continuously updated through content and threat updates.
Memory trick: Applications are the 'App'le of the Firewall's eye for granular control.