Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A network administrator needs to optimize the security policy rulebase for performance. They notice several security policy rules that allow common web applications (e.g., facebook-base, youtube-base, google-search) for internal users to the internet. These rules contain a 'service' object of 'application-default' and are configured with various security profiles. Which best practice should the administrator follow to consolidate and optimize these rules without compromising security?

  1. AChange the 'service' object to 'service-https' for all these rules, as they are primarily HTTPS applications.
  2. BCombine all similar web applications into an 'Application Group' and apply it to a single rule with 'application-default' as the service.
  3. CCreate a single rule with 'any' as the application and 'application-default' as the service, applying all necessary security profiles.
  4. DKeep separate rules for each application to ensure granular logging and security profile application.
Show answer & explanation

Correct answer: B. Combine all similar web applications into an 'Application Group' and apply it to a single rule with 'application-default' as the service.

Combining similar applications into an Application Group is a best practice for rulebase optimization. This allows a single security policy rule to cover multiple related applications, reducing rule count while maintaining application-specific enforcement via App-ID and security profiles.

Why the other options are wrong

  • A. Changing the service to 'service-https' would prevent App-ID from identifying and enforcing policies on applications that might use non-standard ports or protocols other than HTTPS, weakening security.
  • C. Using 'any' as the application is overly broad and reduces the granularity of App-ID, potentially allowing unintended applications and making security less effective.
  • D. Keeping separate rules for each application is what the administrator is trying to optimize away from; while it offers granularity, it leads to a bloated and inefficient rulebase when many similar applications exist.

Application Groups

An Application Group in Palo Alto Networks is a logical grouping of multiple App-IDs that can be used in a single security policy rule. This helps to consolidate the rulebase and simplify management while maintaining granular application control.

  • Combines multiple App-IDs into one object.
  • Reduces rulebase complexity and size.
  • Allows for consistent policy application across related applications.

Memory trick: Group Applications, Simplify Rules.

More Security Policy Configuration questions