@blackisok
Based on the link you provided this is incorrect. Decryption should be first as it is done in the Tunnel decapsulation of the the Ingress Stage. Zone Protection checks is done in the next Firewall Session Lookup Stage. Then Security Policy, then App-ID.
So based on your link it should be
1. Decryption
2. Zone Protection
3. Security Profile
4. App-ID
i think this is it too. Security profile should come first before App-ID. If not what App-ID does it know to check if it does not see the profile first.
The packet processing order in Palo Alto Networks firewalls typically follows these steps:
Packet Ingress:
Zone Protection: This is where the firewall evaluates if the packet complies with the security policies defined for the source and destination zones.
Decryption:
If the traffic is encrypted, the firewall decrypts the packet to inspect the decrypted content. Decryption is often performed using SSL decryption policies.
App-ID (Application Identification):
The firewall identifies the application associated with the traffic. This is a crucial step in allowing or blocking traffic based on the specific applications being used.
Security Profile Enforcement:
After the application is identified, security profiles (such as antivirus, anti-spyware, and vulnerability protection) are applied to the traffic to detect and prevent threats.
This question is confusing as f*ck.
It all depends on wether decryption is based on ssl proxy or VPN traffic
And wether a session already exists or not.
So if this would be adressing a NEW session of SSL Proxy traffic, the order should be
1. Zone protection
2. Decryption
3. App-ID
4. Security profile enforcement
I think it should be Decryption, Zone Protection, App-ID then Security Profile enforcement. See link below.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0
I would say it would have to be taking place first or else the contents of the packet wouldnt be able to be read to determine the remaining Zone/Security/App info.
upvoted 1 times
...
...
...
This section is not available anymore. Please use the main Exam Page.PCNSA Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Mouna_cert
Highly Voted 1 year, 11 months agoblackisok
1 year, 6 months agoErmbmx2
1 year, 6 months agoleini
1 year, 5 months agoSamurai55_1998_01
Highly Voted 1 year, 8 months agocert111
1 year, 5 months agoNetsan
Most Recent 3 months, 3 weeks ago[Removed]
8 months, 1 week agobreal
11 months, 3 weeks agoCalica
1 year agodawlims
1 year, 2 months agonolox
1 year, 8 months agokhaled_ellaboudy
1 year, 9 months agoLetsDiscuss23
1 year, 8 months agoNeil_Neo234
1 year, 12 months agomarkeloff23
2 years, 1 month agoSamurai55_1998_01
1 year, 8 months agoErmbmx2
1 year, 6 months ago