PSE-STRATA · Question #160
Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)
The correct answer is A. Enable User Credential Detection B. Enable User-ID E. Define a uniform resource locator (URL) Filtering profile. Enabling Credential Phishing Prevention on a Palo Alto Networks firewall requires three coordinated components: User Credential Detection (A) is the core engine that identifies when users submit corporate credentials to websites; User-ID (B) is required because the firewall…
Question
Which three of the following actions must be taken to enable Credential Phishing Prevention? (Choose three.)
Options
- AEnable User Credential Detection
- BEnable User-ID
- CDefine a Secure Sockets Layer (SSL) decryption rule base
- DEnable App-ID
- EDefine a uniform resource locator (URL) Filtering profile
How the community answered
(48 responses)- A75% (36)
- C8% (4)
- D17% (8)
Explanation
Enabling Credential Phishing Prevention on a Palo Alto Networks firewall requires three coordinated components: User Credential Detection (A) is the core engine that identifies when users submit corporate credentials to websites; User-ID (B) is required because the firewall must map IP addresses to actual usernames in order to enforce user-based credential policies; and a URL Filtering profile (E) is the vehicle through which credential phishing detection settings are applied and enforced in traffic. Without all three, the feature cannot function end-to-end.
SSL Decryption (C) is a common distractor because HTTPS traffic is often where phishing occurs, but decryption is not a required prerequisite for this feature -- it is recommended but optional. App-ID (D) is also wrong because, while App-ID is foundational to Palo Alto policy generally, it is not a specific configuration step for enabling Credential Phishing Prevention.
Memory tip: Think of the three required steps as "Who, What, Where" -- User-ID answers WHO is submitting credentials, User Credential Detection identifies WHAT is happening (a credential submission), and the URL Filtering profile defines WHERE and how the policy is applied.
Topics
Community Discussion
No community discussion yet for this question.