When configuring Remote Browser Isolation (RBI) with Prisma Access (Managed by Strata Cloud Manager), which element is required to define the protected URLs for mobile users?
A.
A URL access management profile with site access set to " Isolate " applied to a Security policy
B.
A DNS Security profile applied to a Security policy with the action of " Isolate " for the target remote browser DNS categories
C.
An RBI profile applied to the URL access management profile
D.
A Security policy with the target URL categories and set the action to " Isolate "
Native RBI by Palo Alto Networks is built directly on top of the existing URL Access Management framework rather than introducing a separate, parallel policy construct: an administrator creates or updates a URL Access Management profile, selects the specific URL website categories that should undergo isolation, and associates an isolation profile with those categories to define what browser actions (copy/paste, uploads, downloads, printing) are permitted during the isolated session. That URL Access Management profile is then applied to a Security policy rule the same way any other URL filtering profile would be, which is precisely the configuration path option A describes and is confirmed by Palo Alto Networks ' own RBI configuration documentation. Option D is close but structurally imprecise — a Security policy rule alone, without a properly configured URL Access Management profile carrying the " Isolate " site access action for the relevant categories, is not sufficient; the isolation logic itself lives in the profile object, not as a directly assignable Security policy action independent of that profile. There is no DNS Security profile mechanism for triggering isolation (option B); DNS Security governs DNS-based threat detection and sinkholing, an entirely separate capability unrelated to browser isolation triggers. Option C inverts the actual object relationship: an isolation profile is attached to the URL Access Management profile, not the reverse, so describing an " RBI profile applied to the URL access management profile " as the defining element misstates which object drives which.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit