nerdexam
Palo_Alto_Networks

PCNSE · Question #520

Review the images. A firewall policy that permits web traffic includes the following: What is the result of traffic that matches the "Alert - Threats" Profile Match List?

The correct answer is C. The source address of traffic that matches a threat is automatically tagged as BadGuys for 180. Security profile Match Lists with forwarding actions allow the firewall to automatically tag source IP addresses when traffic matches a threat signature. In this scenario, the 'Alert - Threats' Match List is configured to tag the source address with the dynamic tag 'BadGuys'…

Submitted by brentm· Apr 18, 2026Deploy and Configure

Question

Review the images. A firewall policy that permits web traffic includes the following:

What is the result of traffic that matches the "Alert - Threats" Profile Match List?

Exhibits

PCNSE question #520 exhibit 1
PCNSE question #520 exhibit 2

Options

  • AThe source address of SMTP traffic that matches a threat is automatically blocked as BadGuys
  • BThe source address of traffic that matches a threat is automatically blocked as BadGuys for 180
  • CThe source address of traffic that matches a threat is automatically tagged as BadGuys for 180
  • DThe source address of SMTP traffic that matches a threat is automatically tagged as BadGuys for

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    91% (39)
  • D
    2% (1)

Explanation

Security profile Match Lists with forwarding actions allow the firewall to automatically tag source IP addresses when traffic matches a threat signature. In this scenario, the 'Alert - Threats' Match List is configured to tag the source address with the dynamic tag 'BadGuys' for 180 seconds upon a threat match. The tag can then be referenced by a Dynamic Address Group to apply further policy. The key distinctions: the action is tagging (not direct blocking - the firewall registers the IP with a tag, which other policies may use to block), and it applies to any matching threat traffic, not exclusively SMTP. Answers A and D incorrectly restrict the scope to SMTP, and answer B incorrectly states the action is blocking rather than tagging.

Topics

#Security Profiles#IP Tagging#Threat Prevention#Firewall Policy

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice