PSE-STRATA · Question #187
A customer is designing a private data center to host their new web application along with a separate headquarters for users. Which cloud-delivered security service (CDSS) would be recommended for…
The correct answer is A. Threat Prevention. Threat Prevention is the recommended CDSS for headquarters because it actively blocks network-based threats-exploits, command-and-control (C2) traffic, and malware-that target user-generated traffic patterns typical of an office environment. A private data center hosting a web…
Question
A customer is designing a private data center to host their new web application along with a separate headquarters for users. Which cloud-delivered security service (CDSS) would be recommended for the headquarters only?
Options
- AThreat Prevention
- BDNS Security
- CWildFire
- DAdvanced URL Filtering (AURLF)
How the community answered
(26 responses)- A77% (20)
- B4% (1)
- C15% (4)
- D4% (1)
Explanation
Threat Prevention is the recommended CDSS for headquarters because it actively blocks network-based threats-exploits, command-and-control (C2) traffic, and malware-that target user-generated traffic patterns typical of an office environment. A private data center hosting a web application has a different threat profile (primarily inbound server traffic), so the headquarters' user-browsing environment is where Threat Prevention delivers its most targeted value.
Why the distractors are wrong:
- B (DNS Security) protects against DNS-based attacks and tunneling, which is relevant to both the data center and headquarters-not HQ alone.
- C (WildFire) is a cloud sandboxing service for unknown malware analysis; it benefits both environments since unknown files can appear in either location.
- D (Advanced URL Filtering) controls web access by URL category and is broadly applicable across network zones, not restricted to a headquarters use case.
Memory tip: Think "HQ = humans browsing" - Threat Prevention is the core subscription that guards user traffic flows (anti-exploit, anti-spyware, antivirus in-line) against the threats people encounter while working. If a service sounds like it protects "everywhere" (DNS, sandboxing, URL categories), it's too broad to be HQ-only.
Community Discussion
No community discussion yet for this question.