Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
A. Rules without App Controls.
Even if A and D have the same columns and in the same order, here we have rules with any as Apps Allowed, so it is considering Rules without App Controls.
As checked on the actual FW with PANOS 11.0.2, A and D are exactly with the same view in Policy Optimizer.
A. Rules without App Controls
D. Unused Apps
I just checked one more time on the firewall and both answers are correct:
Unused Apps and Without App Control.
Both screens are similar and I could not see any difference in the format. However, the results outcome is different of course.
so I am not quite sure which one should be correct in this case.
Just checked on FW.
There is column Application in New App viewer (3rd, between columns Service and Traffic), which is not present on this pic.
This is only difference between New App V and Rules Wout App Cntrl.
A little more on why it is Rules without Apps Control and not New App Viewer:
Although both are true for this specific screenshot however the difference is that in New App Viewer, we get to see the rules which are configured with applications like web-browsing and such rules are not visible in Rules Without Apps Control. Thus, in New App Viewer, at times we get to see numbers under 'Apps Allowed' whereas on the other hand this column contains 'Any'. Moreover, the New Apps Allowed functionality requires PA Application Cloud Engine (ACE) SaaS subscription to get the App info from cloud DB. The Rules Without Apps Control is on-the-box functionality. Here's the definition from firewall's help page;
New App Viewer—New cloud applications downloaded from the Application Control Engine if the firewall has a SaaS Security subscription.
Rules Without App Controls—Rules that have the application set to any, so you can identify port-based rules to convert to application-based rules.
Cont....
Since the question is asked in simple way without details like conversion of applications (e.g. web-browsing to specific cloud based app), we can safely assume that it is not about New App Viewer.
PS: You can read about Rules Without Apps Control from the link in the original post and for New App Viewer, go to https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/cloud-based-app-id-service/new-app-viewer-policy-optimizer.
I think you are right since by default the column "Application" is displayed in "New App Viewer", here in the screenshot it is not present (verified in PanOS 11 lab). That is why also the correct answer is "Rules without Apps Control" -> A
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
chittadritta
1 day, 9 hours agoShanaia
2 months, 3 weeks agoIE17
4 months, 3 weeks agoCisco995
8 months, 3 weeks agostxc
1 year, 1 month agostxc
1 year, 1 month agonolox
1 year, 2 months agoDatITGuyTho1337
1 year, 3 months agobaccalacca
1 year, 3 months agoDlaEdu_Ex
1 year, 4 months agoOhEmGee
1 year, 5 months agoOhEmGee
1 year, 5 months agoOhEmGee
1 year, 5 months agodrogadotcom
1 year, 2 months agomecacig953
1 year, 5 months agoJ2J2J2J
1 year, 5 months ago