nerdexam
Palo_Alto_Networks

PCNSE · Question #834

A company uses GlobalProtect for its VPN and wants to allow access to users who have only an endpoint solution installed. Which sequence of configuration steps will allow access only for hosts that…

The correct answer is D. Create a HIP object with Anti-Malware enabled and Real Time Protection set to yes. To enforce access only for hosts with antivirus or anti-spyware enabled, you need to leverage Host Information Profile (HIP) objects and profiles. First, create a HIP object that specifies criteria such as Anti-Malware enabled with Real-Time Protection. Then, create a HIP…

Submitted by renata2k· Apr 18, 2026Deploy and Configure

Question

A company uses GlobalProtect for its VPN and wants to allow access to users who have only an endpoint solution installed. Which sequence of configuration steps will allow access only for hosts that have antivirus or anti- spyware enabled?

Options

  • ACreate a HIP object with Anti-Malware enabled and Real Time Protection set to yes.
  • BCreate Security Profiles for Antivirus and Anti-Spyware.
  • CCreate Security Profiles for Antivirus and Anti-Spyware.
  • DCreate a HIP object with Anti-Malware enabled and Real Time Protection set to yes.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    10% (3)
  • D
    81% (25)

Explanation

To enforce access only for hosts with antivirus or anti-spyware enabled, you need to leverage Host Information Profile (HIP) objects and profiles. First, create a HIP object that specifies criteria such as Anti-Malware enabled with Real-Time Protection. Then, create a HIP profile that matches this HIP object. The GlobalProtect Portal Agent must be configured to collect HIP data, and a Security policy must match the HIP profile for enforcement. Finally, the GlobalProtect Gateway Agent should notify users if their endpoints do not meet the criteria. This ensures that only compliant endpoints are allowed access.

Topics

#GlobalProtect#HIP Objects#Endpoint Posture#Antivirus/Anti-Malware

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice