exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 311 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 311
Topic #: 1
[All PCNSA Questions]

Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?

  • A. smb
  • B. imap
  • C. ftp
  • D. http2
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fb48
Highly Voted 12 months ago
Answer B. HTTP/2 has allow which does not create a log-entry
upvoted 7 times
...
mirko1976
Most Recent 2 weeks, 1 day ago
Selected Answer: D
I think D The question asks which protocol permits the traffic after detecting a machine-learning match. Looking at the WildFire Inline ML Action column, only http2 has the action allow. Other protocols (e.g., ftp, smb, imap) have either reset-both or alert, which would either block or just log the traffic.
upvoted 1 times
...
Zeruz
6 months, 3 weeks ago
Selected Answer: B
B: IMAP is the only app in the profile that covers all the requirements to the question.
upvoted 3 times
...
modems
7 months, 2 weeks ago
Why not HTTP? Not too sure how IMAP can be used for machine learning. Action Alert: generates an alert for each application traffic flow. The alert is saved in the threat log.
upvoted 1 times
...
MarkGrootaarts
10 months ago
Selected Answer: B
Is the correct answer
upvoted 1 times
...
DlaEdu_Ex
11 months, 3 weeks ago
Selected Answer: B
B is the correct answer. According to the screenshot, only imap, pop3 and smtp have a default (alert) action, which generates an alert for each application traffic flow. The alert is saved in the threat log. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-profiles
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago