exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 75 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 75
Topic #: 1
[All PCNSA Questions]

Four configuration choices are listed, and each could be used to block access to a specific URL. If you configured each choice to block the same URL then which choice would be the last to block access to the URL?

  • A. EDL in URL Filtering Profile
  • B. Custom URL category in URL Filtering Profile
  • C. Custom URL category in Security policy rule
  • D. PAN-DB URL category in URL Filtering Profile
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IxlJustinlxl
Highly Voted 4 years, 5 months ago
Answer should be D, and here is why: The precedence is from the top down; First Match Wins: 1) Block list: Manually entered blocked URLs Objects - 2) Allow list: Manually entered allowed URLs Objects - 3) Custom URL Categories - 4) Cached Cached: URLs learned from External Dynamic Lists (EDLs) - 5) Pre-Defined Categories: PAN-DB or Brightcloud categories.
upvoted 27 times
webmanau
4 years ago
Option C could block as well but would be the FIRST thing to block.
upvoted 2 times
olexx
3 years, 1 month ago
Check out the wording of the question: "....and each could be used to block access to a specific URL.....which choice would be the last to block access to the URL?" ALL options will block the URLs, it's asking here about the order of blocking, which will be first or last to block, it's not asking IF those options would block or not ;) The answer is of course D 1- Block list 2- Allow list 3- Custom URL Cat. 4- EDLs 5- Downloaded PAN-DB Files 6- PAN-DB Cloud
upvoted 12 times
...
...
...
BTSeeYa
Most Recent 10 months, 2 weeks ago
Selected Answer: D
When you configure a URL category directly in a security rule as match criteria, that will be analyzed before all security profiles, including URL-Filtering. Within URL-Filtering, custom categories are analyzed first, then EDLs, then pre-defined categories. So the answer must be D.
upvoted 2 times
...
baccalacca
2 years, 2 months ago
The precedence is from the top down; First Match Wins: 1) Block list: Manually entered blocked URLs Objects 2) Allow list: Manually entered allowed URLs Objects - 3) Custom URL Categories - 4) Cached Cached: URLs learned from External Dynamic Lists (EDLs) - 5) Pre-Defined Categories: PAN-DB or Brightcloud categories.
upvoted 2 times
...
[Removed]
2 years, 2 months ago
Selected Answer: D
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClyTCAS The order in which the device checks for URL categories is as follows: Block list Allow list Custom categories Device cache BrightCloud downloaded database Cloud lookup (if enabled
upvoted 3 times
...
KirinKev
2 years, 3 months ago
Selected Answer: D
I think D is the most accurate according to this topic https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClyTCAS
upvoted 3 times
...
yinksho
2 years, 5 months ago
Selected Answer: B
B is correct answer.though the question is tricky but remember evaluation is done from top to bottom.custom url will be last after block and allow list .once the traffic matches the custom url ,it would not check others.
upvoted 1 times
...
piipo
2 years, 9 months ago
Selected Answer: D
PAN-DB is last
upvoted 2 times
...
magicbr3
2 years, 10 months ago
Answer cannot be C because Profiles can only block or deny if a policy allows it. Answer is D
upvoted 2 times
...
on2it
2 years, 10 months ago
Selected Answer: D
This is D, beceause PAN-DB is the last that will block
upvoted 2 times
...
Sandman77
2 years, 11 months ago
Selected Answer: D
answer is D
upvoted 2 times
...
LordScorpius
3 years, 1 month ago
Selected Answer: D
PA-DB live is absolutely the last to block...
upvoted 3 times
...
error_909
3 years, 1 month ago
Selected Answer: B
I would go with B.
upvoted 2 times
error_909
3 years, 1 month ago
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/url-filtering/pan-db-categorization.html#idba222a98-c4e2-43a7-b493-ce6c46fbd76c
upvoted 1 times
...
...
Luongchacha1
3 years, 2 months ago
D is incorrect answer, because the purpose is to block a specific url. I think A is correct answer.
upvoted 1 times
...
sahilyakup
3 years, 10 months ago
In earlier release versions, URL Filtering category overrides had priority enforcement ahead of custom URL categories. As part of the upgrade to PAN-OS 9.0, URL category overrides are converted to custom URL categories, and no longer receive priority enforcement over other custom URL categories. Instead of the action you defined for the category override in previous release versions, the new custom URL category is enforced by the security policy rule with the strictest URL Filtering profile action. From most strict to least strict, possible URL Filtering profile actions are: block, override, continue, alert, and allow.
upvoted 1 times
...
Micutzu
4 years ago
In my oppinion the correct answer is D. See also question 59.
upvoted 3 times
...
debabani
4 years, 2 months ago
why not D? I think the correct answer should be D
upvoted 3 times
...
atifikhan
4 years, 4 months ago
I think it is B
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago