nerdexam
Palo_Alto_Networks

PCNSA · Question #16

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which…

The correct answer is B. anti-spyware profile applied to outbound security policies C. antivirus profile applied to outbound security policies. Anti-spyware (B) is specifically designed to detect malware attempting to "phone home" - its primary function is identifying command-and-control traffic patterns, making it the most direct match for this threat. Antivirus (C) complements this by detecting the malware payload…

Submitted by ngozi_ng· Apr 18, 2026Securing Traffic

Question

An administrator receives a global notification for a new malware that infects hosts. The infection will result in the infected host attempting to contact a command-and-control (C2) server. Which two security profile components will detect and prevent this threat after the firewall's signature database has been updated? (Choose two.)

Options

  • Avulnerability protection profile applied to outbound security policies
  • Banti-spyware profile applied to outbound security policies
  • Cantivirus profile applied to outbound security policies
  • DURL filtering profile applied to outbound security policies

How the community answered

(47 responses)
  • A
    13% (6)
  • B
    83% (39)
  • D
    4% (2)

Explanation

Anti-spyware (B) is specifically designed to detect malware attempting to "phone home" - its primary function is identifying command-and-control traffic patterns, making it the most direct match for this threat. Antivirus (C) complements this by detecting the malware payload itself within outbound traffic sessions once the signature database is updated with the new threat's signature.

Vulnerability protection (A) is wrong because it defends against exploit attempts targeting software vulnerabilities (think inbound attacks against your systems), not outbound C2 communications from already-infected hosts. URL filtering (D) is wrong because it operates on a separate URL category database - a malware signature database update doesn't enhance URL filtering's ability to block C2 domains.

Memory tip: Match the profile to the direction and behavior of the threat. "Spyware" = spying/reporting out → anti-spyware blocks the C2 callback. "Virus" = the malicious code itself → antivirus catches it in transit. Vulnerability protection is for inbound exploitation, not outbound infection traffic.

Topics

#Security Profiles#Malware Prevention#Anti-Spyware#Antivirus

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice