nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #78

A Palo Alto Networks NGFW with URL Filtering and Threat Prevention enabled flags an internal user attempting to access a 'gambling' category website. The SOC policy strictly prohibits access to gambli

The correct answer is C. False Positive; The site was miscategorized, leading to an incorrect alert. Submit a URL. This scenario represents a False Positive. The alert was generated due to a miscategorization of a legitimate website. The most appropriate mitigation strategy is to submit a URL categorization change request to Palo Alto Networks to correct the database. Additionally, creating a

Security Monitoring and Alert Triage

Question

A Palo Alto Networks NGFW with URL Filtering and Threat Prevention enabled flags an internal user attempting to access a 'gambling' category website. The SOC policy strictly prohibits access to gambling sites. However, upon further investigation, it's determined the user was attempting to access a legitimate investment trading platform that was miscategorized by the URL filtering service. From an alert classification perspective, how would you describe this situation, and what mitigation strategy is most appropriate to prevent recurrence?

Options

  • ATrue Positive; The policy was violated. Isolate the user and block the website globally.
  • BFalse Negative; The firewall failed to block a prohibited site. Update the URL filtering database
  • CFalse Positive; The site was miscategorized, leading to an incorrect alert. Submit a URL
  • DTrue Negative; The firewall correctly identified benign traffic. No action is needed as the user
  • EThis is a policy violation, not a classification error. Sanction the user per HR policy.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    73% (19)
  • E
    15% (4)

Explanation

This scenario represents a False Positive. The alert was generated due to a miscategorization of a legitimate website. The most appropriate mitigation strategy is to submit a URL categorization change request to Palo Alto Networks to correct the database. Additionally, creating a custom URL category for the legitimate investment platform and adding it to an allow list can provide immediate remediation and ensure the site is accessible while the categorization update is processed. Options A and B are incorrect as the initial assessment was flawed; Option D misunderstands the nature of the alert (it was an alert, not a silent pass); Option E focuses solely on user sanction without addressing the underlying technical misclassification.

Topics

#false positive#URL filtering#alert classification#miscategorization

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice