nerdexam
Palo_Alto_Networks

PCNSA · Question #367

What are three DNS policy actions? (Choose three.)

The correct answer is A. Block D. Sinkhole E. Alert. The three primary DNS policy actions available are Block, Sinkhole, and Alert, which allow administrators to control and respond to malicious DNS queries.

Submitted by marco_it· Apr 18, 2026Securing Traffic

Question

What are three DNS policy actions? (Choose three.)

Options

  • ABlock
  • BAllow
  • CStrict
  • DSinkhole
  • EAlert

How the community answered

(64 responses)
  • A
    92% (59)
  • B
    6% (4)
  • C
    2% (1)

Why each option

The three primary DNS policy actions available are Block, Sinkhole, and Alert, which allow administrators to control and respond to malicious DNS queries.

ABlockCorrect

Block is a direct action that prevents the DNS query from resolving, stopping access to potentially malicious domains.

BAllow

While Allow is a general policy action, it's not typically listed as a distinct malicious DNS policy action in the context of threat prevention profiles, as DNS Security focuses on handling suspicious or malicious queries.

CStrict

Strict is not a standard, distinct DNS policy action; it might describe a profile's overall posture but isn't an individual action like Block or Sinkhole.

DSinkholeCorrect

Sinkhole redirects malicious DNS queries to a specified sinkhole IP address, allowing the firewall to identify infected hosts on the network.

EAlertCorrect

Alert generates a log entry when a malicious DNS query is detected, providing visibility without blocking or redirecting the traffic.

Concept tested: DNS Security policy actions

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/dns-security/configure-dns-security.html

Topics

#DNS Security#Policy Actions#Threat Prevention

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice