Man, Palo loves making these sound trickier than they are. B imo, application filter is what you want since it auto-includes any new high-risk apps in future content updates. Static group (C) wouldn't keep up. Seen similar in practice tests so pretty confident here.
Q: 4
Which object would an administrator create to block access to all high-risk applications?
Options
Discussion
Probably B since application filter will catch all current and future high-risk apps by risk attribute, so you don't have to update anything manually. Official guides and some practice exams mention this being the easiest way when blocking a whole risk category. Not 100% but that's what I'd pick from experience.
B tbh. Application filter is the one that grabs all high-risk apps dynamically, perfect for this use case.
B pretty sure the policy checks pre-NAT stuff for both address and zone right? Someone correct me if I'm off.
Be respectful. No spam.
Question 4 of 35