exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 164 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 164
Topic #: 1
[All PCNSE Questions]

How can an administrator configure the firewall to automatically quarantine a device using GlobalProtect?

  • A. by adding the device's Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device
  • B. by exporting the list of quarantined devices to a pdf or csv file by selecting PDF/CSV at the bottom of the Device Quarantine page and leveraging the appropriate XSOAR playbook
  • C. by using security policies, log forwarding profiles, and log settings
  • D. there is no native auto-quarantine feature so a custom script would need to be leveraged
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mmed
Highly Voted 3 years, 5 months ago
confirm c https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html
upvoted 7 times
...
NLT
Highly Voted 2 years, 5 months ago
After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings.
upvoted 5 times
...
NullNull88
Most Recent 4 days, 2 hours ago
Selected Answer: C
A and B are not automatic it has to be C or D now
upvoted 1 times
...
corpguy
1 month, 3 weeks ago
Selected Answer: A
The answer is A, not sure why people are saying C with the same link. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices
upvoted 3 times
SCCUser
3 weeks ago
The correct answer is C. In your link say "you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings." HOST ID for manually and security policies, log forwarding profiles, and log settings for automatically.
upvoted 2 times
corpguy
2 weeks ago
I missed the key word “automatically”, thank you
upvoted 1 times
...
...
...
Marshpillowz
7 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
lol12
1 year, 9 months ago
Selected Answer: C
C https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device
upvoted 3 times
...
Gilmarcio
2 years, 6 months ago
Correct "C" https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device.html#idb42b2b82-b253-4be7-9840-1efa49dba3da
upvoted 1 times
...
Plato22
2 years, 8 months ago
Answer is C. Read the wording of the question and then find the answer here: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html
upvoted 3 times
...
prosto_marussia
2 years, 8 months ago
After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings. Both A and C kinda work.
upvoted 1 times
Martian89
2 years, 1 month ago
A is not automatic though (question is about automatic quarantine)
upvoted 3 times
...
...
Biz90
2 years, 10 months ago
Hi Team, the answer is A based on the KB below it even tells you that: 'you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device'
upvoted 1 times
Breyarg
2 years, 7 months ago
i agree but then re-read the question it implies "automatically" which suggests no manual intervention. so only "C" can be correct now.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago