NETSEC-ANALYST · Question #359
Which Security profile must be added to Security policies to enable DNS Signatures to be checked?
The correct answer is C. Anti-Spyware. In addition, you can enable the DNS sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define…
Question
Which Security profile must be added to Security policies to enable DNS Signatures to be checked?
Options
- AURL Filtering
- BVulnerability Protection
- CAnti-Spyware
- DAntivirus
How the community answered
(17 responses)- A6% (1)
- B12% (2)
- C76% (13)
- D6% (1)
Explanation
In addition, you can enable the DNS sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/security-profiles
Topics
Community Discussion
No community discussion yet for this question.