nerdexam
Palo_Alto_Networks

PCNSA · Question #424

Which two DNS policy actions in the anti-spyware security profile can prevent hacking attacks through DNS queries to malicious domains? (Choose two.)

The correct answer is B. Sinkhole D. Block. In the Anti-Spyware security profile, DNS Security actions include 'Block' and 'Sinkhole'. Block drops the DNS query outright, preventing the client from resolving the malicious domain. Sinkhole redirects the DNS response to a controlled IP address (the sinkhole), which both…

Submitted by lars.no· Apr 18, 2026Securing Traffic

Question

Which two DNS policy actions in the anti-spyware security profile can prevent hacking attacks through DNS queries to malicious domains? (Choose two.)

Options

  • ADeny
  • BSinkhole
  • COverride
  • DBlock

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    87% (40)
  • C
    4% (2)

Explanation

In the Anti-Spyware security profile, DNS Security actions include 'Block' and 'Sinkhole'. Block drops the DNS query outright, preventing the client from resolving the malicious domain. Sinkhole redirects the DNS response to a controlled IP address (the sinkhole), which both blocks the connection and enables identification of infected internal hosts attempting to reach C2 infrastructure. 'Deny' is not a distinct DNS action in PAN-OS anti-spyware. 'Override' is not a standard protective DNS action in this context.

Topics

#DNS Security#Anti-Spyware Profile#Threat Prevention Actions#Malicious Domains

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice