Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security engineer is configuring a new security policy rule to allow outbound web traffic for internal users. The policy mandates that all web traffic (HTTP/HTTPS) must be subject to a standard set of security profiles including antivirus, anti-spyware, vulnerability protection, and URL filtering. To simplify management and ensure consistency, how should these profiles be applied to the security policy rule?

  1. AUse the 'none' option for security profiles, as web traffic is inherently secure with App-ID.
  2. BOnly apply URL Filtering, as it covers most web-related threats.
  3. CApply each security profile individually to the rule.
  4. DCreate a Security Profile Group containing all required profiles and apply the group to the rule.
Show answer & explanation

Correct answer: D. Create a Security Profile Group containing all required profiles and apply the group to the rule.

A Security Profile Group allows multiple security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, etc.) to be bundled together and applied as a single object to a security policy rule. This simplifies configuration, ensures consistency, and makes management easier.

Why the other options are wrong

  • A. Using 'none' would disable all security profiles, leaving the web traffic unprotected and violating the company's security mandate.
  • B. Only applying URL Filtering would neglect protection against malware (antivirus), spyware, and exploits (vulnerability protection), failing to meet the comprehensive security requirements.
  • C. Applying each profile individually is possible but is less efficient for management and consistency, especially across many rules.

Security Profile Groups

A Security Profile Group is a collection of individual security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, Data Filtering) that can be applied to a security policy rule as a single object, simplifying policy management.

  • Bundles multiple security profiles.
  • Simplifies policy rule configuration.
  • Ensures consistent application of security best practices.

Memory trick: Group Profiles, Easy Rules.

More Security Policy Configuration questions