mediumMultiple ChoiceObjective-mapped
PCNSA Practice Question: Is creating a security policy that should allow…
A security engineer is creating a security policy that should allow access to Salesforce.com for the sales team. The engineer configures the policy to allow application 'ssl' with no restriction on URL category. How can the engineer ensure that only traffic to Salesforce.com is allowed and not all SSL traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use App-ID to identify the 'salesforce' application and add a URL category for Salesforce domains.
Using App-ID to identify the 'salesforce' application and adding a URL category for Salesforce domains ensures only traffic to Salesforce.com is allowed, not all SSL traffic. Option A is wrong because allowing all SSL traffic is too broad and does not restrict to Salesforce. Option B is wrong because 'web-browsing' is not specific to Salesforce and URL category alone cannot enforce application control. Option D is wrong because SSL decryption inspects traffic but does not restrict access to specific sites without additional policy configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a destination address object for the known Salesforce IP addresses.
Why it's wrong here
IP addresses can change and are not as reliable as App-ID and URL filtering.
- ✗
Change the application to 'web-browsing' and restrict by URL category.
Why it's wrong here
Web-browsing is too broad and would allow other web traffic.
- ✓
Use App-ID to identify the 'salesforce' application and add a URL category for Salesforce domains.
Why this is correct
This combination provides precise identification of Salesforce traffic regardless of IP or encryption.
- ✗
Enable SSL decryption to inspect the traffic.
Why it's wrong here
Decryption alone does not enforce which sites are allowed; it only enables inspection.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.