Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 576 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 576
Topic #: 1
[All PCNSE Questions]

A firewall engineer supports a mission-critical network that has zero tolerance for application downtime. A best-practice action taken by the engineer is to configure an Applications and Threats update schedule with a new App-ID threshold of 48 hours.

Which two additional best-practice guideline actions should be taken with regard to dynamic updates? (Choose two.)

  • A. Configure an Applications and Threats update schedule with a threshold of 24 to 48 hours.
  • B. Click "Review Apps" after application updates are installed in order to assess how the changes might impact Security policy.
  • C. Create a Security policy rule with an application filter to always allow certain categories of new App-IDs.
  • D. Select the action "download-only" when configuring an Applications and Threats update schedule.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Mtro
1 week, 4 days ago
Best practice action taken by the engineer is to configure a new App-ID threshold of 48 hours. The additional best practice actions are B and C
upvoted 1 times
...
hcir
2 weeks ago
after re reading, A would be true if it said up to 48h, but it says between 24 and 48 hours. So B and C
upvoted 1 times
...
rmorganq
2 months, 2 weeks ago
Selected Answer: BC
B and C as per "Best Practices for Content Updates—Mission-Critical".
upvoted 2 times
poiuytr
1 month, 2 weeks ago
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-upgrade/software-and-content-updates/best-practices-for-app-and-threat-content-updates/best-practices-mission-critical
upvoted 1 times
...
...
Marshpillowz
3 months, 1 week ago
Selected Answer: BC
B and C correct
upvoted 1 times
...
evilCorpBot7494
3 months, 2 weeks ago
Selected Answer: BC
A is true, but it has already been done and D is not a good practice. Right answers are B and C, as reviewing apps is a good practice as per the link provided by omgt2k2, and C just makes sense.
upvoted 1 times
...
omgt2k2
3 months, 3 weeks ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/software-and-content-updates/best-practices-for-app-and-threat-content-updates/best-practices-mission-critical#id184AH00L078 Always review the new and modified App-IDs that a content release introduces, in order to assess how the changes might impact your security policy. The following topic describes the options you can use to update your security policy both before and after installing new App-IDs: Manage New and Modified App-IDs.
upvoted 2 times
...
wsdeffwd
3 months, 3 weeks ago
A&C Security first customer: Should do hourly recurrence for download and install action and set threshold to less than 6 hours. Availability first customer: Should do daily recurrence for download and install action and set threshold in the range 24-48. https://live.paloaltonetworks.com/t5/best-practice-assessment-device/dynamic-updates-new-app-id-threshold/ta-p/338191
upvoted 1 times
...
franko_72
3 months, 3 weeks ago
OK, I see lots more comments on here, upon 30 min review which takes up time when there is 580 ish questions! I think it's also B, C Def not D and A is for: Schedule content updates so that they download-and-install automatically. Then, set a Threshold that determines the amount of time the firewall waits before installing the latest content. In a mission-critical network, schedule up to a 48 hour threshold. So really it's probably A, B, C but since only 2 choices, B, C for General Best Practice and A for Security First approach.
upvoted 1 times
...
JRKhan
3 months, 4 weeks ago
Selected Answer: BD
BD are correct. C is a good to have but given it only mentions certain categories and question specifically said zero tolerance for app downtime it will not be the best option. Application Availability: The goal of Application Availability is to ensure that changes are implemented only after an administrator has assessed any potential impact. Updates to the application signatures are not installed until manually done so. However, this task delays the process of updating signatures. But for certain environments, Application Availability is a requirement. (Taken from Palo training course on best practices for App-ID and Threat Updates.)
upvoted 1 times
...
Yetti254
4 months ago
Selected Answer: BC
A doesn't help with the question B you should definitely do anyways thats a given C is best practice per palo D makes no sense So it's obviously BC
upvoted 1 times
...
hcir
4 months ago
To minimize application downtime, answer is A and C. Install the content update up to 48h and create the app filter to allow always new apps of a specific category. Reviewing Apps is a good practice before installing the update not after.
upvoted 1 times
...
omgt2k2
4 months, 1 week ago
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBDbCAO&lang=en_US%E2%80%A9
upvoted 1 times
...
franko_72
4 months, 1 week ago
Has to be AC, see link below from 90fa8d0.
upvoted 1 times
...
90fa8d0
4 months, 1 week ago
Selected Answer: AC
Sorry.. its AC
upvoted 1 times
...
90fa8d0
4 months, 1 week ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/software-and-content-updates/best-practices-for-app-and-threat-content-updates/best-practices-mission-critical#id184AH00L078
upvoted 2 times
...
Morpheus1
4 months, 1 week ago
Answer: B,C Create a security policy rule to always allow certain categories of new App-IDs Click Review Apps in order to assess how the changes might impact your security policy https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/software-and-content-updates/best-practices-for-app-and-threat-content-updates/best-practices-mission-critical#id184AH00L078
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...