exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 192 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 192
Topic #: 1
[All PCNSA Questions]

You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact command-and-control server.
Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection?

  • A. Anti-Spyware Profile
  • B. Data Filtering Profile
  • C. Antivirus Profile
  • D. Vulnerability Protection Profile
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Zeruz
9 months ago
Selected Answer: A
A: Anti-spyware does C2 traffic blocking.
upvoted 2 times
...
guuillauume
1 year ago
why not antivirus ?
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: A
correct
upvoted 1 times
...
Najmmm
1 year, 6 months ago
Selected Answer: A
"Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers"
upvoted 2 times
...
Alex48694
1 year, 6 months ago
Selected Answer: A
Anti-Spyware Profile
upvoted 1 times
...
TheMaster01
1 year, 7 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
Hyay
1 year, 7 months ago
Selected Answer: A
"Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers"
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago