URL Category in the security policy match criteria allows you to vary the security profiles based on the URL category. Security profiles are things like AntiVirus Profiles, Vulnerability Profiles, WildFire Profiles, Anti-Spyware Profiles, File Blocking Profiles, Data Filtering Profiles, etc. One common use-case is to allow users to visit questionable URL categories, but restrict the file types they can download from those locations. You need 2 security policy rules to accomplish this. The first policy allows web-browsing with URL category = unknown/parked/insufficient, and then you attach a strict file blocking profile that prevents dangerous file types from being downloaded (PE, pdf, office, java, flash, etc.) The 2nd security policy is for web-browsing in general, no URL category match, but then you can attach a less restrictive file blocking profile that allows PDFs, office docs, etc. This concept/tactic is discussed in a little more detail in the "Best Practices for Ransomware Prevention" document, Step #4, found here: - https://live.paloaltonetworks.com/t5/Featured-Articles/Best-Practices-for-Ransomware-Prevention/ta-p/74148
... View more