Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A company has implemented a new policy requiring all internal users to only use the corporate-sanctioned version of Microsoft Teams, and block all other versions or personal accounts. Which feature of Palo Alto Networks firewalls should the administrator leverage to enforce this granular control?
- AContent-ID with file blocking
- BURL Filtering with custom categories
- CApp-ID with application filters
- DUser-ID with group mapping
Show answer & explanationAnswer & explanation
Correct answer: C. App-ID with application filters
App-ID, combined with application filters or specific application definitions, allows for granular control over different versions or instances of an application like Microsoft Teams. It can distinguish between corporate and personal instances, enabling precise policy enforcement.
Why the other options are wrong
- A. Content-ID focuses on inspecting file content and types, not the specific version or instance of an application being used.
- B. URL Filtering controls access based on website categories, not specific application versions or instances.
- D. User-ID identifies users but doesn't differentiate between application versions or instances; it's used to apply policies to specific users or groups.
App-ID for Granular Application Control
App-ID identifies applications traversing the firewall, enabling granular control based on the application itself, rather than just port and protocol.
- Identifies applications on all ports, regardless of evasive tactics.
- Allows for precise policy enforcement based on application type, function, or sub-application.
- Continuously updated by Palo Alto Networks.
Memory trick: App-ID: See the App, Not Just the Port.