nerdexam
Palo_Alto_Networks

PCNSE · Question #439

Refer to the exhibit. Using the above screenshot of the ACC, what is the best method to set a global filter, narrow down Blocked User Activity, and locate the user(s) that could be compromised by a bo

The correct answer is D. Click the hyperlink for the botnet Threat Category.. To effectively filter for blocked botnet activity and identify compromised users in the ACC, the best method is to click the hyperlink for the 'botnet Threat Category'.

Submitted by carter_n· Apr 18, 2026Operate

Question

Refer to the exhibit. Using the above screenshot of the ACC, what is the best method to set a global filter, narrow down Blocked User Activity, and locate the user(s) that could be compromised by a botnet?

Exhibit

PCNSE question #439 exhibit

Options

  • AClick the hyperlink for the Zero Access.Gen threat.
  • BClick the left arrow beside the Zero Access.Gen threat.
  • CClick the source user with the highest threat count.
  • DClick the hyperlink for the botnet Threat Category.

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    7% (3)
  • C
    2% (1)
  • D
    77% (33)

Why each option

To effectively filter for blocked botnet activity and identify compromised users in the ACC, the best method is to click the hyperlink for the 'botnet Threat Category'.

AClick the hyperlink for the Zero Access.Gen threat.

Clicking the hyperlink for a specific threat like 'Zero Access.Gen' would only filter for that particular botnet variant, potentially missing other botnet activity and compromised users.

BClick the left arrow beside the Zero Access.Gen threat.

Clicking the left arrow typically collapses a section or provides a different action, not usually to apply a global filter for a category.

CClick the source user with the highest threat count.

Clicking on a single source user, even one with a high threat count, would focus on that individual user rather than broadly filtering all botnet activity across all users to identify potential compromises.

DClick the hyperlink for the botnet Threat Category.Correct

Clicking the hyperlink for the 'botnet Threat Category' applies a global filter across the ACC, immediately narrowing the view to all sessions identified as botnet activity, which helps in finding all potentially compromised users.

Concept tested: Palo Alto Networks ACC filtering for threat investigation

Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/use-the-application-command-center/acc-filters.html

Topics

#ACC (Application Command Center)#Filtering#Botnet detection#User monitoring

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice