nerdexam
Palo_Alto_Networks

NETSEC-GENERALIST · Question #19

In conjunction with Advanced URL Filtering, which feature can be enabled after usemame-to-IP mapping is set up?

The correct answer is B. Credential phishing prevention. Credential phishing prevention is a feature that requires both Advanced URL Filtering and User-ID (username-to-IP mapping) to function. Once User-ID is configured, the firewall knows which user is associated with each IP address. Advanced URL Filtering then identifies when a…

Threat Prevention

Question

In conjunction with Advanced URL Filtering, which feature can be enabled after usemame-to-IP mapping is set up?

Options

  • AHost information profile (HIP)
  • BCredential phishing prevention
  • CClient probing
  • DIndexed data matching

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    87% (48)
  • C
    4% (2)
  • D
    7% (4)

Explanation

Credential phishing prevention is a feature that requires both Advanced URL Filtering and User-ID (username-to-IP mapping) to function. Once User-ID is configured, the firewall knows which user is associated with each IP address. Advanced URL Filtering then identifies when a user attempts to submit corporate credentials (usernames and passwords) to a website categorized as phishing or an unknown/risky site. Together, these two technologies allow the firewall to block credential submission to unauthorized sites, protecting against account compromise via phishing. Host Information Profile or HIP (A) is a GlobalProtect feature that collects endpoint posture data and is not dependent on URL Filtering. Client probing (C) is a User-ID mechanism for mapping usernames to IPs and is an input to User-ID, not an output. Indexed data matching (D) is a Data Loss Prevention concept unrelated to URL Filtering and user mapping.

Topics

#Credential Phishing Prevention#Advanced URL Filtering#User-ID#Palo Alto Networks

Community Discussion

No community discussion yet for this question.

Full NETSEC-GENERALIST Practice