exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 398 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 398
Topic #: 1
[All PCNSE Questions]

An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems. From the Pre-defined Categories tab within the URL Filtering profile what is the right configuration to prevent such connections?

  • A. Set the malware category to block
  • B. Set the Command and Control category to block
  • C. Set the phishing category to override
  • D. Set the hacking category to continue
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
422849c
4 months, 2 weeks ago
Selected Answer: A
The answer is A because the question asking HOW an admin would accomplish a task "An administrator wants to prevent users from unintentionally accessing malicious domains where data can be exfiltrated through established connections to remote systems" The admin's goal is to stop known good users from getting to these malicious websites unknowingly C2 could be the answer if the question was worded differently but in this case the answer is A Set the malware category to block
upvoted 3 times
422849c
4 months, 2 weeks ago
https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/url-categories Malware Sites containing or known to host malicious content, executables, scripts, viruses, trojans, and code. Command and Control Command-and-control (C2) URLs and domains used by malware or compromised systems to surreptitiously communicate with an attacker's remote server to receive malicious commands or exfiltrate data.
upvoted 3 times
...
...
MostafaNawar
9 months, 2 weeks ago
Selected Answer: B
Command-and-control (C2) URLs and domains used by malware or compromised systems to surreptitiously communicate with an attacker's remote server to receive malicious commands or exfiltrate data.
upvoted 1 times
...
Marshpillowz
11 months, 3 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
Metgatz
1 year, 1 month ago
Selected Answer: B
C2 domains
upvoted 1 times
...
TheIronSheik
1 year, 11 months ago
Selected Answer: B
A could be correct since CC is part of what the malware does. However, if there is a category for CC traffic then that is what I would go with.
upvoted 2 times
...
Kaspinas
2 years, 1 month ago
Selected Answer: B
Answer B: "command-and-control—Command-and-control URLs and domains used by malware and/or compromised systems to surreptitiously communicate with an attacker's remote server to receive malicious commands or exfiltrate data."
upvoted 2 times
...
jabautista100191
2 years, 1 month ago
Selected Answer: B
"established connections to remote system"->Command and Control The correct is B
upvoted 2 times
...
mz101
2 years, 1 month ago
Looks like A is also correct? malware—Sites known to host malware or used for command and control (C2) traffic. May also exhibit Exploit Kits. (From the same web link)
upvoted 2 times
Goharam
2 years, 1 month ago
"command-and-control—Command-and-control URLs and domains used by malware and/or compromised systems to surreptitiously communicate with an attacker's remote server to receive malicious commands or exfiltrate data." so the answer is B, not A. cuz the question said: "from unintentionally accessing malicious domains".
upvoted 3 times
...
...
chrisy042
2 years, 1 month ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/url-filtering/url-categories/url-category-best-practices
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago