PCNSA · Question #334
Which type of DNS signatures are used by the firewall to identify malicious and command-and- control domains?
The correct answer is B. DNS Security signatures. Palo Alto Networks uses DNS Security signatures to identify domains associated with malware, command-and-control (C2) infrastructure, phishing, and other malicious activity. These signatures are delivered via the DNS Security subscription service and are used by the Anti-Spyware
Question
Which type of DNS signatures are used by the firewall to identify malicious and command-and- control domains?
Options
- ADNS Malicious signatures
- BDNS Security signatures
- CDNS Malware signatures
- DDNS Block signatures
How the community answered
(26 responses)- B92% (24)
- C4% (1)
- D4% (1)
Explanation
Palo Alto Networks uses DNS Security signatures to identify domains associated with malware, command-and-control (C2) infrastructure, phishing, and other malicious activity. These signatures are delivered via the DNS Security subscription service and are used by the Anti-Spyware profile to detect and block malicious DNS queries. Terms like 'DNS Malicious signatures,' 'DNS Malware signatures,' and 'DNS Block signatures' are not official Palo Alto Networks terminology and do not correspond to actual signature types in PAN-OS.
Topics
Community Discussion
No community discussion yet for this question.