nerdexam
Palo_Alto_Networks

PCNSA · Question #278

Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?

The correct answer is D. Anti-Spyware. The Anti-Spyware Security profile is specifically designed to detect and block communication from compromised hosts to external command-and-control (C2) servers.

Submitted by zhang_li· Apr 18, 2026Securing Traffic

Question

Which Security profile can be used to detect and block compromised hosts from trying to communicate with external command-and-control (C2) servers?

Options

  • AURL Filtering
  • BAntivirus
  • CVulnerability
  • DAnti-Spyware

How the community answered

(28 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (26)

Why each option

The Anti-Spyware Security profile is specifically designed to detect and block communication from compromised hosts to external command-and-control (C2) servers.

AURL Filtering

URL Filtering controls access to websites based on categories or custom lists, but its primary function is not the detection and blocking of C2 communication initiated by compromised hosts.

BAntivirus

Antivirus profiles primarily detect and block known malware files based on signatures, but they are not the primary mechanism for detecting and preventing C2 communication channels.

CVulnerability

Vulnerability profiles detect and block exploits against known system vulnerabilities, which is different from detecting active C2 communication from an already compromised host.

DAnti-SpywareCorrect

The Anti-Spyware Security profile is purpose-built to prevent and detect malware such as spyware and botnets, including their attempts to communicate with C2 servers, by identifying and blocking malicious DNS queries or C2 traffic patterns.

Concept tested: Anti-Spyware for C2 detection

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/configure-anti-spyware-security-profiles

Topics

#Security Profiles#Anti-Spyware#Command-and-Control (C2)#Threat Prevention

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice