NETSEC-ANALYST · Question #16
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which…
The correct answer is B. anti-spyware profile applied to outbound security policies C. antivirus profile applied to outbound security policies. Antivirus: Includes new and updated antivirus signatures, including WildFire signatures and automatically generated command-and-control (C2) signatures. WildFire signatures detect malware seen first by firewalls from around the world. You must have a Threat Prevention…
Question
An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)
Options
- Avulnerability protection profile applied to outbound security policies
- Banti-spyware profile applied to outbound security policies
- Cantivirus profile applied to outbound security policies
- DURL filtering profile applied to outbound security policies
How the community answered
(21 responses)- A5% (1)
- B81% (17)
- D14% (3)
Explanation
Antivirus: Includes new and updated antivirus signatures, including WildFire signatures and automatically generated command-and-control (C2) signatures. WildFire signatures detect malware seen first by firewalls from around the world. You must have a Threat Prevention subscription to get these updates. New antivirus signatures are published daily. Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers, allowing you to detect malicious traffic leaving the network from infected clients. You can apply various levels of protection between https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-profiles
Topics
Community Discussion
No community discussion yet for this question.