nerdexam
Palo_Alto_Networks

PCNSA · Question #268

An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems. From the Pre-defined…

The correct answer is D. Set the Command and Control category to block. Command and Control (C2) is the precise category for domains that malware uses to maintain persistent, outbound connections to attacker-controlled infrastructure - exactly the mechanism described in the question where data is exfiltrated through "established connections to…

Submitted by skyler.x· Apr 18, 2026Securing Traffic

Question

An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems. From the Pre-defined Categories tab within the URL Filtering profile, what is the right configuration to prevent such connections?

Options

  • ASet the hacking category to continue.
  • BSet the phishing category to override.
  • CSet the malware category to block.
  • DSet the Command and Control category to block.

How the community answered

(55 responses)
  • A
    7% (4)
  • B
    4% (2)
  • C
    2% (1)
  • D
    87% (48)

Explanation

Command and Control (C2) is the precise category for domains that malware uses to maintain persistent, outbound connections to attacker-controlled infrastructure - exactly the mechanism described in the question where data is exfiltrated through "established connections to remote systems." Blocking C2 URLs cuts that communication channel before data leaves the network.

Why the distractors fail:

  • A (hacking/continue) - "Continue" only warns users; it doesn't block anything. Also, the hacking category targets exploit tools and techniques, not exfiltration channels.
  • B (phishing/override) - Phishing covers credential-harvesting pages, not remote exfiltration pipelines; and "override" permits access after admin authentication, which is the opposite of prevention.
  • C (malware/block) - Malware covers sites that deliver malicious payloads (downloads), not sites that receive stolen data via established sessions - a critical distinction.

Memory tip: Think of C2 as the "phone home" category - it's where already-infected hosts call their masters. The question's phrase "established connections to remote systems" is your signal that the malware is already inside and talking out, which is C2 territory, not phishing or malware-delivery territory.

Topics

#URL Filtering#Command and Control (C2)#Data Exfiltration Prevention#Security Profiles

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice