nerdexam
Palo_Alto_Networks

PCNSA · Question #359

Which Security profile must be added to Security policies to enable DNS Signatures to be checked?

The correct answer is C. Anti-Spyware. DNS Signatures (part of the DNS Security feature) are enforced through the Anti-Spyware Security profile. Within the profile's DNS Policies section, administrators define actions for detected DNS-based threats such as C2 domains identified via DNS signatures or DNS Security…

Submitted by lucia.co· Apr 18, 2026Securing Traffic

Question

Which Security profile must be added to Security policies to enable DNS Signatures to be checked?

Options

  • AURL Filtering
  • BVulnerability Protection
  • CAnti-Spyware
  • DAntivirus

How the community answered

(22 responses)
  • A
    5% (1)
  • C
    91% (20)
  • D
    5% (1)

Explanation

DNS Signatures (part of the DNS Security feature) are enforced through the Anti-Spyware Security profile. Within the profile's DNS Policies section, administrators define actions for detected DNS-based threats such as C2 domains identified via DNS signatures or DNS Security categories. Without an Anti-Spyware profile attached to a Security policy rule, DNS signature checking is not performed on matching traffic. Antivirus, Vulnerability Protection, and URL Filtering profiles do not contain DNS Signature controls.

Topics

#Anti-Spyware Profile#DNS Signatures#Security Profiles#Security Policies

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice