pcnsa question 225 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 225

An administrator needs to add capability to perform real time signature lookups to block or sinkhole all known malware domains.
Which type of single, unified engine will get this result?

  • A. Content ID
  • B. App-ID
  • C. Security Processing Engine
  • D. User-ID
Answer:

c

User Votes:
A 1 votes
50%
B
50%
C 1 votes
50%
D
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

Content-ID gives you a real-time threat prevention engine, combined with a comprehensive URL database, and elements of application identification to:

Limit unauthorized data and file transfers
Detect and block exploits, malware and malware communications
Control unapproved web surfing

sara123
1 month, 3 weeks ago

Content ID: This unified engine is responsible for inspecting traffic and applying various security mechanisms, including blocking or sinkholing domains associated with malware. It leverages the threat intelligence database to perform real-time lookups against known malware signatures.