PCNSE · Question #854
A security engineer is informed that the vulnerability protection profile of their on-premises Palo Alto Networks firewall is triggering on a common Threat ID, and which has been determined to be a fa
The correct answer is B. Select "Show all signatures" within the vulnerability protection profile under "Exceptions". When a Threat ID isn't visible in the Vulnerability Protection profile's Exceptions tab, selecting "Show all signatures" (Option B) reveals all available threat signatures, including those not recently triggered, allowing the administrator to add an exception efficiently. This is
Question
A security engineer is informed that the vulnerability protection profile of their on-premises Palo Alto Networks firewall is triggering on a common Threat ID, and which has been determined to be a false positive. The engineer is asked to resolve the issue as soon as possible because it is causing an outage for a critical service. The engineer opens the vulnerability protection profile to add the exception, but the Threat ID is missing. Which action is the most operationally efficient for the security engineer to find and implement the exception?
Options
- AReview high-severity system logs to identify why the threat is missing in "Vulnerability Profile
- BSelect "Show all signatures" within the vulnerability protection profile under "Exceptions"
- CReview traffic logs to add the exception from there
- DOpen a support case
How the community answered
(32 responses)- A3% (1)
- B75% (24)
- C16% (5)
- D6% (2)
Explanation
When a Threat ID isn't visible in the Vulnerability Protection profile's Exceptions tab, selecting "Show all signatures" (Option B) reveals all available threat signatures, including those not recently triggered, allowing the administrator to add an exception efficiently. This is the fastest way to resolve false positives without external assistance.
Topics
Community Discussion
No community discussion yet for this question.