exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 130 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 130
Topic #: 1
[All PCNSA Questions]

What is the main function of Policy Optimizer?

  • A. reduce load on the management plane by highlighting combinable security rules
  • B. migrate other firewall vendors' security rules to Palo Alto Networks configuration
  • C. eliminate ג€Log at Session Startג€ security rules
  • D. convert port-based security rules to application-based security rules
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/app-id-features/policy-optimizer.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
H3kerman
Highly Voted 2 years, 1 month ago
Policy Optimizer provides a simple workflow to migrate your legacy Security policy rulebase to an App-ID-based rulebase, which improves your security by reducing the attack surface and offering visibility into applications so you can safely enable them. Policy Optimizer identifies port-based rules so you can convert them to application-based whitelist rules or add applications from a port-based rule to an existing application-based rule without compromising application availability. It also identifies over-provisioned App-ID-based rules (App-ID rules configured with unused applications). Policy Optimizer helps you prioritize which port-based rules to migrate first, identify application-based rules that allow applications you do not use, and analyze rule usage characteristics such as hit count.
upvoted 6 times
...
a2mhkzz
Most Recent 3 months, 1 week ago
Should be D What are the benefits? Allow for Converting port-based rules to application-based rules Allow and deny access to all other applications, which improves security posture (Security Policies have less Attack surface). To identify and clean up Unused Apps.
upvoted 2 times
...
samassier
4 months, 2 weeks ago
Policy Optimizer provides a simple workflow to migrate your legacy Security policy rulebase to an App-ID based rulebase, which improves your security by reducing the attack surface and gaining visibility into applications so you can safely enable them.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago