pcnsa question 327 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 327

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact and command-and-control (C2) server.
Which security profile components will detect and prevent this threat after the firewall's signature database has been updated?

  • A. antivirus profile applied to outbound security policies
  • B. data filtering profile applied to inbound security policies
  • C. data filtering profile applied to outbound security policies
  • D. vulnerability profile applied to inbound security policies
Answer:

c

User Votes:
A 4 votes
50%
B
50%
C 3 votes
50%
D 1 votes
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

An antivirus profile is specifically designed to detect and block malware based on signatures. Since the malware will attempt to communicate with a C2 server, the outbound traffic from infected hosts needs to be monitored.