Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy
A network security engineer is designing a new security policy for a critical application server that hosts sensitive customer data. The application requires access only from a specific internal subnet and a limited set of administrative hosts. Additionally, the application communicates with a backend database server on a non-standard port. Which design principle should the engineer prioritize to ensure the strongest security posture for this application?
- AUtilize application-default service for all rules to automatically handle port changes.
- BApply a 'least privilege' model, allowing only necessary traffic on authorized ports and protocols.
- CImplement a broad 'allow all' policy for internal-to-internal traffic to simplify management.
- DConfigure a single 'any-any' rule with threat prevention profiles for all application traffic.
Show answer & explanationAnswer & explanation
Correct answer: B. Apply a 'least privilege' model, allowing only necessary traffic on authorized ports and protocols.
The 'least privilege' security model dictates that access should only be granted to what is absolutely necessary, minimizing the attack surface. This is critical for sensitive application servers.
Why the other options are wrong
- A. While 'application-default' is useful, it doesn't inherently enforce least privilege for source/destination or time, and might allow more than necessary if not carefully controlled.
- C. A broad 'allow all' policy increases the attack surface and is contrary to security best practices for critical assets.
- D. An 'any-any' rule, even with threat prevention, is overly permissive and exposes the application to unnecessary risks.
Least Privilege Security Policy
A security policy design principle where users, applications, or systems are granted only the minimum necessary permissions or access rights to perform their intended functions.
- Minimizes the attack surface.
- Reduces the potential impact of a breach.
- Requires granular control over access.
Memory trick: Least Privilege: Only open the doors you absolutely need to, and only for those who absolutely need to pass.