nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #160

Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)

The correct answer is A. Enable User Credential Detection B. Enable User-ID E. Define a uniform resource locator (URL) Filtering profile. Enabling Credential Phishing Prevention on a Palo Alto Networks firewall requires three coordinated components: User Credential Detection (A) is the core engine that identifies when users submit corporate credentials to websites; User-ID (B) is required because the firewall…

Threat Prevention

Question

Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)

Options

  • AEnable User Credential Detection
  • BEnable User-ID
  • CDefine a Secure Sockets Layer (SSL) decryption rule base
  • DEnable App-ID
  • EDefine a uniform resource locator (URL) Filtering profile

How the community answered

(48 responses)
  • A
    75% (36)
  • C
    8% (4)
  • D
    17% (8)

Explanation

Enabling Credential Phishing Prevention on a Palo Alto Networks firewall requires three coordinated components: User Credential Detection (A) is the core engine that identifies when users submit corporate credentials to websites; User-ID (B) is required because the firewall must map IP addresses to actual usernames in order to enforce user-based credential policies; and a URL Filtering profile (E) is the vehicle through which credential phishing detection settings are applied and enforced in traffic. Without all three, the feature cannot function end-to-end.

SSL Decryption (C) is a common distractor because HTTPS traffic is often where phishing occurs, but decryption is not a required prerequisite for this feature -- it is recommended but optional. App-ID (D) is also wrong because, while App-ID is foundational to Palo Alto policy generally, it is not a specific configuration step for enabling Credential Phishing Prevention.

Memory tip: Think of the three required steps as "Who, What, Where" -- User-ID answers WHO is submitting credentials, User Credential Detection identifies WHAT is happening (a credential submission), and the URL Filtering profile defines WHERE and how the policy is applied.

Topics

#Credential Phishing Prevention#User Identification#URL Filtering#Threat Detection

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice