nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #205

What is the correct behavior when a Palo Alto Networks next-generation firewall (NGFW) is unable to retrieve a DNS verdict from DNS service cloud in the configured lookup time?

The correct answer is C. NGFW permit a response from the DNS server.. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns- security/enable-dns-security

Threat Prevention

Question

What is the correct behavior when a Palo Alto Networks next-generation firewall (NGFW) is unable to retrieve a DNS verdict from DNS service cloud in the configured lookup time?

Options

  • ANGFW discard a response from the DNS server.
  • BNGFW temporarily disable DNS Security function.
  • CNGFW permit a response from the DNS server.
  • DNGFW resend a verdict challenge to DNS service cloud.

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    14% (6)
  • C
    74% (31)
  • D
    5% (2)

Explanation

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/dns- security/enable-dns-security

Topics

#DNS Security#fail-open behavior#DNS verdict lookup#timeout handling

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice