PCNSA · Question #262
An administrator wants to prevent hacking attacks through DNS queries to malicious domains. Which two DNS policy actions can the administrator choose in the Anti-Spyware Security Profile? (Choose…
The correct answer is B. block C. sinkhole. An administrator can use 'block' or 'sinkhole' actions in an Anti-Spyware Security Profile to prevent DNS queries to malicious domains.
Question
An administrator wants to prevent hacking attacks through DNS queries to malicious domains. Which two DNS policy actions can the administrator choose in the Anti-Spyware Security Profile? (Choose two.)
Options
- Adeny
- Bblock
- Csinkhole
- Doverride
How the community answered
(29 responses)- A7% (2)
- B90% (26)
- D3% (1)
Why each option
An administrator can use 'block' or 'sinkhole' actions in an Anti-Spyware Security Profile to prevent DNS queries to malicious domains.
'Deny' is a general security policy action, but in the context of DNS policy within Anti-Spyware, 'block' or 'sinkhole' are the specific actions for preventing resolution of malicious domains.
The 'block' action prevents a DNS query to a malicious domain from being resolved, effectively stopping communication to known malicious IPs.
The 'sinkhole' action redirects DNS queries for malicious domains to a specified sinkhole IP address, allowing the firewall to log and track infected hosts.
'Override' is not a standard DNS policy action in Anti-Spyware profiles; it might relate to overriding other settings but not a direct action against malicious DNS queries.
Concept tested: Anti-Spyware DNS policy actions
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/configure-anti-spyware-security-profiles/anti-spyware-security-profile-actions
Topics
Community Discussion
No community discussion yet for this question.