exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 281 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 281
Topic #: 1
[All PCNSE Questions]

The manager of the network security team has asked you to help configure the company's Security Profiles according to Palo Alto Networks best practice. As part of that effort, the manager has assigned you the Vulnerability Protection profile for the Internet gateway firewall. Which action and packet-capture setting for items of high severity and critical severity best matches Palo Alto Networks best practice?

  • A. action 'reset-server' and packet capture 'disable'
  • B. action 'default' and packet capture 'single-packet'
  • C. action 'reset-both' and packet capture 'extended-capture'
  • D. action 'reset-both' and packet capture 'single-packet'
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mysteryzjoker
Highly Voted 2 years, 4 months ago
answer is C "Enable extended-capture for critical, high, and medium severity events and single-packet capture for low severity events. " https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-security-profiles-vulnerability-protection
upvoted 24 times
secdaddy
2 years, 3 months ago
See the best practices document (kudos to GBD35055 for the URL) : The best practice Anti-Spyware profile retains the default Action to reset the connection when the firewall detects a medium, high, or critical severity threat, and enables single packet capture (PCAP) for those threats. https://docs.paloaltonetworks.com/best-practices/10-2/data-center-best-practices/data-center-best-practice-security-policy/how-to-create-data-center-best-practice-security-profiles/create-the-data-center-best-practice-anti-spyware-profile
upvoted 4 times
...
fireb
2 years, 3 months ago
Option C is correct.
upvoted 2 times
confusion
2 years, 2 months ago
No, D is correct! Question asks for Best Practice Internet Gateway Vulnerability Protection Profile.
upvoted 3 times
...
...
droide
1 year, 11 months ago
Still the same in pan-os 11.0
upvoted 2 times
...
...
masccsam8
Most Recent 3 months, 1 week ago
Selected Answer: D
answer is D
upvoted 1 times
...
0d2fdfa
8 months ago
Selected Answer: D
Option D is correct Option C is wrong This is internet Gateway Firewall. Packet captures on Internet gateway firewall does not make sense. Firewall would rather shut the session. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXCCA0 Notice that Anti-Spyware and Vulnerability Protection have more options Disabled Single Packet Select single-packet to capture one packet when a threat is detected. Extended-capture Select the extended-capture option to capture more packets. Extended-capture will provides much more context to the threat when analyzing the threat logs or when providing the captures for TAC to analyze.
upvoted 1 times
...
MostafaNawar
9 months, 2 weeks ago
Selected Answer: C
Answer C, Enable extended-capture for critical, high, and medium severity events and single-packet capture for low severity events. Use the default extended-capture value of 5 packets, which provides enough information to analyze the threat in most cases.
upvoted 2 times
...
Thunnu
10 months, 2 weeks ago
Yup D. https://docs.paloaltonetworks.com/best-practices/9-1/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/create-best-practice-security-profiles
upvoted 2 times
...
JRKhan
1 year ago
Selected Answer: D
Correct answer is D. For inbound traffic aka internet traffic to the network behind paloalto firewall, the best practice is to use strict profile which uses *reset-both* action for critical/high sev events. For pcaps, use *single pcap* as the traffic volume is usually high. Can also use extended captures if the action is set to *alert*.
upvoted 1 times
...
Whizdhum
1 year, 1 month ago
Selected Answer: D
Clone the predefined strict Vulnerability Protection profile and edit it to create the best practice profile: Change the Action in the three brute force rules to reset-both and Packet Capture to single-packet to transition from alerting on brute-force attack events to blocking them. Consolidate critical, high, and medium severity events for servers and clients into one rule. Set the Action to reset-both and set Packet Capture to single-packet. This simplifies the profile and works because the profile uses the same action and the same packet capture settings for these severities.
upvoted 1 times
...
Metgatz
1 year, 1 month ago
C is the correct option: action 'reset-both' and packet capture 'extended-capture
upvoted 2 times
...
RoamingFo
1 year, 1 month ago
Selected Answer: D
Recommended Action "Reset-Both" Recommended Capture ? This General doc recommends "Enable extended-capture for critical, high, and medium severity" https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-web-interface-help/objects/objects-security-profiles-vulnerability-protection The Internet Gateway Specific Doc Recommends "Consolidate critical, high,…. Set the Action to reset-both and set Packet Capture to single-packet" Correct Answer is D
upvoted 2 times
...
dorf05
1 year, 3 months ago
Selected Answer: D
https://docs.paloaltonetworks.com/best-practices/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/create-best-practice-security-profiles#:~:text=end%20user%E2%80%99s%20device.-,Best%20Practice%20Internet%20Gateway%20Vulnerability%20Protection%20Profile,same%20action%20and%20the%20same%20packet%20capture%20settings%20for%20these%20severities.,-For%20profiles%20that
upvoted 1 times
...
Betty2022
1 year, 5 months ago
Selected Answer: D
D is correct Question asks for Best Practice Internet Gateway Vulnerability Protection Profile. https://docs.paloaltonetworks.com/best-practices/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/create-best-practice-security-profiles Change the Action in the three brute force rules to reset-both and Packet Capture to single-packet to transition from alerting on brute-force attack events to blocking them. Consolidate critical, high, and medium severity events for servers and clients into one rule. Set the Action to reset-both and set Packet Capture to single-packet. This simplifies the profile and works because the profile uses the same action and the same packet capture settings for these severities.
upvoted 3 times
...
Pochex
1 year, 7 months ago
Answer D is correct. Refer to https://docs.paloaltonetworks.com/best-practices/10-2/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/create-best-practice-security-profiles and read the following section: 'Best Practice Internet Gateway Vulnerability Protection Profile'
upvoted 1 times
...
sujss
1 year, 9 months ago
Selected Answer: D
"For the best practice profile, for each rule except simple-client-informational and simple-server-informational, double-click the Rule Name and change Packet Capture from disable to single-packet to enable packet capture (PCAP) for each rule so you can track down the source of potential attacks." https://docs.paloaltonetworks.com/best-practices/10-2/data-center-best-practices/data-center-best-practice-security-policy/how-to-create-data-center-best-practice-security-profiles/create-the-data-center-best-practice-vulnerability-protection-profile
upvoted 1 times
...
[Removed]
1 year, 9 months ago
Selected Answer: C
For the best security, set the Action for both client and server critical, high, and medium severity events to reset-both and use the default action for Informational and Low severity events.
upvoted 1 times
...
IntheZone
1 year, 10 months ago
Selected Answer: C
"items of high severity and critical severity best matches Palo Alto Networks best practice" It is C
upvoted 1 times
...
daytonadave2011
1 year, 10 months ago
Selected Answer: D
D. Just went through some BPA's and single-capture is the recommended.
upvoted 1 times
...
Rowdy_47
1 year, 10 months ago
Selected Answer: D
For the best practice profile, for each rule except simple-client-informational and simple-server-informational, double-click the Rule Name and change Packet Capture from disable to single-packet to enable packet capture (PCAP) for each rule so you can track down the source of potential attacks. Don’t change the rest of the settings. Apply extended PCAP (as opposed to single PCAP) to high-value traffic to which you apply the alert Action We would not be setting an alert action on high severity and critical severity matches I think the answer is D https://docs.paloaltonetworks.com/best-practices/10-2/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/create-best-practice-security-profiles
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago