nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #187

A customer is designing a private data center to host their new web application along with a separate headquarters for users. Which cloud-delivered security service (CDSS) would be recommended for…

The correct answer is A. Threat Prevention. Threat Prevention is the recommended CDSS for headquarters because it actively blocks network-based threats-exploits, command-and-control (C2) traffic, and malware-that target user-generated traffic patterns typical of an office environment. A private data center hosting a web…

Question

A customer is designing a private data center to host their new web application along with a separate headquarters for users. Which cloud-delivered security service (CDSS) would be recommended for the headquarters only?

Options

  • AThreat Prevention
  • BDNS Security
  • CWildFire
  • DAdvanced URL Filtering (AURLF)

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    4% (1)
  • C
    15% (4)
  • D
    4% (1)

Explanation

Threat Prevention is the recommended CDSS for headquarters because it actively blocks network-based threats-exploits, command-and-control (C2) traffic, and malware-that target user-generated traffic patterns typical of an office environment. A private data center hosting a web application has a different threat profile (primarily inbound server traffic), so the headquarters' user-browsing environment is where Threat Prevention delivers its most targeted value.

Why the distractors are wrong:

  • B (DNS Security) protects against DNS-based attacks and tunneling, which is relevant to both the data center and headquarters-not HQ alone.
  • C (WildFire) is a cloud sandboxing service for unknown malware analysis; it benefits both environments since unknown files can appear in either location.
  • D (Advanced URL Filtering) controls web access by URL category and is broadly applicable across network zones, not restricted to a headquarters use case.

Memory tip: Think "HQ = humans browsing" - Threat Prevention is the core subscription that guards user traffic flows (anti-exploit, anti-spyware, antivirus in-line) against the threats people encounter while working. If a service sounds like it protects "everywhere" (DNS, sandboxing, URL categories), it's too broad to be HQ-only.

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice