A network administrator needs to ensure that internal users can only access specific SaaS applications (e.g., Salesforce, Office 365) and block all other cloud applications. The firewall is configured for App-ID. Which approach to security policy configuration is most effective and adheres to the principle of least privilege?
- ACreate an 'Allow' rule for known SaaS applications, followed by a 'Deny' rule for 'application: any'.
- BCreate an 'Allow' rule for 'application: any', and then use a URL Filtering profile to block unwanted cloud services.
- CCreate an 'Allow' rule for specific SaaS applications, followed by a 'Deny' rule for the 'cloud-apps' application category.
- DCreate an 'Allow' rule for 'application: web-browsing, ssl', followed by a 'Deny' rule for all other applications.
Show answer & explanationAnswer & explanation
Correct answer: C. Create an 'Allow' rule for specific SaaS applications, followed by a 'Deny' rule for the 'cloud-apps' application category.
To enforce granular control over cloud applications while adhering to least privilege, the most effective method is to explicitly allow desired SaaS applications and then explicitly deny the broader 'cloud-apps' application category. This ensures that only approved cloud applications are accessible, and other non-approved cloud applications are blocked by the specific deny rule, which is more precise than a general 'deny any' at the end.
Why the other options are wrong
- A. While a 'deny any' rule is good practice at the end, explicitly denying 'cloud-apps' is more precise and provides better visibility for troubleshooting unapproved cloud usage.
- B. Using 'application: any' is too permissive. While URL filtering can block some cloud services, App-ID is more accurate for controlling cloud applications themselves, regardless of their URL category.
- D. Allowing 'web-browsing, ssl' is too broad and would allow many unapproved cloud applications that use standard web protocols.
App-ID for Cloud Application Control
Palo Alto Networks App-ID can identify and categorize various cloud applications, enabling granular security policies to control access to sanctioned and unsanctioned cloud services.
- App-ID identifies specific SaaS applications (e.g., Salesforce, Box, Office 365).
- Applications are grouped into categories like 'cloud-apps', 'social-networking', 'file-sharing'.
- Policies can explicitly allow sanctioned cloud apps and deny entire categories of unsanctioned cloud apps.
- This provides more precise control than port-based or even generic web-browsing rules.
Memory trick: Cloud App: Allow specifics, deny categories, stay secure, not generic.