Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security auditor requires that all HTTP traffic to specific high-risk URL categories (e.g., gambling, adult) must be blocked, and users attempting to access these sites should receive a customizable block page. Additionally, all HTTPS traffic to these same categories must be reset-server. Which security profile needs to be configured and applied to achieve this granular control?

  1. AThreat Prevention Profile
  2. BDecryption Profile
  3. CURL Filtering Profile
  4. DFile Blocking Profile
Show answer & explanation

Correct answer: C. URL Filtering Profile

The requirement specifically mentions blocking based on 'URL categories' and providing a 'block page'. This functionality is provided by the URL Filtering Profile, which allows administrators to define actions (allow, block, continue, alert, override, reset-client, reset-server) based on predefined or custom URL categories. The 'reset-server' action for HTTPS traffic to these categories is also a feature of URL Filtering when decryption is not performed.

Why the other options are wrong

  • A. Threat Prevention Profile focuses on blocking exploits, malware, and spyware, not URL category-based access control.
  • B. Decryption Profile determines which SSL/TLS traffic is decrypted, but doesn't define actions based on URL categories.
  • D. File Blocking Profile controls specific file types, not website categories.

URL Filtering Profile Actions

The URL Filtering Profile allows administrators to define various actions for different URL categories, including blocking, alerting, and resetting connections.

  • Actions can be applied per URL category (e.g., allow, block, continue, alert, override, reset-client, reset-server).
  • Customizable block pages can be presented to users for blocked categories.
  • Supports both HTTP and HTTPS traffic, with specific actions like 'reset-server' for encrypted traffic without decryption.
  • Predefined categories are maintained by Palo Alto Networks' Threat Intelligence Cloud.

Memory trick: URL Filtering: Categorize, action, block page, keep web clean.

More Security Policy Configuration questions