Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 164 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 164
Topic #: 1
[All PCNSE Questions]

How can an administrator configure the firewall to automatically quarantine a device using GlobalProtect?

  • A. by adding the device's Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device
  • B. by exporting the list of quarantined devices to a pdf or csv file by selecting PDF/CSV at the bottom of the Device Quarantine page and leveraging the appropriate XSOAR playbook
  • C. by using security policies, log forwarding profiles, and log settings
  • D. there is no native auto-quarantine feature so a custom script would need to be leveraged
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically- quarantine-a-device

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mmed
Highly Voted 3 years, 1 month ago
confirm c https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html
upvoted 7 times
...
Marshpillowz
Most Recent 2 months, 4 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
lol12
1 year, 6 months ago
Selected Answer: C
C https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device
upvoted 3 times
...
NLT
2 years, 1 month ago
After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings.
upvoted 4 times
...
Gilmarcio
2 years, 2 months ago
Correct "C" https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device.html#idb42b2b82-b253-4be7-9840-1efa49dba3da
upvoted 1 times
...
Plato22
2 years, 4 months ago
Answer is C. Read the wording of the question and then find the answer here: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html
upvoted 3 times
...
prosto_marussia
2 years, 4 months ago
After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings. Both A and C kinda work.
upvoted 1 times
Martian89
1 year, 9 months ago
A is not automatic though (question is about automatic quarantine)
upvoted 2 times
...
...
Biz90
2 years, 6 months ago
Hi Team, the answer is A based on the KB below it even tells you that: 'you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device'
upvoted 1 times
Breyarg
2 years, 3 months ago
i agree but then re-read the question it implies "automatically" which suggests no manual intervention. so only "C" can be correct now.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...