PCNSA PCNSA Threat Prevention 2 — Questions and Answers
Question 1: What is the recommended WildFire file blocking action for unknown files in a high-security environment?
- Allow and log
- Forward for analysis (Correct answer)
- Block until verdict
- Skip analysis
Correct answer: Forward for analysis
Forwarding unknown files to WildFire for analysis allows the firewall to receive a verdict and take appropriate action.
Question 2: Which profile type must be attached to a security policy rule for threat prevention to be enforced?
- Authentication profile
- Certificate profile
- Security profile (Correct answer)
- HIP profile
Correct answer: Security profile
Security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, etc.) must be attached to security policy rules to enforce threat inspection.
Question 3: What does the 'reset-both' action do in a Palo Alto Networks threat prevention profile?
- Resets only the client-side TCP connection
- Sends TCP reset to both the client and the server (Correct answer)
- Resets the firewall session table
- Restarts the threat prevention service
Correct answer: Sends TCP reset to both the client and the server
The reset-both action terminates the TCP connection by sending a TCP RST to both the client and the server simultaneously.
Question 4: In Palo Alto Networks, what is a 'Security Profile Group' used for?
- Grouping firewall administrators by role
- Combining multiple security profiles into a single object for easy policy assignment (Correct answer)
- Defining zones that share the same security level
- Grouping IP addresses for security policies
Correct answer: Combining multiple security profiles into a single object for easy policy assignment
A Security Profile Group bundles multiple individual profiles (Antivirus, Anti-Spyware, etc.) so they can be applied to policy rules as a single object.
Question 5: Which threat severity level in Palo Alto Networks indicates the highest risk and requires immediate attention?
- Medium
- High
- Low
- Critical (Correct answer)
Correct answer: Critical
Critical severity indicates the most serious threats, such as those that could allow full system compromise or remote code execution.
Question 6: What is the primary function of Zone Protection profiles on a Palo Alto Networks firewall?
- Encrypting traffic between zones
- Protecting zones from flood, reconnaissance, and packet-based attacks (Correct answer)
- Managing user authentication at zone boundaries
- Defining which applications are allowed between zones
Correct answer: Protecting zones from flood, reconnaissance, and packet-based attacks
Zone Protection profiles defend network zones against DoS floods, port scans, and malformed packet attacks at the zone ingress.
What is the recommended WildFire file blocking action for unknown files in a high-security environment?