nerdexam
Palo_Alto_Networks

PCNSA · Question #126

A Security Profile can block or allow traffic at which point?

The correct answer is A. after it is matched to a Security policy rule that allows traffic. Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection, etc.) are applied as a second layer of inspection only after traffic has already been permitted by a Security policy rule. They cannot act on traffic that is blocked by policy because blocked traffic is…

Submitted by ricky.ec· Apr 18, 2026Securing Traffic

Question

A Security Profile can block or allow traffic at which point?

Options

  • Aafter it is matched to a Security policy rule that allows traffic
  • Bon either the data plane or the management plane
  • Cafter it is matched to a Security policy rule that allows or blocks traffic
  • Dbefore it is matched to a Security policy rule

How the community answered

(18 responses)
  • A
    94% (17)
  • C
    6% (1)

Explanation

Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection, etc.) are applied as a second layer of inspection only after traffic has already been permitted by a Security policy rule. They cannot act on traffic that is blocked by policy because blocked traffic is dropped before content inspection occurs. A Security Profile attached to an 'allow' rule instructs the firewall's content inspection engines to scan the permitted traffic for threats. Option C is incorrect because profiles are never evaluated on rules that block traffic. Option D is incorrect because profiles operate after policy matching, not before. Option B is incorrect because Security Profiles operate exclusively on the data plane, not the management plane.

Topics

#Security Profiles#Traffic Processing#Packet Flow#Security Policy

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice