exam questions

Exam PCSFE All Questions

View all questions & answers for the PCSFE exam

Exam PCSFE topic 1 question 125 discussion

Actual exam question from Palo Alto Networks's PCSFE
Question #: 125
Topic #: 1
[All PCSFE Questions]

Which three traffic flows can protect against zero-day attacks? (Choose three.)

  • A. Outbound
  • B. North-south
  • C. Inbound
  • D. Internal
  • E. East-west
Show Suggested Answer Hide Answer
Suggested Answer: ACE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
davidtolo
10 months, 3 weeks ago
I say B,C, E Here's a brief explanation: North-south traffic (B): This refers to traffic that moves between the internal network and external networks, such as the internet. Protecting this traffic flow is critical as it can prevent external threats from entering the network and block outbound communication to malicious sites. Inbound traffic (C): This includes traffic coming into the network from external sources. By inspecting and securing inbound traffic, zero-day threats can be stopped before they reach internal resources. East-west traffic (E): This is the traffic that moves laterally within a data center or network. Protecting east-west traffic helps prevent the spread of threats once they have entered the network, limiting the damage that zero-day attacks can cause within the internal environment.
upvoted 2 times
...
Doobiedoo
1 year ago
Selected Answer: ACD
Of the listed options, only inbound traffic flow inspection can directly protect against zero-day attacks. Here's why the other options are less effective: * Outbound: This inspects traffic leaving the network, which wouldn't necessarily catch malicious code entering from outside. * North-south: This refers to traffic between the internet and the internal network, which includes both inbound and outbound traffic. While inbound traffic is part of north-south flow, it's not the only component. * Internal: This inspects traffic within the internal network, useful for malware detection but not specifically zero-day attacks at the entry point. * East-west: Similar to internal traffic, this focuses on communication between devices within the network, not necessarily catching external threats. Therefore, the most relevant option for zero-day protection is "C": Inbound By inspecting inbound traffic, firewalls can potentially identify and block suspicious activity even if it exploits an unknown vulnerability (zero-day).
upvoted 1 times
Doobiedoo
1 year ago
I choose ""Outbound", "Inbound", and "Internal" because those are terms used with the official IronSkillet object tags and security profile names. So those terms are likely more correct when considering "Palo Alto Terminology" versus using the terms "North-South" and "East-West".
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago