Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A network security administrator is configuring a new Palo Alto Networks firewall and is setting up a security policy rule. The administrator wants to ensure that specific applications, such as 'facebook-base' and 'youtube-base', are allowed, but only during business hours. Which of the following components should be configured in the security policy rule to achieve this granular control?

  1. AService/URL Category
  2. BUser-ID/User Group
  3. CApplication/Application Group
  4. DZone/Interface
Show answer & explanation

Correct answer: C. Application/Application Group

To control traffic based on specific applications like 'facebook-base' and 'youtube-base', the 'Application' or 'Application Group' component within the security policy rule must be used. This allows for granular control over application usage.

Why the other options are wrong

  • A. Service/URL Category is used for port-based control or web filtering, not specific application identification.
  • B. User-ID/User Group is used to identify and control traffic based on users or user groups, not applications.
  • D. Zone/Interface defines the ingress and egress points for traffic, not the application itself.

Palo Alto Networks Application-ID

Application-ID is a core technology in Palo Alto Networks firewalls that accurately identifies applications traversing the network, regardless of port, protocol, evasive techniques, or encryption.

  • Identifies applications using multiple techniques (signatures, decryption, protocol decoding).
  • Enables granular policy control based on actual application usage.
  • Continuously updated through content and threat updates.

Memory trick: Applications are the 'App'le of the Firewall's eye for granular control.

More Core Concepts questions