An administrator needs to allow DNS traffic from the Trust zone to the Untrust zone. The security policy rule uses the application 'dns' and service 'application-default'. Which port will be allowed by default?
The 'dns' application uses TCP and UDP port 53 by default. When 'application-default' is selected, the firewall automatically permits these ports. This is the correct answer because DNS primarily relies on port 53 for both TCP and UDP. Allowing this service ensures DNS queries and responses can pass.
Why this answer
The 'dns' application in Palo Alto Networks firewalls uses both TCP and UDP port 53. When 'application-default' is selected, the firewall automatically allows these ports. This ensures that DNS queries, responses, and zone transfers function properly without manual service definition.
Exam trap
The trap here is assuming DNS only uses UDP; however, TCP port 53 is also included in the default service for the 'dns' application.