Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSA topic 1 question 25 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 25
Topic #: 1
[All PCNSA Questions]

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command- and-control (C2) server.
Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)

  • A. vulnerability protection profile applied to outbound security policies
  • B. anti-spyware profile applied to outbound security policies
  • C. antivirus profile applied to outbound security policies
  • D. URL filtering profile applied to outbound security policies
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/policy/create-best-practice-security-profiles

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Cyril_the_Squirl
Highly Voted 2 years, 8 months ago
B & D are Correct
upvoted 9 times
...
azzawim
Most Recent 2 days, 18 hours ago
Selected Answer: BD
answer is B&D
upvoted 1 times
...
cjace
1 month, 2 weeks ago
B & C is correct
upvoted 1 times
...
cjace
1 month, 2 weeks ago
While URL filtering (D) is beneficial and can contribute to preventing access to known malicious sites, it is not as effective as Anti-spyware (B) and Antivirus (C) profiles in detecting and preventing malware infections and their subsequent C2 communications directly. Thus, the primary tools for handling this threat after the signature database update would be Anti-spyware and Antivirus profiles.
upvoted 1 times
...
cjace
1 month, 2 weeks ago
B & D is correct
upvoted 1 times
...
davidmdlp85
3 months ago
Selected Answer: BC
I believe the key is in the question, when says Detect (spyware) and prevent (antivirus). Antivirus profiles protect against viruses, worms, and trojans as well as spyware downloads. Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers, allowing you to detect malicious traffic leaving the network from infected clients.
upvoted 2 times
...
agatica
5 months ago
Selected Answer: BD
B&D -Anti-spyware is the only profile type that specifies c2 protections. -URL Filtering (command and control category) because the IP and URL associated with the c2 server will be added to a table of known malicious actors with the signature update.
upvoted 3 times
...
Aiazd
7 months, 1 week ago
Selected Answer: BC
Read the question: Which profiles will DETECT (anti-virus, URL doesn't do detection it does filtering) and PREVENT from communicating (anti-spyware) + it's based on the signature database update So A & C
upvoted 3 times
...
rt_85
9 months ago
B&D -Anti-spyware is the only profile type that specifies c2 protections. -URL Filtering because the IP and URL associated with the c2 server will be added to a table of known malicious actors with the signature update.
upvoted 2 times
...
BMRobertson
1 year, 5 months ago
Its B&C; Take a look at the PCNSA studyguide (https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnsa-study-guide.pdf) and do a ctrl-F for "C2"...the only things that come up explicitly are Antispyware (p. 86, 90) and Antivirus (p. 35). Page 86 connects Antivirus with Wildfire which "also provides signatures for the persistent threats that are more evasive and have not yet been discovered by other antivirus solutions. As WildFire discovers threats, signatures are quickly created and then integrated into the standard antivirus signatures, which Threat Prevention subscribers can then download daily (sub-hourly for WildFire subscribers)"
upvoted 1 times
...
83KG
1 year, 5 months ago
Selected Answer: BC
Page 35 https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnsa-study-guide.pdf
upvoted 3 times
...
argyris23
1 year, 5 months ago
I was thinking B and D and I gmade this question to ChatGPT. It replied C and D and here is what is answers when I asked why B is not a correct answer: B. Anti-spyware profile is a type of security profile that is typically used to prevent spyware and other malicious software from being installed on a network's endpoints. It may not be the best solution to detect and prevent malware that has already infected a host and is attempting to communicate with a C2 server. In this case, an antivirus profile (C.), which specifically detects and prevents the spread of viruses and other malicious software, would be more appropriate. Additionally, a URL filtering profile (D.), which blocks access to malicious or undesirable websites, could be used to prevent the infected host from communicating with the C2 server.
upvoted 1 times
halifax
1 year, 2 months ago
ChatGPT is stupid lol - How is website address blocking going to help you? The malware is already inside your network. The malware isn't going to use url to contact the C2 server it is already on the same network; it will use other protocols for the special delivery to C2 server.
upvoted 3 times
captainpratt
11 months, 1 week ago
you are right about that..
upvoted 1 times
...
...
...
gbongain
1 year, 5 months ago
Selected Answer: BC
This is Anti-Spyware but also Antivirus. The question says how the FW will detect it after 'signature update', meaning the malware signatures that the device can detect. URL filtering provide another solution but nothing to do with signatures.
upvoted 2 times
...
Merlin0o
1 year, 6 months ago
Selected Answer: BC
B & C Should be correct, pages of the study guide: 36: Antivirus 133 4.1.2 Anti-Spyware
upvoted 1 times
...
PunkSp
1 year, 7 months ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles
upvoted 1 times
...
PLO
1 year, 10 months ago
Selected Answer: BD
B & D are correct
upvoted 2 times
...
domesticpig
1 year, 11 months ago
A & D - Page 134
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in