Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy

A company policy mandates that all internal users must be able to securely access external financial web services, but direct access to streaming video platforms is strictly prohibited. The security administrator has already configured App-ID and URL filtering. Which action should be configured in the URL Filtering profile applied to the outbound security policy rule for streaming video categories?

  1. Aallow
  2. Balert
  3. Ccontinue
  4. Dblock
Show answer & explanation

Correct answer: D. block

To strictly prohibit access to streaming video platforms, the 'block' action in the URL Filtering profile is the most appropriate. This action actively denies the connection, preventing users from reaching the prohibited sites.

Why the other options are wrong

  • A. 'Allow' would permit access, directly contradicting the policy.
  • B. 'Alert' would only log the access without preventing it, which violates the 'strictly prohibited' requirement.
  • C. 'Continue' would allow the traffic to proceed and potentially be evaluated by other security profiles, but would not block it outright.

URL Filtering Actions

URL Filtering actions define how the firewall responds when traffic matches a specific URL category in a URL Filtering profile.

  • Block: Denies access to the URL.
  • Alert: Logs access without blocking.
  • Allow: Permits access to the URL.
  • Continue: Allows traffic, but may prompt user for confirmation or log.

Memory trick: URL Filtering is like a bouncer: it checks your ID (URL category) and decides if you're in or out.

More Security Policy Configuration questions