Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 19 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 19
Topic #: 1
[All PCNSE Questions]

A Security policy rule is configured with a Vulnerability Protection Profile and an action of `Deny`.
Which action will this cause configuration on the matched traffic?

  • A. The configuration is invalid. The Profile Settings section will be grayed out when the Action is set to ג€Denyג€.
  • B. The configuration will allow the matched session unless a vulnerability signature is detected. The ג€Denyג€ action will supersede the per-severity defined actions defined in the associated Vulnerability Protection Profile.
  • C. The configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.
  • D. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to ג€Denyג€.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-policy/security-policy-actions

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
bbud55
Highly Voted 3 years, 1 month ago
D is correct https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/security-profiles.html First note in above link states: "Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." The first thing the firewall checks per it's flow is the security policy match and action. The Security Profile never gets checked if a match happens on a policy set to deny that match.
upvoted 20 times
...
Marshpillowz
Most Recent 3 months ago
Selected Answer: D
D is correct answer.
upvoted 1 times
...
avator
4 months, 1 week ago
it is kind of burdening the firewall resource by allowing the traffic payload to be scanned once the traffic is denied to get a network service so the answer should be A or the question it self is doubting is weather the action "Deny" is it for the security rule or is it for the security profile ? if it is for the security profile it should be "Drop"
upvoted 1 times
...
Chris71Mach1
1 year, 3 months ago
Selected Answer: D
If a traffic flow matches a security policy whose action is set to Deny, it doesn't matter what security profiles are configured within the policy, cause the traffic will be dropped regardless.
upvoted 1 times
...
Kuronekosama
1 year, 7 months ago
Selected Answer: D
D is correct. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-policy/components-of-a-security-policy-rule Provide additional protection from threats, vulnerabilities, and data leaks. Security profiles are evaluated only for rules that have an allow action.
upvoted 1 times
...
Pakawat
1 year, 9 months ago
D is correct : "Blocks traffic and enforces the default Deny Action defined for the application that is being denied.." https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-policy/security-policy-actions
upvoted 1 times
...
Meko
1 year, 10 months ago
Selected Answer: D
D - traffic is already deny.
upvoted 1 times
...
datz
1 year, 11 months ago
Selected Answer: D
D for sure. if the Sec policy is already denied, no point checking Sec profiles, etc
upvoted 1 times
...
tururu1496
2 years, 1 month ago
Selected Answer: D
Answer: D
upvoted 1 times
...
bigdaddy_69
2 years, 3 months ago
Selected Answer: D
Allow = security profile processing.
upvoted 2 times
...
Bighize
2 years, 5 months ago
Agreed. Failed Exam today. Only had about 8 questions from this dump. They are shifting to focus to Panaorama Deployment, Device Groups and Template stacks, UserID and mapping, Certificate questions and SSL decryption and SD-WAN. There is some Prisma on there, as well. You may not pass if you rely on this.
upvoted 3 times
...
Kane002
2 years, 5 months ago
D. Security policies are evaluated before security profiles in the SP3. The packet will be discarded and the security profile will never be consulted.
upvoted 2 times
...
NNgiggs
2 years, 6 months ago
A is the right answer, Vulnerability profile can only be checked if the traffic is allowed. there is no reason for a firewall to check traffic for vulnerability when it has been denied and will be dropped. this traffic will not make it through the slow path of traffic flow in palo alto and so no session will be created because the traffic is DENIED!!!
upvoted 1 times
...
r0ze
2 years, 6 months ago
Correct Answer: D
upvoted 1 times
...
Ceejer
2 years, 7 months ago
Thank god for the discussion.. So many of these solutions are wrong
upvoted 1 times
...
SMahaldar
2 years, 9 months ago
D is correct ans.
upvoted 1 times
...
Prutser2
2 years, 10 months ago
D, the security policy is set to deny, this is enough not to allow the oacket, considering the polcy evaluation order, where security profiles get evalauted last, really the sec profile is not relevant as the packet is already denied
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...