Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard
A security auditor requires that all HTTP/HTTPS traffic to known malicious or high-risk URL categories must be blocked, and all other uncategorized URLs must be allowed but logged for review. Which URL Filtering profile action should be configured for 'malware' and 'phishing' categories, and for 'uncategorized' URLs, respectively?
- ABlock for 'malware'/'phishing', Allow for 'uncategorized'
- BReset Server for 'malware'/'phishing', Allow for 'uncategorized'
- CBlock for 'malware'/'phishing', Continue for 'uncategorized'
- DBlock for 'malware'/'phishing', Alert for 'uncategorized'
Show answer & explanationAnswer & explanation
Correct answer: D. Block for 'malware'/'phishing', Alert for 'uncategorized'
To block malicious categories, the 'Block' action is correct. For uncategorized URLs that must be allowed *but logged for review*, the 'Alert' action is most appropriate. 'Alert' allows the traffic to pass but generates a log entry, fulfilling the 'logged for review' requirement. 'Allow' would allow traffic but might not generate a log by default depending on logging settings, while 'Continue' is more for user acknowledgment.
Why the other options are wrong
- A. While 'Allow' allows the traffic, it doesn't explicitly meet the 'logged for review' requirement as effectively as 'Alert' which always generates a log.
- B. 'Reset Server' terminates the connection, which is a form of blocking. 'Allow' for uncategorized might not guarantee logging by default without additional logging configuration.
- C. 'Continue' prompts the user with a block page and allows them to proceed, which is not the same as 'allow but log for review'.
URL Filtering Actions
URL Filtering actions define how the firewall responds to traffic destined for specific URL categories, including blocking, allowing, alerting, or resetting connections.
- Actions are configured per URL category in a URL Filtering Profile.
- Common actions: Allow, Block, Alert, Continue, Override, Reset.
- Logging is often a separate setting, but 'Alert' implicitly logs.
Memory trick: URL Actions: Block Bad, Alert Unknown, Permit Good.