An administrator sees that a runtime audit has been generated for a Container. The audit message is `DNS resolution of suspicious name wikipedia.com. type A`. Why would this message appear as an audit?
A.
The DNS was not learned as part of the Container model or added to the DNS allow list.
B.
This is a DNS known to be a source of malware.
C.
The process calling out to this domain was not part of the Container model.
D.
The Layer7 firewall detected this as anomalous behavior.
A --> To avoid getting such an event for a known and allowed domain, add the domain name to the Runtime rule’s Domains list under Allowed in the Networking tab.
A
https://docs.paloaltonetworks.com/prisma/prisma-cloud/21-08/prisma-cloud-compute-edition-admin/runtime_defense/runtime_audits
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Spippolo
1 week, 1 day agoChichi23
1 month, 2 weeks agoRedrum702
4 months, 1 week ago