nerdexam
Palo_Alto_Networks

PCNSA · Question #334

Which type of DNS signatures are used by the firewall to identify malicious and command-and- control domains?

The correct answer is B. DNS Security signatures. Palo Alto Networks uses DNS Security signatures to identify domains associated with malware, command-and-control (C2) infrastructure, phishing, and other malicious activity. These signatures are delivered via the DNS Security subscription service and are used by the Anti-Spyware

Submitted by carter_n· Apr 18, 2026Securing Traffic

Question

Which type of DNS signatures are used by the firewall to identify malicious and command-and- control domains?

Options

  • ADNS Malicious signatures
  • BDNS Security signatures
  • CDNS Malware signatures
  • DDNS Block signatures

How the community answered

(26 responses)
  • B
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Palo Alto Networks uses DNS Security signatures to identify domains associated with malware, command-and-control (C2) infrastructure, phishing, and other malicious activity. These signatures are delivered via the DNS Security subscription service and are used by the Anti-Spyware profile to detect and block malicious DNS queries. Terms like 'DNS Malicious signatures,' 'DNS Malware signatures,' and 'DNS Block signatures' are not official Palo Alto Networks terminology and do not correspond to actual signature types in PAN-OS.

Topics

#DNS Security#Command and Control#Threat Prevention#Palo Alto Firewall Features

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice