nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #72

PSE-PLATFORM Question #72: Real Exam Question with Answer & Explanation

The correct answer is A. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole. Explanation/Reference: Starting with PAN-OS 6.0, DNS sinkhole is an action that can be enabled in Anti-Spyware profiles. A DNS sinkhole can be used to identify infected hosts on a protected network using DNS traffic in environments where the firewall can see the DNS query to a ma

Question

A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermore, SSL is used to tunnel malicious traffic to command-and-control servers on the internet and SSL Forward Proxy Decryption is not enabled. Which component once enabled on a perimeter firewall will allow the identification of existing infected hosts in an environment?

Options

  • AAnti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole
  • BFile Blocking profiles applied to outbound security policies with action set to alert
  • CVulnerability Protection profiles applied to outbound security policies with action set to block
  • DAntivirus profiles applied to outbound security policies with action set to alert

Explanation

Explanation/Reference: Starting with PAN-OS 6.0, DNS sinkhole is an action that can be enabled in Anti-Spyware profiles. A DNS sinkhole can be used to identify infected hosts on a protected network using DNS traffic in environments where the firewall can see the DNS query to a malicious URL. The DNS sinkhole enables the Palo Alto Networks device to forge a response to a DNS query for a known malicious domain/URL and causes the malicious domain name to resolve to a definable IP address (fake IP) that is given to the client. If the client attempts to access the fake IP address and there is a security rule in place that blocks traffic to this IP, the information is recorded in the logs. https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice