Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A security engineer is configuring a new security policy rule to allow outbound web traffic for internal users. The policy mandates that all web traffic (HTTP/HTTPS) must be subject to a standard set of security profiles including antivirus, anti-spyware, vulnerability protection, and URL filtering. To simplify management and ensure consistency, how should these profiles be applied to the security policy rule?
- AUse the 'none' option for security profiles, as web traffic is inherently secure with App-ID.
- BOnly apply URL Filtering, as it covers most web-related threats.
- CApply each security profile individually to the rule.
- DCreate a Security Profile Group containing all required profiles and apply the group to the rule.
Show answer & explanationAnswer & explanation
Correct answer: D. Create a Security Profile Group containing all required profiles and apply the group to the rule.
A Security Profile Group allows multiple security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, etc.) to be bundled together and applied as a single object to a security policy rule. This simplifies configuration, ensures consistency, and makes management easier.
Why the other options are wrong
- A. Using 'none' would disable all security profiles, leaving the web traffic unprotected and violating the company's security mandate.
- B. Only applying URL Filtering would neglect protection against malware (antivirus), spyware, and exploits (vulnerability protection), failing to meet the comprehensive security requirements.
- C. Applying each profile individually is possible but is less efficient for management and consistency, especially across many rules.
Security Profile Groups
A Security Profile Group is a collection of individual security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, URL Filtering, File Blocking, Data Filtering) that can be applied to a security policy rule as a single object, simplifying policy management.
- Bundles multiple security profiles.
- Simplifies policy rule configuration.
- Ensures consistent application of security best practices.
Memory trick: Group Profiles, Easy Rules.