nerdexam
Palo_Alto_Networks

PCNSE · Question #20

Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)

The correct answer is C. PAN-DB URL Filtering D. DNS-based command-and-control signatures. Palo Alto Networks maintains a dynamic database of known malicious domains used for threat prevention. PAN-DB URL Filtering (C) uses this database to block access to malicious or command-and-control domains during web browsing. DNS-based command-and-control signatures (D) use…

Submitted by kwame.gh· Apr 18, 2026Core Concepts

Question

Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)

Options

  • ABrute-force signatures
  • BBrightCloud Url Filtering
  • CPAN-DB URL Filtering
  • DDNS-based command-and-control signatures

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    93% (26)

Explanation

Palo Alto Networks maintains a dynamic database of known malicious domains used for threat prevention. PAN-DB URL Filtering (C) uses this database to block access to malicious or command-and-control domains during web browsing. DNS-based command-and-control signatures (D) use the same database to detect and block DNS queries to malicious domains, preventing malware from communicating with C2 infrastructure via DNS. Brute-force signatures (A) detect authentication attacks and do not use domain reputation data. BrightCloud (B) is a third-party URL filtering vendor and is a separate product, not Palo Alto's native database.

Topics

#URL Filtering#DNS Security#Threat Prevention#Malicious Domains

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice