Q: 5
Based on the show security policy rule would match all FTP traffic from the inside zone to the outside
zone?

Options
Discussion
My pick: B, saw a similar question on a practice test and engress outside matched inside to outside FTP traffic.
Anyone double-checked if "engress outside" (B) is actually first in policy order? Remember from a mock that ordering matters, since firewall applies rules top to bottom. Just want to confirm we're all reading the zones right.
Matches what I'd expect too. B lines up since it's specifically for inside to outside traffic, and the application set to any means FTP gets included. I think that's the clear match, unless there's a hidden catch.
B imo. The rule name 'engress outside' is the only one that lines up with source zone inside and destination outside. Plus, application is any which covers FTP. Pretty sure that's what Palo expects, unless another rule above it gets there first but don't see one in the screenshot.
Option B. Not A, that one's for inside to DMZ, which is a common trap answer on these. For FTP from inside to outside, engress outside fits the zone pairing. Pretty sure that's what the exam goes for here.
Has anyone tried checking the official study guide or using the lab for rules matching?
That fits with what I'm seeing. B
B , matches FTP from inside to outside since the rule uses those exact source and destination zones. Also, the app/service fields are set to 'any' and 'application-default', so FTP gets covered. I think this is right unless something above overrides it.
B tbh, unless there's a policy with a more specific app/service match above it that would take precedence.
Not C, A. Antivirus and Vulnerability Protection only scan traffic that's actually permitted by the rule.
Be respectful. No spam.
