nerdexam
Palo_Alto_Networks

PSE-STRATA-PRO-24 · Question #57

Which initial action can a network security engineer take to prevent a malicious actor from using a file-sharing application for data exfiltration without impacting users who still need to use file…

The correct answer is B. Use App-ID to limit access to file-sharing applications based on job functions. To prevent malicious actors from abusing file-sharing applications for data exfiltration, App-ID provides a granular approach to managing application traffic. Palo Alto Networks' App-ID is a technology that identifies applications traversing the network, regardless of port…

Application Control and Data Protection

Question

Which initial action can a network security engineer take to prevent a malicious actor from using a file-sharing application for data exfiltration without impacting users who still need to use file- sharing applications?

Options

  • AUse DNS Security to limit access to file-sharing applications based on job functions.
  • BUse App-ID to limit access to file-sharing applications based on job functions.
  • CUse DNS Security to block all file-sharing applications and uploading abilities.
  • DUse App-ID to block all file-sharing applications and uploading abilities.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    85% (29)
  • C
    9% (3)
  • D
    3% (1)

Explanation

To prevent malicious actors from abusing file-sharing applications for data exfiltration, App-ID provides a granular approach to managing application traffic. Palo Alto Networks' App-ID is a technology that identifies applications traversing the network, regardless of port, protocol, encryption (SSL), or evasive tactics. By leveraging App-ID, security engineers can implement policies that restrict the use of specific applications or functionalities based on job functions, ensuring that only authorized users or groups can use file-sharing applications while blocking unauthorized or malicious usage. Option B: App-ID provides the ability to identify file-sharing applications (such as Dropbox, Google Drive, or OneDrive) and enforce policies to restrict their use. For example, you can create a security rule allowing file-sharing apps only for specific job functions, such as HR or marketing, while denying them for other users. This targeted approach ensures legitimate business needs are not disrupted, which aligns with the requirement of not impacting valid users.

Topics

#App-ID#data exfiltration#file-sharing applications#application control

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA-PRO-24 Practice