exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 38 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 38
Topic #: 1
[All PCNSA Questions]

The CFO found a USB drive in the parking lot and decide to plug it into their corporate laptop. The USB drive had malware on it that loaded onto their computer and then contacted a known command and control (CnC) server, which ordered the infected machine to begin Exfiltrating data from the laptop.
Which security profile feature could have been used to prevent the communication with the CnC server?

  • A. Create an anti-spyware profile and enable DNS Sinkhole
  • B. Create an antivirus profile and enable DNS Sinkhole
  • C. Create a URL filtering profile and block the DNS Sinkhole category
  • D. Create a security policy and enable DNS Sinkhole
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Oteslar
2 months, 1 week ago
A is correct
upvoted 1 times
...
kewokil120
8 months ago
Selected Answer: A
A is correct
upvoted 3 times
...
javim
10 months, 2 weeks ago
Yes, the correct answer is A. DNS Sinkhole is not a Category of URL Filtering.
upvoted 2 times
...
Jheax
11 months, 2 weeks ago
DNS sinkhole can only be configured on the antispyware security profile. Answer is A.
upvoted 3 times
...
rodobrian
2 years, 8 months ago
Because they mention 'known C2 server' I think that URL filtering & DNS sinkhole is also a legitimate answer here. Known URLs that are associated with C2 are blocked via Pan-DB
upvoted 3 times
PANW
2 years, 8 months ago
Answer C is saying block DNS Sinkhole which is incorrect The answer is A
upvoted 11 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago