PCNSA · Question #295
An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how will the firewall…
The correct answer is D. It uses the default action assigned to the virus signature. When an Antivirus Security profile detects a virus and no explicit action is configured, the firewall will apply the default action defined for that specific virus signature.
Question
An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how will the firewall handle the traffic?
Options
- AIt allows the traffic but generates an entry in the Threat logs.
- BIt drops the traffic because the profile was not set to explicitly allow the traffic.
- CIt allows the traffic because the profile was not set the explicitly deny the traffic.
- DIt uses the default action assigned to the virus signature.
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- D93% (26)
Why each option
When an Antivirus Security profile detects a virus and no explicit action is configured, the firewall will apply the default action defined for that specific virus signature.
Allowing traffic but only logging it is a possible action, but not the default behavior if no action is specified; the default action depends on the specific signature.
Dropping traffic is a common action for viruses, but it's not universally applied by default if no explicit action is set; the specific signature's default action governs this.
Allowing traffic because no explicit deny was set is incorrect; the security profile's purpose is to enforce security, and a default action for detected threats will always apply.
In Palo Alto Networks Antivirus profiles, if an administrator does not explicitly override the action for a detected virus signature, the firewall will enforce the predefined default action associated with that specific signature (e.g., block, alert, reset connections).
Concept tested: Antivirus profile default actions
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/configure-antivirus-profiles
Topics
Community Discussion
No community discussion yet for this question.