nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #157

Access to a business site is blocked by URL Filtering inline machine learning (ML) and considered as a false-positive. How should the site be made available?

The correct answer is C. Create a custom URL category and add it on exception of the inline ML profile. Option C is correct because Palo Alto Networks' URL Filtering inline ML operates as a sub-component within the URL Filtering profile, and it has its own exception mechanism - you add a custom URL category containing the false-positive site directly to that profile's inline ML…

Threat Prevention

Question

Access to a business site is blocked by URL Filtering inline machine learning (ML) and considered as a false-positive. How should the site be made available?

Options

  • ADisable URL Filtering inline ML
  • BCreate a custom URL category and add it to the Security policy
  • CCreate a custom URL category and add it on exception of the inline ML profile
  • DChange the action of real-time detection category on URL filtering profile

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    82% (28)
  • D
    9% (3)

Explanation

Option C is correct because Palo Alto Networks' URL Filtering inline ML operates as a sub-component within the URL Filtering profile, and it has its own exception mechanism - you add a custom URL category containing the false-positive site directly to that profile's inline ML exceptions, which lets the site bypass ML-based blocking while leaving the ML engine active for everything else.

Option A is wrong because disabling inline ML entirely removes a layer of security for all traffic just to accommodate one site. Option B is wrong because adding a custom URL category to the Security policy controls policy-level allow/deny actions but does not override the inline ML engine, which operates earlier in the inspection pipeline within the URL Filtering profile itself. Option D is wrong because changing the action on the real-time detection category modifies how inline ML handles all flagged URLs globally, not just the specific false-positive site.

Memory tip: Think of inline ML as a specialized guard with its own override list. To let one site through, you add it to that guard's personal exception list (the inline ML profile exception), not to the front-door policy (Security policy) and not by firing the guard (disabling ML).

Topics

#URL Filtering#Inline ML#Security Policy#Exception Handling

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice