PCNSA · Question #370
An administrator receives a notification about new malware that is being used to attack hosts. The malware exploits a software bug in a common application. Which Security Profile will detect and block
The correct answer is A. Vulnerability Profile applied to inbound Security policy rules. To detect and block malware exploiting software bugs, a Vulnerability Profile is used, typically applied to inbound security policy rules to protect internal hosts from external threats.
Question
An administrator receives a notification about new malware that is being used to attack hosts. The malware exploits a software bug in a common application. Which Security Profile will detect and block access to this threat after the administrator updates the firewall's threat signature database?
Options
- AVulnerability Profile applied to inbound Security policy rules
- BAntivirus Profile applied to outbound Security policy rules
- CData Filtering Profile applied to outbound Security policy rules
- DData Filtering Profile applied to inbound Security policy rules
How the community answered
(40 responses)- A90% (36)
- B3% (1)
- C3% (1)
- D5% (2)
Why each option
To detect and block malware exploiting software bugs, a Vulnerability Profile is used, typically applied to inbound security policy rules to protect internal hosts from external threats.
A Vulnerability Protection profile specifically detects and prevents attempts to exploit system vulnerabilities and software bugs, making it the appropriate security profile for this type of threat. Applying it to inbound rules ensures protection for internal hosts from attacks originating outside the network.
An Antivirus Profile primarily detects and blocks known viruses, spyware, and other malware downloads, but not necessarily exploits against software bugs.
A Data Filtering Profile is used for Data Loss Prevention (DLP) to prevent sensitive information from leaving the network, not for detecting incoming malware exploits.
A Data Filtering Profile is for Data Loss Prevention (DLP) and would not detect incoming malware exploiting software bugs.
Concept tested: Vulnerability protection and threat prevention profiles
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/vulnerability-protection/vulnerability-protection-overview
Topics
Community Discussion
No community discussion yet for this question.