Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A company requires that all outbound web traffic from the internal network to the internet must be inspected for threats. Due to compliance regulations, only traffic that uses standard HTTP (port 80) and HTTPS (port 443) should be allowed. Traffic on other ports, even if it's web-related, should be blocked. Which service object should be configured in the security policy rule to meet this requirement?

  1. Aany
  2. Bapplication-default
  3. Cservice-http and service-https
  4. Dweb-browsing
Show answer & explanation

Correct answer: B. application-default

To allow only standard HTTP (port 80) and HTTPS (port 443) for web traffic while blocking web-related traffic on other ports, 'application-default' is the most suitable service. When used with web-related App-IDs, 'application-default' ensures that only traffic on the standard ports for those applications is permitted, effectively blocking non-standard ports.

Why the other options are wrong

  • A. 'any' would allow all ports and protocols, violating the requirement to restrict to standard HTTP/HTTPS ports.
  • C. While 'service-http' and 'service-https' represent ports 80 and 443 respectively, using them directly as service objects would bypass App-ID's ability to identify the actual application and enforce standard port usage dynamically. 'application-default' combined with the correct App-ID is more robust.
  • D. 'web-browsing' is an App-ID, not a service object. App-IDs are configured in the 'Application' column of the rule.

Application-Default Service Object

The 'application-default' service object dynamically enforces the standard ports and protocols associated with the applications identified by App-ID in a security policy rule.

  • Used in conjunction with App-ID.
  • Ensures traffic for an identified application uses its standard ports.
  • Blocks traffic on non-standard ports for that application.
  • Promotes best practice for port-based security.

Memory trick: Application-default is like a smart doorman: it only lets you in if you're the right application using your designated standard door (port).

More Security Policy Configuration questions