Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy

A network security administrator is configuring a new security policy rule to allow internal users to access a newly deployed internal web application. The application uses a non-standard TCP port 8080. Which service object should the administrator use in the security policy rule to ensure only this specific application traffic is permitted?

  1. Aservice-http
  2. Bany
  3. Capplication-default
  4. Dtcp-8080
Show answer & explanation

Correct answer: D. tcp-8080

To allow traffic on a specific non-standard port for a new application without relying on App-ID or allowing all traffic, a custom service object defining that port is the most precise method. 'application-default' would use App-ID recognized ports, and 'any' would be too broad.

Why the other options are wrong

  • A. 'service-http' typically refers to TCP port 80, not 8080, and would not match the application's port.
  • B. Using 'any' would permit all types of traffic on any port, which is not specific enough for the requirement.
  • C. 'application-default' allows traffic only on the standard ports associated with applications identified by App-ID, which might not include a non-standard port 8080 without a custom App-ID.

Custom Service Objects

Custom service objects define specific port and protocol combinations for use in security policies, allowing granular control over non-standard application traffic.

  • Used for applications running on non-standard ports.
  • Overrides App-ID's default port recognition for specific rules.
  • Provides granular control over allowed traffic.

Memory trick: Service objects define the specific 'door' and 'language' for traffic.

More Security Policy Configuration questions