exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 597 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 597
Topic #: 1
[All PCNSE Questions]

Which two items must be configured when implementing application override and allowing traffic through the firewall? (Choose two.)

  • A. Application filter
  • B. Application override policy rule
  • C. Security policy rule
  • D. Custom app
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DatITGuyTho1337
2 months, 1 week ago
Why even attempt an APPLICATION Override when there's no custom app in the first place? Might as well keep using App-ID. BCD.
upvoted 2 times
...
examtopicstroilevw
3 months ago
Selected Answer: BC
B and C. Please note: a custom app IS NOT REQUIRED to do an application override. you can override the built-in app, per the KB article. "What You'll Need for Setup To configure an Application Override, go to Policies > Application Override in the WebGUI. For setup, you'll need the following: Custom Application to be used in the Application Override policy (recommended) Application Override policy Security Policy that allows the newly created Custom Application through the firewall Special Note about Content and Threat inspection Application Override to a custom application will force the firewall to bypass Content and Threat inspection for the traffic that is matching the override rule. The exception to this is when you override to a pre-defined application that supports threat inspection. " https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0
upvoted 2 times
DatITGuyTho1337
2 weeks, 2 days ago
You literally quoted: "*Custom Application* to be used in the Application Override policy (recommended)". I mean, c'mon man!!
upvoted 1 times
...
...
hcir
8 months, 2 weeks ago
BCD, but the ask for 2 answers only so I guess that Custom app is implicitly included in B?
upvoted 1 times
...
jaypogi16
9 months, 2 weeks ago
Selected Answer: BC
Once the custom application object has been created, it requires two additional things before it will be used by the Palo Alto firewall: There must be a security policy in place that permits the traffic (unless this is a new site or recently added subnet, this should already exist) There must be an application override policy that specifies when the custom application object should be used There must be an application override policy that specifies when the custom application object should be used
upvoted 2 times
poiuytr
9 months, 2 weeks ago
D - not necessary, cause: Policies : Policies > Application Override : Application Override Protocol/Application Tab: "Application - Select the override application for traffic flows that match the above rule criteria. When overriding to a custom application, there is no threat inspection that is performed. The exception to this is when you override to a pre-defined application that supports threat inspection."
upvoted 3 times
prenotazioni
7 months ago
Poiuytr is right
upvoted 1 times
...
...
...
rhinogkn24
9 months, 2 weeks ago
Selected Answer: BC
Answers should include (D) Custom App (with no signature) as well as BC
upvoted 1 times
...
torgy1
9 months, 2 weeks ago
BC...D https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0
upvoted 2 times
scanossa
6 months, 2 weeks ago
For setup, you'll need the following: Custom Application to be used in the Application Override policy (recommended) Application Override policy Security Policy that allows the newly created Custom Application through the firewall
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago