exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 19 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 19
Topic #: 1
[All PCNSE Questions]

A Security policy rule is configured with a Vulnerability Protection Profile and an action of `Deny`.
Which action will this cause configuration on the matched traffic?

  • A. The configuration is invalid. The Profile Settings section will be grayed out when the Action is set to ג€Denyג€.
  • B. The configuration will allow the matched session unless a vulnerability signature is detected. The ג€Denyג€ action will supersede the per-severity defined actions defined in the associated Vulnerability Protection Profile.
  • C. The configuration is invalid. It will cause the firewall to skip this Security policy rule. A warning will be displayed during a commit.
  • D. The configuration is valid. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no effect if the Security policy rule action is set to ג€Denyג€.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bbud55
Highly Voted 3 years, 6 months ago
D is correct First note in above link states: "Security profiles are not used in the match criteria of a traffic flow. The security profile is applied to scan traffic after the application or category is allowed by the security policy." The first thing the firewall checks per it's flow is the security policy match and action. The Security Profile never gets checked if a match happens on a policy set to deny that match.
upvoted 21 times
...
DaNhiCon
Most Recent 1 week, 3 days ago
Selected Answer: A
The configuration is invalid. Because when you choose action is “Deny”, you can not assign security profile to security rule
upvoted 1 times
...
Marshpillowz
8 months, 1 week ago
Selected Answer: D
D is correct answer.
upvoted 1 times
...
avator
9 months, 2 weeks ago
it is kind of burdening the firewall resource by allowing the traffic payload to be scanned once the traffic is denied to get a network service so the answer should be A or the question it self is doubting is weather the action "Deny" is it for the security rule or is it for the security profile ? if it is for the security profile it should be "Drop"
upvoted 2 times
...
Chris71Mach1
1 year, 9 months ago
Selected Answer: D
If a traffic flow matches a security policy whose action is set to Deny, it doesn't matter what security profiles are configured within the policy, cause the traffic will be dropped regardless.
upvoted 1 times
...
Kuronekosama
2 years ago
Selected Answer: D
D is correct. Provide additional protection from threats, vulnerabilities, and data leaks. Security profiles are evaluated only for rules that have an allow action.
upvoted 1 times
...
Pakawat
2 years, 2 months ago
D is correct : "Blocks traffic and enforces the default Deny Action defined for the application that is being denied.."
upvoted 1 times
...
Meko
2 years, 3 months ago
Selected Answer: D
D - traffic is already deny.
upvoted 1 times
...
datz
2 years, 4 months ago
Selected Answer: D
D for sure. if the Sec policy is already denied, no point checking Sec profiles, etc
upvoted 1 times
...
tururu1496
2 years, 6 months ago
Selected Answer: D
Answer: D
upvoted 1 times
...
bigdaddy_69
2 years, 8 months ago
Selected Answer: D
Allow = security profile processing.
upvoted 2 times
...
Bighize
2 years, 10 months ago
Agreed. Failed Exam today. Only had about 8 questions from this dump. They are shifting to focus to Panaorama Deployment, Device Groups and Template stacks, UserID and mapping, Certificate questions and SSL decryption and SD-WAN. There is some Prisma on there, as well. You may not pass if you rely on this.
upvoted 3 times
...
Kane002
2 years, 10 months ago
D. Security policies are evaluated before security profiles in the SP3. The packet will be discarded and the security profile will never be consulted.
upvoted 2 times
...
NNgiggs
2 years, 11 months ago
A is the right answer, Vulnerability profile can only be checked if the traffic is allowed. there is no reason for a firewall to check traffic for vulnerability when it has been denied and will be dropped. this traffic will not make it through the slow path of traffic flow in palo alto and so no session will be created because the traffic is DENIED!!!
upvoted 1 times
...
r0ze
2 years, 11 months ago
Correct Answer: D
upvoted 1 times
...
Ceejer
3 years ago
Thank god for the discussion.. So many of these solutions are wrong
upvoted 1 times
...
SMahaldar
3 years, 2 months ago
D is correct ans.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago