Palo_Alto_Networks
PSE-STRATA · Question #205
What is the correct behavior when a Palo Alto Networks next-generation firewall (NGFW) is unable to retrieve a DNS verdict from DNS service cloud in the configured lookup time?
The correct answer is C. NGFW permit a response from the DNS server.. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns- security/enable-dns-security
Threat Prevention
Question
What is the correct behavior when a Palo Alto Networks next-generation firewall (NGFW) is unable to retrieve a DNS verdict from DNS service cloud in the configured lookup time?
Options
- ANGFW discard a response from the DNS server.
- BNGFW temporarily disable DNS Security function.
- CNGFW permit a response from the DNS server.
- DNGFW resend a verdict challenge to DNS service cloud.
How the community answered
(42 responses)- A7% (3)
- B14% (6)
- C74% (31)
- D5% (2)
Explanation
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns- security/enable-dns-security
Topics
#DNS Security#fail-open behavior#DNS verdict lookup#timeout handling
Community Discussion
No community discussion yet for this question.