Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security administrator needs to configure a security policy rule that allows internal users to access web-browsing applications (HTTP/HTTPS) and SSH, while enforcing strict threat prevention measures including antivirus, anti-spyware, and vulnerability protection. To simplify management, these threat prevention profiles should be applied consistently to all allowed traffic within this rule. Which configuration approach BEST achieves this?

  1. AApply Antivirus, Anti-Spyware, and Vulnerability Protection directly to the 'web-browsing', 'ssl', and 'ssh' App-IDs.
  2. BCreate a Security Profile Group containing Antivirus, Anti-Spyware, and Vulnerability Protection, then apply this group to a single security policy rule.
  3. CUse 'any' as the application and 'any' as the service, then apply Antivirus, Anti-Spyware, and Vulnerability Protection profiles.
  4. DCreate individual security policy rules for each application (web-browsing, ssl, ssh) and apply the profiles to each rule.
Show answer & explanation

Correct answer: B. Create a Security Profile Group containing Antivirus, Anti-Spyware, and Vulnerability Protection, then apply this group to a single security policy rule.

To apply a consistent set of threat prevention profiles to multiple applications within a single security policy rule and simplify management, a Security Profile Group is the most efficient and recommended approach. This allows defining the desired profiles once and reusing them.

Why the other options are wrong

  • A. Security profiles are applied to security policy rules, not directly to App-IDs.
  • C. Using 'any' for application and service is too broad and would allow all traffic, violating the principle of least privilege. While it would allow applying the profiles, it's not a secure configuration for the application access specified.
  • D. This approach would work but is inefficient and complex for management, as changes would need to be made across multiple rules.

Security Profile Groups

Security Profile Groups are collections of individual security profiles (e.g., Antivirus, Anti-Spyware) that can be applied as a single object to security policy rules, simplifying management and ensuring consistent policy enforcement.

  • Combines multiple security profiles.
  • Applied to security policy rules.
  • Simplifies policy management.
  • Ensures consistent application of threat prevention measures.

Memory trick: A Security Profile Group is like a pre-packaged security kit: grab the whole box instead of picking individual tools for each job.

More Security Policy Configuration questions