nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #347

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and-control (C2) servers…

Anti-Spyware (A) is correct because this profile type is specifically designed to detect and block command-and-control traffic - including DNS-based C2, beaconing, and other "phone-home" behaviors from already-compromised hosts. It inspects outbound traffic for known C2…

Threat Prevention

Question

A firewall administrator has been asked to configure a Palo Alto Networks NGFW to prevent against compromised hosts trying to phone-home or beacon out to external command-and-control (C2) servers. Which Security Profile type will prevent these behaviors?

Options

  • AAnti-Spyware
  • BWildFire
  • CVulnerability Protection
  • DAntivirus

Explanation

Anti-Spyware (A) is correct because this profile type is specifically designed to detect and block command-and-control traffic - including DNS-based C2, beaconing, and other "phone-home" behaviors from already-compromised hosts. It inspects outbound traffic for known C2 signatures and can block or sinkhole malicious DNS queries used by malware to reach attacker infrastructure.

WildFire (B) analyzes unknown files and URLs in a cloud sandbox to identify zero-day threats - it's about discovering new malware, not stopping post-compromise C2 communications. Vulnerability Protection (C) defends against exploits targeting system vulnerabilities (pre-compromise), not traffic from hosts that are already infected. Antivirus (D) scans file transfers and downloads for known malware signatures during delivery - again, pre-compromise, not post.

Memory tip: Think "spyware = spy reporting back to headquarters." Anti-Spyware cuts the spy's radio signal - it stops the outbound call home, making it the right tool once a host is already compromised.

Topics

#Anti-Spyware#command and control#C2 beaconing#Security Profiles

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice