nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #80

Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)

The correct answer is B. DoS Protection Profile D. Zone Protection Profile. Explanation/Reference: C: PAN-DB categorizes URLs based on their content at the domain, file and page level, and receives updates from WildFire cloud-based malware analysis environment every 30 minutes to make sure that, when web content changes, so do categorizations. This conti

Threat Prevention

Question

Palo Alto Networks maintains a dynamic database of malicious domains. Which two Security Platform components use this database to prevent threats? (Choose two)

Options

  • AVulnerability Object
  • BDoS Protection Profile
  • CData Filtering Profile
  • DZone Protection Profile

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    74% (23)
  • C
    19% (6)

Explanation

Explanation/Reference: C: PAN-DB categorizes URLs based on their content at the domain, file and page level, and receives updates from WildFire cloud-based malware analysis environment every 30 minutes to make sure that, when web content changes, so do categorizations. This continuous feedback loop enables you to keep pace with the rapidly changing nature of the web, automatically. D: DNS is a very necessary and ubiquitous application, as such, it is a very commonly abused protocol for command-and-control and data exfiltration. This tech brief summarizes the DNS classification, inspection and protection capabilities supported by our next-generation security platform, which includes: 1. Malformed DNS messages (symptomatic of vulnerability exploitation attack). 2. DNS responses with suspicious composition (abused query types, DNS-based denial of service attacks). 3. DNS queries for known malicious domains. Our ability to prevent threats from hiding within DNS The passive DNS network feature allows you to opt-in to share anonymized DNS query and response data with our global passive DNS network. The data is continuously mined to discover malicious domains that are then added to the PAN-OS DNS signature set that is delivered daily, enabling timely detection of compromised hosts within the network and the disruption of command-and-control channels that rely on name resolution. Explanation/Reference: B: There are two DoS protection mechanisms that the Palo Alto Networks firewalls support. * Flood Protection -Detects and prevents attacks where the network is flooded with packets resulting in too many half-open sessions and/or services being unable to respond to each request. In this case the source address of the attack is usually spoofed. * Resource Protection -Detects and prevent session exhaustion attacks. In this type of attack, a large number of hosts (bots) are used to establish as many fully established sessions as possible to consume all of a system's resources. You can enable both types of protection mechanisms in a single DoS protection profile. D: Provides additional protection between specific network zones in order to protect the zones against attack. The profile must be applied to the entire zone, so it is important to carefully test the profiles in order to prevent issues that may arise with the normal traffic traversing the zones. When defining packets per second (pps) thresholds limits for zone protection profiles, the threshold is based on the packets per second that do not match a previously established session. Incorrect Answers: A: Vulnerability protection stops attempts to exploit system flaws or gain unauthorized access to systems. For example, this feature will protect against buffer overflows, illegal code execution, and other attempts to exploit system vulnerabilities. C: Data Filtering helps to prevent sensitive information such as credit card or social security numbers from leaving a protected network.

Topics

#malicious domains#dynamic database#Zone Protection#DoS Protection

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice