PSE-PLATFORM · Question #347
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and-control (C2) servers…
Anti-Spyware (A) is correct because this profile type is specifically designed to detect and block command-and-control traffic - including DNS-based C2, beaconing, and other "phone-home" behaviors from already-compromised hosts. It inspects outbound traffic for known C2…
Question
A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and-control (C2) servers. Which Security Profile type will prevent these behaviors?
Options
- AAnti-Spyware
- BWildFire
- CVulnerability Protection
- DAntivirus
Explanation
Anti-Spyware (A) is correct because this profile type is specifically designed to detect and block command-and-control traffic - including DNS-based C2, beaconing, and other "phone-home" behaviors from already-compromised hosts. It inspects outbound traffic for known C2 signatures and can block or sinkhole malicious DNS queries used by malware to reach attacker infrastructure.
WildFire (B) analyzes unknown files and URLs in a cloud sandbox to identify zero-day threats - it's about discovering new malware, not stopping post-compromise C2 communications. Vulnerability Protection (C) defends against exploits targeting system vulnerabilities (pre-compromise), not traffic from hosts that are already infected. Antivirus (D) scans file transfers and downloads for known malware signatures during delivery - again, pre-compromise, not post.
Memory tip: Think "spyware = spy reporting back to headquarters." Anti-Spyware cuts the spy's radio signal - it stops the outbound call home, making it the right tool once a host is already compromised.
Topics
Community Discussion
No community discussion yet for this question.