PSE-PRISMACLOUD · Question #3
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW Vulnerability Protection Profiles?
The correct answer is D. Clone the predefined Strict Profile, with packet capture settings enabled. Cloning the predefined Strict Profile with packet capture enabled (D) is the Palo Alto Networks best practice because the Strict Profile applies the most aggressive threat prevention settings for both client-side and server-side vulnerabilities, and cloning it lets you…
Question
When protecting against attempts to exploit client-side and server-side vulnerabilities, what is the Palo Alto Networks best practice when using NGFW Vulnerability Protection Profiles?
Options
- AUse the default Vulnerability Protection Profile to protect clients from all known critical, high, and
- BClone the predefined Strict Profile, with packet capture settings disabled
- CUse the default Vulnerability Protection Profile to protect servers from all known critical, high, and
- DClone the predefined Strict Profile, with packet capture settings enabled
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- D92% (23)
Explanation
Cloning the predefined Strict Profile with packet capture enabled (D) is the Palo Alto Networks best practice because the Strict Profile applies the most aggressive threat prevention settings for both client-side and server-side vulnerabilities, and cloning it lets you customize without overwriting the original. Packet capture must be enabled so that when a vulnerability trigger fires, the network traffic is recorded for forensic analysis and incident investigation - disabling it (option B) leaves you blind to what actually happened during an attack.
Options A and C are wrong for the same reason: the default Vulnerability Protection Profile is a loosely configured baseline that only covers a subset of severity levels and uses less aggressive actions (e.g., alert instead of block); it is not recommended for production security - regardless of whether you're protecting clients or servers.
Memory tip: Think "Clone Strict, Capture Evidence." Strict = maximum protection; Clone = preserve the original; Capture Enabled = you can always investigate later. Never tune down security (no capture, default profile) when you can tune up.
Topics
Community Discussion
No community discussion yet for this question.