nerdexam
Palo_Alto_Networks

PCNSA · Question #295

An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how will the firewall…

The correct answer is D. It uses the default action assigned to the virus signature. When an Antivirus Security profile detects a virus and no explicit action is configured, the firewall will apply the default action defined for that specific virus signature.

Submitted by sofia.br· Apr 18, 2026Securing Traffic

Question

An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile. If a virus gets detected, how will the firewall handle the traffic?

Options

  • AIt allows the traffic but generates an entry in the Threat logs.
  • BIt drops the traffic because the profile was not set to explicitly allow the traffic.
  • CIt allows the traffic because the profile was not set the explicitly deny the traffic.
  • DIt uses the default action assigned to the virus signature.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • D
    93% (26)

Why each option

When an Antivirus Security profile detects a virus and no explicit action is configured, the firewall will apply the default action defined for that specific virus signature.

AIt allows the traffic but generates an entry in the Threat logs.

Allowing traffic but only logging it is a possible action, but not the default behavior if no action is specified; the default action depends on the specific signature.

BIt drops the traffic because the profile was not set to explicitly allow the traffic.

Dropping traffic is a common action for viruses, but it's not universally applied by default if no explicit action is set; the specific signature's default action governs this.

CIt allows the traffic because the profile was not set the explicitly deny the traffic.

Allowing traffic because no explicit deny was set is incorrect; the security profile's purpose is to enforce security, and a default action for detected threats will always apply.

DIt uses the default action assigned to the virus signature.Correct

In Palo Alto Networks Antivirus profiles, if an administrator does not explicitly override the action for a detected virus signature, the firewall will enforce the predefined default action associated with that specific signature (e.g., block, alert, reset connections).

Concept tested: Antivirus profile default actions

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/configure-antivirus-profiles

Topics

#Antivirus Security Profile#Threat Prevention#Security Policy Configuration#Default Actions

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice