exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 10 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 10
Topic #: 1
[All PCNSA Questions]

Which two statements are correct about App-ID content updates? (Choose two.)

  • A. Updated application content might change how Security policy rules are enforced.
  • B. After an application content update, new applications must be manually classified prior to use.
  • C. Existing security policy rules are not affected by application content updates.
  • D. After an application content update, new applications are automatically identified and classified.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rebet
Highly Voted 3 years, 11 months ago
The correct answers are: A. Updated application content may change how security policy rules are enforced D. After an application content update, new applications are automatically identified and classified 'B' is not correct as there is no need to do any manual classification of applications.
upvoted 33 times
PANW
3 years, 8 months ago
I agree A & D are correct As new App-IDs are introduced and delivered to the firewall via weekly updates, dynamic filters are automatically updated for those applications that meet the filter criteria. This helps minimize administrative effort associated with security policy management. Source: https://www.paloaltonetworks.com/resources/techbriefs/app-id-tech-brief.html
upvoted 5 times
...
...
RedByte
Highly Voted 4 years, 2 months ago
The answer should be A and B: "A firewall admin must be careful before they install any App‐ID updates because some applications may have changed since the last App‐ID update (content update). For example, an application that was previously categorized under web‐browsing now may be categorized under its own unique App‐ID. Categorization of applications into more specific applications allows more granularity and control of applications within security policies. Because the new App‐ID no longer will be categorized as web‐browsing, no security policy now will contain this new App‐ID. Consequently, the new App‐ID will be blocked."
upvoted 7 times
...
Rivand
Most Recent 3 months, 4 weeks ago
Selected Answer: AD
A and D are acorrect
upvoted 1 times
...
J0aquin
4 months ago
Selected Answer: AD
A: "Newly-categorized and modified App-IDs can change the way in which the firewall enforces traffic. Review the content update policy to see how new and modified App-IDs impact your Security policy and to easily make any necessary adjustments. You can review the content update policy for both downloaded and installed content."
upvoted 1 times
...
blu_gandalf
8 months, 1 week ago
i just answer it in practice exam , A & D
upvoted 2 times
...
[Removed]
8 months, 3 weeks ago
Selected Answer: AD
A and D
upvoted 1 times
...
all_nicknames_are_taken
10 months, 3 weeks ago
A,D: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-new-app-ids-introduced-in-content-releases
upvoted 1 times
...
BMRobertson
11 months, 3 weeks ago
The answer(s) are A&D. Please look at the following link: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/software-and-content-updates/app-and-threat-content-updates states "As the firewall automatically retrieves and installs the latest application and threat signatures (based on your custom settings), it starts enforcing security policy based on the latest App-IDs and threat protection without any additional configuration." This means B is incorrect and D is correct; further down it states, "Because new App-IDs can change how the security policy enforces traffic..." (this means A is correct and C is not);
upvoted 1 times
...
argyris23
12 months ago
Selected Answer: AD
A,D source: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/manage-new-app-ids-introduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules
upvoted 2 times
...
Ankitkumar2029
1 year ago
Selected Answer: A
A. Updated application content might change how Security policy rules are enforced.
upvoted 1 times
...
yurakoresh
1 year, 6 months ago
Selected Answer: AD
A & D should be the correct answers!
upvoted 2 times
...
LordScorpius
1 year, 10 months ago
Please DON'T take this exam IF you believe that App-ID updates can't break some of Security Policy Rules. The training Palo writes spends a great deal of time explaining how it can! Secondly, stop wishfully thinking everything is automatic. Dependencies must be allowed or denied after they are created. The answer here is clearly A and D.
upvoted 1 times
...
Raimz
1 year, 10 months ago
I go with A & B
upvoted 1 times
...
error_909
1 year, 10 months ago
Selected Answer: AD
The correct answers are: A. Updated application content may change how security policy rules are enforced D. After an application content update, new applications are automatically identified and classified. For any manual process in app-id updates, the option disable content update must be done first, then the admin must allow new signatures manually
upvoted 4 times
...
Cyril_the_Squirl
2 years, 2 months ago
A & B are correct. Updated or changed application identifiers MIGHT surely change the way security policy is applied if there's been changes or new additions. (A is correct). Therefore where there are NEW additions to applications and app identifiers, all the new app-IDs MUST be explicitly/manually included correctly in the security policy.(B is correct). C is wrong.... it's silly to think security policy is not affected by app-id when it's in the app-id profile is used. D is wrong...lost me at "automatically"
upvoted 2 times
vdsdrs
2 years, 1 month ago
All apps are automatically identified and classified if they match the signature... A&D are correct.
upvoted 2 times
...
...
Kane002
2 years, 2 months ago
A and D. For people arguing for B, the wording seems to imply that an admin would have to manually classify new applications via application overrides or custom application signatures, which they do not have to do, this is done automatically, it's the whole point of the content update.
upvoted 1 times
...
Rowdy_47
2 years, 4 months ago
A and D As the firewall automatically retrieves and installs the latest application and threat signatures (based on your custom settings), it starts enforcing security policy based on the latest App-IDs and threat protection without any additional configuration. Because new App-IDs can change how the security policy enforces traffic, this more limited release of new App-IDs is intended to provide you with a predictable window in which you can prepare and update your security policy. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/app-and-threat-content-updates
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago