pcnsa question 298 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 298

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP
Addresses list?

  • A. destination address
  • B. source address
  • C. destination zone
  • D. source zone
Answer:

d

User Votes:
A 2 votes
50%
B 5 votes
50%
C 1 votes
50%
D 1 votes
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

Explanation: This condition refers to the IP address of the originating traffic (the sender). To block traffic from known malicious IP addresses, this is the correct match condition, as you want to prevent any traffic coming from those sources.