exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 151 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 151
Topic #: 1
[All PCNSA Questions]

You receive notification about new malware that infects hosts through malicious files transferred by FTP.
Which Security profile detects and protects your internal networks from this threat after you update your firewall's threat signature database?

  • A. URL Filtering profile applied to inbound Security policy rules.
  • B. Data Filtering profile applied to outbound Security policy rules.
  • C. Antivirus profile applied to inbound Security policy rules.
  • D. Vulnerability Protection profile applied to outbound Security policy rules.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-profiles

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cjace
1 month, 3 weeks ago
The default Antivirus profile inspects all of the listed protocol decoders for malware, and generates alerts for SMTP, IMAP, and POP3 protocols while blocking for FTP, HTTP, and SMB protocols3. Therefore, the correct answer is C. Antivirus profile applied to inbound Security policy rules. Please note that the other profiles mentioned have different purposes: URL Filtering profile is used to control access to websites based on categories1. Data Filtering profile is used to prevent sensitive information from leaving the network1. Vulnerability Protection profile is used to protect against exploits that target software vulnerabilities1.
upvoted 3 times
...
H3kerman
2 years, 7 months ago
Antivirus profiles protect against viruses, worms, and trojans as well as spyware downloads. Using a stream-based malware prevention engine, which inspects traffic the moment the first packet is received, the Palo Alto Networks antivirus solution can provide protection for clients without significantly impacting the performance of the firewall. This profile scans for a wide variety of malware in executables, PDF files, HTML and JavaScript viruses, including support for scanning inside compressed files and data encoding schemes. If you have enabled Decryption on the firewall, the profile also enables scanning of decrypted content. The default profile inspects all of the listed protocol decoders for viruses, and generates alerts for SMTP, IMAP, and POP3 protocols while blocking for FTP, HTTP, and SMB protocols.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago