PCNSA · Question #278
Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?
The correct answer is D. Anti-Spyware. The Anti-Spyware Security profile is specifically designed to detect and block communication from compromised hosts to external command-and-control (C2) servers.
Question
Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?
Options
- AURL Filtering
- BAntivirus
- CVulnerability
- DAnti-Spyware
How the community answered
(28 responses)- A4% (1)
- C4% (1)
- D93% (26)
Why each option
The Anti-Spyware Security profile is specifically designed to detect and block communication from compromised hosts to external command-and-control (C2) servers.
URL Filtering controls access to websites based on categories or custom lists, but its primary function is not the detection and blocking of C2 communication initiated by compromised hosts.
Antivirus profiles primarily detect and block known malware files based on signatures, but they are not the primary mechanism for detecting and preventing C2 communication channels.
Vulnerability profiles detect and block exploits against known system vulnerabilities, which is different from detecting active C2 communication from an already compromised host.
The Anti-Spyware Security profile is purpose-built to prevent and detect malware such as spyware and botnets, including their attempts to communicate with C2 servers, by identifying and blocking malicious DNS queries or C2 traffic patterns.
Concept tested: Anti-Spyware for C2 detection
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/configure-anti-spyware-security-profiles
Topics
Community Discussion
No community discussion yet for this question.