PSE-PLATFORM · Question #72
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermore, SSL is used to t
The correct answer is A. Anti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole. Explanation/Reference: Starting with PAN-OS 6.0, DNS sinkhole is an action that can be enabled in Anti-Spyware profiles. A DNS sinkhole can be used to identify infected hosts on a protected network using DNS traffic in environments where the firewall can see the DNS query to a ma
Question
A critical US-CERT notification is published regarding a newly discovered botnet. The malware is very evasive and is not reliably detected by endpoint antivirus software. Furthermore, SSL is used to tunnel malicious traffic to command-and-control servers on the internet and SSL Forward Proxy Decryption is not enabled. Which component once enabled on a perimeter firewall will allow the identification of existing infected hosts in an environment?
Options
- AAnti-Spyware profiles applied outbound security policies with DNS Query action set to sinkhole
- BFile Blocking profiles applied to outbound security policies with action set to alert
- CVulnerability Protection profiles applied to outbound security policies with action set to block
- DAntivirus profiles applied to outbound security policies with action set to alert
How the community answered
(40 responses)- A57% (23)
- B5% (2)
- C25% (10)
- D13% (5)
Explanation
Explanation/Reference: Starting with PAN-OS 6.0, DNS sinkhole is an action that can be enabled in Anti-Spyware profiles. A DNS sinkhole can be used to identify infected hosts on a protected network using DNS traffic in environments where the firewall can see the DNS query to a malicious URL. The DNS sinkhole enables the Palo Alto Networks device to forge a response to a DNS query for a known malicious domain/URL and causes the malicious domain name to resolve to a definable IP address (fake IP) that is given to the client. If the client attempts to access the fake IP address and there is a security rule in place that blocks traffic to this IP, the information is recorded in the logs. https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Sinkhole/ta-p/58891
Topics
Community Discussion
No community discussion yet for this question.