exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 50 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 50
Topic #: 1
[All PCNSE Questions]

If the firewall is configured for credential phishing prevention using the `Domain Credential Filter` method, which login will be detected as credential theft?

  • A. Mapping to the IP address of the logged-in user.
  • B. First four letters of the username matching any valid corporate username.
  • C. Using the same user's corporate username and password.
  • D. Matching any valid corporate username.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Silent_Sanctuary
Highly Voted 4 years, 5 months ago
Correct Answer is C The Windows-based User‐ID agent is installed on a Read-Only Domain Controller (RODC). The User‐ID agent collects password hashes that correspond to users for which you want to enable credential detection and sends these mappings to the firewall. The firewall then checks if the source IP address of a session matches a username and if the password submitted to the webpage belongs to that username. With this mode, the firewall blocks or alerts on the submission only when the password submitted matches a user password.
upvoted 13 times
...
Sammy3637
Highly Voted 4 years, 10 months ago
correct answer is C
upvoted 5 times
...
Marshpillowz
Most Recent 9 months, 2 weeks ago
Selected Answer: C
Correct answer is C
upvoted 1 times
...
JRKhan
9 months, 4 weeks ago
Selected Answer: C
C is correct. With Domain credential method, firewall check both the username and password submitted on the untrusted/potentially phishing website.
upvoted 1 times
...
lol12
2 years ago
Selected Answer: A
I think it's A. Domain Credential Filter - To verify that the credentials belong to the login username—The firewall looks for a mapping between the IP address of the login username and the detected username in its IP address-to-username mapping table.
upvoted 1 times
...
JMIB
2 years, 2 months ago
C is a correct. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/prevent-credential-phishing/methods-to-check-for-corporate-credential-submissions
upvoted 1 times
...
UFanat
2 years, 4 months ago
Selected Answer: C
C is a correct. A - for ip user mapping not domain https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/prevent-credential-phishing/methods-to-check-for-corporate-credential-submissions
upvoted 2 times
...
tenebrox
2 years, 4 months ago
Selected Answer: C
Correct Answer is C
upvoted 2 times
...
Jared28
2 years, 7 months ago
Selected Answer: C
In PCNSE Beacon Practice exam, confirms C but likely retired
upvoted 3 times
...
wmelo
3 years, 3 months ago
Correct Answer C Use Domain Credential Filter—Checks for valid corporate usernames and password submissions and verifies that the submitted credentials match the user logged into the source IP address of the session. Link: https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/credential-phishing-prevention
upvoted 2 times
...
nashwan19
3 years, 4 months ago
C is the correct answer https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/threat-prevention/prevent-credential-phishing/methods-to-check-for-corporate-credential-submissions.html#id29eff481-13de-45b9-b73c-83e2e932ba20
upvoted 2 times
...
YasserSaied
3 years, 4 months ago
C -- is the correct answer
upvoted 1 times
...
yogininangpal
3 years, 5 months ago
What is the question that is being asked does the question ask about if Domain credential filter is implemented how does the credential theft detected then the answer is C, maybe Palo needs to get people to write exam questions correctly and ask what they really mean!! There is no reason to ask trick question when you are trying to test knowledge for the product!!
upvoted 2 times
...
trashboat
3 years, 6 months ago
C is the answer, since the question asks about Domain Credential Filter credential checking. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/url-filtering/prevent-credential-phishing/methods-to-check-for-corporate-credential-submissions.html#id29eff481-13de-45b9-b73c-83e2e932ba20
upvoted 1 times
...
jordan_gsi
3 years, 7 months ago
read carefully, question it self said using “Domain Credential Filter method” if you are using that method : detects whether a user is submitting a valid username and password and that those credentials match the user who is logged in to the source IP address of the session, Configure Credential Detection with the Windows-basedUser-IDAgent and Map IP Addresses to Users. but if you are using IP user mapping method A: would be the right answer, below the KB Enjoy! https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/content-inspection-features/credential-phishing-prevention
upvoted 2 times
...
reyesm
3 years, 9 months ago
Use Domain Credential Filter—Checks for valid corporate usernames and password submissions and verifies that the username maps to the IP address of the logged in user.
upvoted 1 times
...
trykali
3 years, 10 months ago
The answer is C, IP-User: This credential detection method checks for valid username submissions. You can use this method to detect credential submissions that include a valid corporate username (regardless of the accompanying password). Domain Credential: This credential detection method enables the firewall to check for a valid corporate username and the associated password. The firewall determines if the username and password a user submits matches the same user’s corporate username and password.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago