exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 25 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 25
Topic #: 1
[All PCNSA Questions]

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command- and-control (C2) server.
Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)

  • A. vulnerability protection profile applied to outbound security policies
  • B. anti-spyware profile applied to outbound security policies
  • C. antivirus profile applied to outbound security policies
  • D. URL filtering profile applied to outbound security policies
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cyril_the_Squirl
Highly Voted 3 years, 9 months ago
B & D are Correct
upvoted 12 times
...
Haryor
Most Recent 6 months ago
Selected Answer: BC
Anti-virus will protect against virus and worms while antispyware will prevent infected hosts from trying to contact C2 which is the attacker host
upvoted 1 times
...
azzawim
1 year ago
Selected Answer: BD
answer is B&D
upvoted 2 times
...
cjace
1 year, 2 months ago
B & C is correct
upvoted 1 times
...
cjace
1 year, 2 months ago
While URL filtering (D) is beneficial and can contribute to preventing access to known malicious sites, it is not as effective as Anti-spyware (B) and Antivirus (C) profiles in detecting and preventing malware infections and their subsequent C2 communications directly. Thus, the primary tools for handling this threat after the signature database update would be Anti-spyware and Antivirus profiles.
upvoted 2 times
...
cjace
1 year, 2 months ago
B & D is correct
upvoted 1 times
...
agatica
1 year, 5 months ago
Selected Answer: BD
B&D -Anti-spyware is the only profile type that specifies c2 protections. -URL Filtering (command and control category) because the IP and URL associated with the c2 server will be added to a table of known malicious actors with the signature update.
upvoted 4 times
...
Aiazd
1 year, 7 months ago
Selected Answer: BC
Read the question: Which profiles will DETECT (anti-virus, URL doesn't do detection it does filtering) and PREVENT from communicating (anti-spyware) + it's based on the signature database update So A & C
upvoted 4 times
...
rt_85
1 year, 9 months ago
B&D -Anti-spyware is the only profile type that specifies c2 protections. -URL Filtering because the IP and URL associated with the c2 server will be added to a table of known malicious actors with the signature update.
upvoted 3 times
...
BMRobertson
2 years, 5 months ago
Its B&C; Take a look at the PCNSA studyguide (https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnsa-study-guide.pdf) and do a ctrl-F for "C2"...the only things that come up explicitly are Antispyware (p. 86, 90) and Antivirus (p. 35). Page 86 connects Antivirus with Wildfire which "also provides signatures for the persistent threats that are more evasive and have not yet been discovered by other antivirus solutions. As WildFire discovers threats, signatures are quickly created and then integrated into the standard antivirus signatures, which Threat Prevention subscribers can then download daily (sub-hourly for WildFire subscribers)"
upvoted 1 times
...
83KG
2 years, 5 months ago
Selected Answer: BC
Page 35 https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnsa-study-guide.pdf
upvoted 3 times
...
argyris23
2 years, 5 months ago
I was thinking B and D and I gmade this question to ChatGPT. It replied C and D and here is what is answers when I asked why B is not a correct answer: B. Anti-spyware profile is a type of security profile that is typically used to prevent spyware and other malicious software from being installed on a network's endpoints. It may not be the best solution to detect and prevent malware that has already infected a host and is attempting to communicate with a C2 server. In this case, an antivirus profile (C.), which specifically detects and prevents the spread of viruses and other malicious software, would be more appropriate. Additionally, a URL filtering profile (D.), which blocks access to malicious or undesirable websites, could be used to prevent the infected host from communicating with the C2 server.
upvoted 1 times
halifax
2 years, 3 months ago
ChatGPT is stupid lol - How is website address blocking going to help you? The malware is already inside your network. The malware isn't going to use url to contact the C2 server it is already on the same network; it will use other protocols for the special delivery to C2 server.
upvoted 3 times
captainpratt
1 year, 12 months ago
you are right about that..
upvoted 1 times
...
...
...
gbongain
2 years, 6 months ago
Selected Answer: BC
This is Anti-Spyware but also Antivirus. The question says how the FW will detect it after 'signature update', meaning the malware signatures that the device can detect. URL filtering provide another solution but nothing to do with signatures.
upvoted 4 times
...
Merlin0o
2 years, 7 months ago
Selected Answer: BC
B & C Should be correct, pages of the study guide: 36: Antivirus 133 4.1.2 Anti-Spyware
upvoted 1 times
...
PunkSp
2 years, 7 months ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles
upvoted 1 times
...
PLO
2 years, 11 months ago
Selected Answer: BD
B & D are correct
upvoted 2 times
...
domesticpig
3 years ago
A & D - Page 134
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...