Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSA topic 1 question 3 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 3
Topic #: 1
[All PCNSA Questions]

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by
App-ID as SuperApp_base.
On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days.
Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

  • A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
  • B. No impact because the apps were automatically downloaded and installed
  • C. No impact because the firewall automatically adds the rules to the App-ID interface
  • D. All traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until the security administrator approves the applications
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
rebet
Highly Voted 4 years, 2 months ago
The correct answer is: A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
upvoted 23 times
...
rach91
Highly Voted 4 years, 2 months ago
I agree with you @Rebet. To allow the new applications, we need to modify or add a new policy. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-ids-introduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules
upvoted 9 times
...
rtberry72
Most Recent 7 months ago
Correct Answer is A: App-ID Updates and Impact Firewall administrators must be careful before they install any App-ID updates because some applications might have changed since the last App-ID update (content update). For example, an application that previously was categorized under web-browsing now might be categorized under its own unique App-ID. Categorization of applications into more specific applications enables more granularity and control of applications within Security policy rules. Because the new App-ID no longer will be categorized as web-browsing, no Security policy rule now will contain this new App-ID. Consequently, the new App-ID will be blocked.
upvoted 1 times
...
j4v13rh4ack
1 year, 2 months ago
Selected Answer: A
Letter A.
upvoted 1 times
...
daytonadave2011
1 year, 3 months ago
Selected Answer: A
I believe the answer is A because if the new App-IDs are being blocked, it will show in the policy optimizer that those App-IDs are being blocked and must be added again for functionality.
upvoted 1 times
...
kewokil120
1 year, 11 months ago
Selected Answer: A
The correct answer is: A
upvoted 3 times
...
error_909
2 years, 1 month ago
Selected Answer: A
All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer matches the SuperApp-base application
upvoted 5 times
...
error_909
2 years, 1 month ago
Selected Answer: A
A is the only one that make sense
upvoted 3 times
...
Gaven
2 years, 1 month ago
Selected Answer: A
A. You need to modify the policy to include the new application. I have seen in the past these updates denying traffic due to this. I would also refer to @Rebet.
upvoted 3 times
...
Kane002
2 years, 6 months ago
A is correct. For example, Facebook-chat is a dependency on Facebook-base, and must be specifically allowed through a dependency commit, explicit security policy, etc. It would not be implicitly allowed, things that are implicitly allowed would be ssl and web-browsing, as facebook-base could not function without those.
upvoted 2 times
...
DatBroNZ
2 years, 6 months ago
It all depends on how the security policy is configured. If it is using the parent SuperApp, then anything new added under that category will be automatically allowed, so no impact, answer C. But if the security policy is locked to the SuperApp-base, then the traffic to the new apps would be blocked, option A.
upvoted 3 times
...
Cyril_the_Squirl
2 years, 6 months ago
A is Correct. When new APP-IDs are downloaded and added to device, the security policy must exist to explicitly allow them. But because they're "new" they will get dropped until you modify/add security policy to explicitly allow them otherwise they're dropped by InterZone polcy which drops the traffic by default.
upvoted 2 times
...
Rowdy_47
2 years, 7 months ago
Rediculous canf find a clear answer on this!!! Cisco all over again
upvoted 3 times
Rowdy_47
2 years, 7 months ago
Edit:update Spoke to one of my colleagues who have been working with PAs for 2 years He has never once had to redefine apps and change policies, seems to be in line with the way PaloAlto does things so I am going to choose C PS - he said he also got that question in his exam and chose C
upvoted 3 times
Rowdy_47
2 years, 5 months ago
Update This is wrong, the correct answer is A
upvoted 7 times
...
...
...
Micutzu
2 years, 10 months ago
The correct answer is "C. No impact because the firewall automatically adds the rules to the App-ID interface". The question is refering to SuperApp and SuperApp is the upper level for SuperApp_base, SuperApp_chat and SuperApp_download. As an example we have the top level FACEBOOK ans subcategories: FACEBOOK_BASE, FACEBOOK_CHAT, FACEBOOK_DOWNLOAD, ...
upvoted 3 times
...
ramasamymuthiah
2 years, 11 months ago
Correct answer is A
upvoted 2 times
...
debabani
3 years, 2 months ago
A is the correct answer
upvoted 1 times
...
prseedd
3 years, 6 months ago
Ans Correct ans-C...Otherwise it will be huge disadvantage
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...