PCNSA · Question #211
An administrator needs to add capability to perform real-time signature lookups to block or sinkhole all known malware domains. Which type of single unified engine will get this result?
The correct answer is D. Content-ID. Content-ID is Palo Alto Networks' single unified threat inspection engine that performs real-time content analysis, including DNS-based lookups against Palo Alto Networks' threat intelligence to block or sinkhole known malware domains. It integrates IPS, anti-malware, URL…
Question
An administrator needs to add capability to perform real-time signature lookups to block or sinkhole all known malware domains. Which type of single unified engine will get this result?
Options
- AUser-ID
- BApp-ID
- CSecurity Processing Engine
- DContent-ID
How the community answered
(39 responses)- A3% (1)
- B3% (1)
- C5% (2)
- D90% (35)
Explanation
Content-ID is Palo Alto Networks' single unified threat inspection engine that performs real-time content analysis, including DNS-based lookups against Palo Alto Networks' threat intelligence to block or sinkhole known malware domains. It integrates IPS, anti-malware, URL filtering, and DNS security capabilities. User-ID (A) maps IP addresses to usernames. App-ID (B) identifies applications. The Security Processing Engine (C) is the underlying hardware/software processing platform, not a specific feature engine for threat lookup.
Topics
Community Discussion
No community discussion yet for this question.