exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 15 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 15
Topic #: 1
[All PCNSA Questions]

Choose the option that correctly completes this statement. A Security Profile can block or allow traffic ____________.

  • A. on either the data place or the management plane.
  • B. after it is matched by a security policy rule that allows traffic.
  • C. before it is matched to a Security policy rule.
  • D. after it is matched by a security policy rule that allows or blocks traffic.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Angel123
Highly Voted 4 years ago
'B' is correct answer according PCNSA Study Guide 2020, p.131 After a packet has been allowed by the Security policy, Security Profiles are used to scan packets for threats, vulnerabilities, viruses, spyware, malicious URLs, data exfiltration, and exploitation software.
upvoted 21 times
...
nabilzay
Highly Voted 4 years, 4 months ago
B is the correct answer, the security policy has to allow the traffic for the security profile to take action
upvoted 15 times
...
[Removed]
Most Recent 1 week, 4 days ago
Selected Answer: B
No reason to scan if the traffic is blocked. Must be allowed for security profile to take effect
upvoted 1 times
...
dragossky
8 months ago
Selected Answer: B
Security Profiles are not used in the match criteria of a traffic flow. The Security Profile is applied to scan traffic after the application or category is allowed by the Security policy rule.
upvoted 1 times
...
vinicius27
11 months ago
I believe that is a 'B' is correct, and "D" not is the correct. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles "Security Profiles are not used in the match criteria of a traffic flow. The Security Profile is applied to scan traffic after the application or category is allowed by the Security policy rule."
upvoted 1 times
...
Snookerloopy
1 year, 3 months ago
Selected Answer: B
you dont put security profiles on a security policy that denies traffic
upvoted 1 times
...
Rivand
1 year, 7 months ago
Selected Answer: B
t's B. D is wrong, the Profile can only take actions if the traffic is allowed by the security policy rule.
upvoted 1 times
...
claudio392
1 year, 8 months ago
Of course B
upvoted 1 times
...
Aaronyukin
1 year, 8 months ago
"B" is the Correct, as it is shown in the PCNSE exam questions.
upvoted 1 times
...
[Removed]
1 year, 12 months ago
Selected Answer: B
B is correct answer.
upvoted 2 times
...
all_nicknames_are_taken
2 years, 1 month ago
B: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles
upvoted 1 times
...
Najmmm
2 years, 2 months ago
Security policy rules allow or block traffic in network, while security profiles scans the applications for threats, such as viruses, malware, spyware, and DDOS attacks. So the answer B is correct as the traffic will need to be allowed first for security profiles scans
upvoted 1 times
Najmmm
2 years, 2 months ago
While security policy rules enable you to allow or block traffic on your network, security profiles help you define an allow but scan rule, which scans allowed applications for threats, such as viruses, malware, spyware, and DDOS attacks
upvoted 1 times
...
...
argyris23
2 years, 3 months ago
Selected Answer: C
Definitely C!, if the security rule blocks the traffic it will never make it to the security profiles
upvoted 1 times
...
daytonadave2011
2 years, 4 months ago
Selected Answer: B
B is correct. Remember the Security Policy at the end of the Policy must be set to Allow, then you can add additional policies to check prior to allowing the traffic.
upvoted 1 times
...
DDisGR8
2 years, 8 months ago
Selected Answer: B
B is the correct answer
upvoted 1 times
...
seb_berlin
2 years, 9 months ago
Selected Answer: B
Of course is B the right answer. Took the PAN-EDU-210 a few weeks ago the course material says so as well as -> https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-profiles While security policy rules enable you to allow or block traffic on your network, security profiles help you define an allow but scan rule, which scans allowed applications for threats, such as viruses, malware, spyware, and DDOS attacks. When traffic matches the allow rule defined in the security policy, the security profile(s) that are attached to the rule are applied for further content inspection rules such as antivirus checks and data filtering.
upvoted 1 times
...
scanossa
2 years, 10 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago