exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 476 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 476
Topic #: 1
[All PCNSE Questions]

A Security policy rule is configured with a Vulnerability Protection Profile and an action of “Deny”.

Which action will this configuration cause on the matched traffic?

  • A. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to “Deny”.
  • B. The configuration will allow the matched session unless a vulnerability signature is detected. The “Deny” action will supersede the per-severity defined actions defined in the associated Vulnerability Protection Profile.
  • C. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.
  • D. The Profile Settings section will be grayed out when the Action is set to “Deny”.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
djedeen
Highly Voted 2 years ago
A: If you want to block traffic from zone A to zone B and you have configured the security rule to block this traffic, lets say the first packet comes from zone A, we do a route lookup and find the destination zone to be zone B. You will then do a policy lookup and see that there is a policy match. But since the action is set to "deny", the packet is dropped immediately. Firewall will only inspect the traffic if the policy it matched has action set to "allow".
upvoted 6 times
...
Marshpillowz
Most Recent 11 months, 2 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
Knowledge33
1 year, 7 months ago
Selected Answer: A
answer is A
upvoted 1 times
...
DenskyDen
1 year, 11 months ago
Selected Answer: A
I second the explanation of Djedeen.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...