pcnsa question 227 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 227

All users from the internal zone must be allowed only HTTP access to a server in the DMZ zone.

Complete the empty field in the Security policy using an application object to permit only this type of access.


Source Zone: Internal
Destination Zone: DMZ Zone Application: __________

Service: application-default Action: allow

  • A. Application = "any"
  • B. Application = "web-browsing"
  • C. Application = "ssl"
  • D. Application = "http"
Answer:

d

User Votes:
A
50%
B 1 votes
50%
C
50%
D 1 votes
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

i think the answer is B, becauce http is not an application but service, the web-browsing cab be http/https.