Free Palo Alto Networks Cybersecurity-Apprentice Actual Exam Questions - Question 13 Discussion

Question No. 13
You are configuring a Palo Alto Networks firewall for an organization. The goal is to allow inbound traffic
from a trusted partner's IP range (192.168.10.0/24) to access the organization's web server on port 443
securely. At the same time, you must block all other traffic from untrusted external sources to the web
server. Which two actions correctly configure the firewall rules to meet the requirements? (Choose two)
Select all that apply, then reveal solution.
US
VE
Vikas E.
2026-02-10

B definitely, since it targets the trusted IP range and port 443 specifically. C makes sense too to block everything else from untrusted sources, keeping the access tight and secure.

0
VE
Vikas E.
2026-02-09

It’s definitely B and C again for me. Allowing only that specific IP range to port 443 keeps the access tight and secure, while the deny-all rule makes sure nothing else slips in. A and D don’t really fit because port 80 isn’t part of the requirement, and SSL decryption isn’t necessary just to allow or block traffic. E’s about NAT, which isn’t mentioned or required here. So sticking with B and C covers both allowing the right traffic and blocking everything else effectively.

0
VE
Vikas E.
2026-01-29

It’s B and C. Allowing only the partner’s IP range on port 443 keeps it tight, and having a default deny rule ensures no other traffic sneaks through. The rest don’t directly address the secure, limited access goal.

0
VE
Vikas E.
2026-01-29

Better to rule out A and D here. Port 80 isn’t needed since the question only mentions secure access on 443, so enabling port 80 from all external IPs contradicts the “block all other traffic” part. SSL decryption (D) might be useful but isn’t a must-have to meet the core requirement of allowing trusted IPs and blocking others. B allows the trusted partner’s range explicitly on 443, and C ensures no other untrusted traffic sneaks through, so those two fit best.

0
SW
Shoaib W.
2026-01-26

B imo, since it explicitly allows the partner’s IP range on 443.

0
AK
Andre K.
2026-01-25

Maybe C is key since a deny-all rule after the allow is standard practice. Also, B makes sense because it specifically allows the partner’s IP range on port 443, which fits the requirement perfectly.

0
IP
Imran P.
2026-01-15

B and C

0