nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #146

Which Security profile would you apply to identify infected hosts on the protected network using DNS traffic?

The correct answer is C. anti-spyware. In addition, you can enable the DNS Sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. This feature helps to identify inf

Threat Prevention

Question

Which Security profile would you apply to identify infected hosts on the protected network using DNS traffic?

Options

  • AURL traffic
  • Bvulnerability protection
  • Canti-spyware
  • Dantivirus

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    16% (5)
  • C
    72% (23)
  • D
    3% (1)

Explanation

In addition, you can enable the DNS Sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. This feature helps to identify infected hosts on the protected network using DNS traffic.

Topics

#anti-spyware#DNS sinkhole#command and control#infected host detection

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice