PCNSA · Question #365
Given the detailed log information above, what was the result of the firewall traffic inspection?
The correct answer is D. It was blocked by the Anti-Spyware Profile action. The firewall traffic inspection resulted in the traffic being blocked due to an action triggered by the Anti-Spyware Security profile.
Question
Given the detailed log information above, what was the result of the firewall traffic inspection?
Exhibit
Options
- AIt denied the category DNS phishing.
- BIt denied the traffic because of unauthorized attempts.
- CIt was blocked by the Anti-Virus Security profile action.
- DIt was blocked by the Anti-Spyware Profile action.
How the community answered
(41 responses)- A5% (2)
- B12% (5)
- C7% (3)
- D76% (31)
Why each option
The firewall traffic inspection resulted in the traffic being blocked due to an action triggered by the Anti-Spyware Security profile.
While DNS phishing is a threat, denying a category is typically a URL Filtering action or a specific DNS policy action, which is distinct from an Anti-Spyware profile block.
"Unauthorized attempts" is a generic term; traffic blocked by an Anti-Spyware profile provides a more precise technical reason for the block.
The Anti-Virus Security profile specifically targets viruses and worms; a block by the Anti-Spyware profile indicates a different type of threat detection.
The Anti-Spyware Security Profile is designed to protect against spyware and other malicious software, including command-and-control (C2) traffic. When traffic matches a signature or behavior defined in this profile and the profile's action is set to block, the firewall will drop the connection.
Concept tested: Security profile actions (Anti-Spyware)
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/anti-spyware/configure-anti-spyware-profiles.html
Topics
Community Discussion
No community discussion yet for this question.
