nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #359

Which Security profile must be added to Security policies to enable DNS Signatures to be checked?

The correct answer is C. Anti-Spyware. In addition, you can enable the DNS sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. https://docs.paloaltonetworks.com/

Threat Prevention

Question

Which Security profile must be added to Security policies to enable DNS Signatures to be checked?

Options

  • AURL Filtering
  • BVulnerability Protection
  • CAnti-Spyware
  • DAntivirus

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    12% (2)
  • C
    76% (13)
  • D
    6% (1)

Explanation

In addition, you can enable the DNS sinkholing action in Anti-Spyware profiles to enable the firewall to forge a response to a DNS query for a known malicious domain, causing the malicious domain name to resolve to an IP address that you define. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/security-profiles

Topics

#DNS signatures#anti-spyware#security profiles#DNS security

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice