PSE-STRATA · Question #175
A customer with a fully licensed Palo Alto Networks firewall is concerned about threats based on domain generation algorithms (DGAS). Which Security profile is used to configure Domain Name Security…
The correct answer is D. Anti-Spyware profile. Anti-Spyware is the correct profile because Palo Alto Networks embeds DNS Security configuration directly within it - this is where you enable DGA detection, which uses cloud-based machine learning to identify algorithmically generated domains in real time, even if they've…
Question
A customer with a fully licensed Palo Alto Networks firewall is concerned about threats based on domain generation algorithms (DGAS). Which Security profile is used to configure Domain Name Security (DNS) to Identity and block previously unknown DGA-based threats in real time?
Options
- AURL Filtering profile
- BWildFire Analysis profile
- CVulnerability Protection profile
- DAnti-Spyware profile
How the community answered
(31 responses)- A10% (3)
- B3% (1)
- C3% (1)
- D84% (26)
Explanation
Anti-Spyware is the correct profile because Palo Alto Networks embeds DNS Security configuration directly within it - this is where you enable DGA detection, which uses cloud-based machine learning to identify algorithmically generated domains in real time, even if they've never been seen before.
Why the distractors are wrong:
- A (URL Filtering): Controls web category access, not DNS-layer threat detection.
- B (WildFire Analysis): Submits unknown files for sandbox analysis; it doesn't inspect DNS queries for DGA patterns.
- C (Vulnerability Protection): Defends against exploits targeting known CVEs in software, not domain-based C2 communication.
Memory tip: Think "spyware calls home" - DGA is how malware phones its command-and-control server via sneaky domains, and Anti-Spyware is what catches that call. DNS Security lives inside Anti-Spyware because both address covert outbound communication, not web browsing (URL Filtering) or file threats (WildFire).
Topics
Community Discussion
No community discussion yet for this question.