Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 336 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 336
Topic #: 1
[All PCNSE Questions]

A Firewall Engineer is migrating a legacy firewall to a Palo Alto Networks firewall in order to use features like App-ID and SSL decryption.
Which order of steps is best to complete this migration?

  • A. First migrate SSH rules to App-ID; then implement SSL decryption.
  • B. Configure SSL decryption without migrating port-based security rules to App-ID rules.
  • C. First implement SSL decryption; then migrate port-based rules to App-ID rules.
  • D. First migrate port-based rules to App-ID rules; then implement SSL decryption.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
secdaddy
Highly Voted 1 year, 11 months ago
Why not C ? Don't we need visibility (via decryption) before app-ID can function?
upvoted 8 times
Jared28
6 months, 1 week ago
Definitely D. The link provided by some, pay close attention to this specific line (and the non-standard port part): "...Security policy rules are likely to use application default ports to prevent traffic from using non-standard ports." Granted you could account for non-default ports just fine beforehand too but test is on PAN BPs so D
upvoted 1 times
...
...
Roger123444
Highly Voted 1 year, 10 months ago
Selected Answer: D
Migrate from port-based to application-based Security policy rules before you create and deploy Decryption policy rules. https://docs.paloaltonetworks.com/best-practices/9-1/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment
upvoted 5 times
...
BTSeeYa
Most Recent 1 month, 2 weeks ago
Putting C as a protest vote. That best practice statement is stupid from Palo. As if an engineer would forget which ports he configured in a few decryption rules and couldn't easily look at them. I'd want my App-ID visibility right off the bat - granular App-IDs won't work without decryption.
upvoted 1 times
...
gully300
1 year, 7 months ago
Selected Answer: D
https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment "Migrating to App-ID based rules before deploying decryption ensures that when you test your decryption deployment"
upvoted 4 times
...
confusion
1 year, 10 months ago
Selected Answer: D
D move to App-ID befohttps://www.examtopics.com/exams/palo-alto-networks/pcnse/view/#re you implement Decryption
upvoted 3 times
...
TAKUM1y
1 year, 10 months ago
Selected Answer: D
https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment
upvoted 3 times
...
GBD35055
1 year, 11 months ago
D is correct. Migrate from port-based to applicaon-based Security policy rules before you create and deploy Decrypon policy rules. If you create Decrypon rules based on port-based Security policy and then migrate to applicaon-based Security policy, the change could cause the Decrypon rules to block traffic that you intend to allow because Security policy rules are likely to use applicaon default ports to prevent traffic from using non-standard ports. Migrang to App-ID based rules before deploying decrypon ensures that when you test your decrypon deployment, you’ll discover Security policy misconfiguraons and fix them before rolling decrypon out to the general user populaon.
upvoted 5 times
Gabuu
1 year, 11 months ago
Can you post the link where you got your information ?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...