PCNSA PCNSA Threat Prevention 1 — Questions and Answers
Question 1: Which Palo Alto Networks security profile is used to detect and block known vulnerability exploits targeting applications?
- Antivirus profile
- Vulnerability Protection profile (Correct answer)
- Anti-Spyware profile
- URL Filtering profile
Correct answer: Vulnerability Protection profile
The Vulnerability Protection profile detects and blocks exploit attempts targeting known application vulnerabilities.
Question 2: What is the purpose of the Antivirus security profile on a Palo Alto Networks firewall?
- Block access to malicious URLs
- Detect and block malware in network traffic (Correct answer)
- Prevent command-and-control communications
- Identify and block known exploits
Correct answer: Detect and block malware in network traffic
The Antivirus security profile scans network traffic to detect and block malware, including viruses and trojans.
Question 3: Which action in a Threat Prevention profile causes the firewall to generate a log entry but still allow the traffic?
- Block
- Drop
- Alert (Correct answer)
- Reset-client
Correct answer: Alert
The Alert action logs the event and generates an alert but permits the traffic to pass through.
Question 4: What does the Anti-Spyware profile protect against on a Palo Alto Networks firewall?
- SQL injection attacks
- Command-and-control (C2) traffic and spyware phone-home activity (Correct answer)
- Buffer overflow exploits
- Brute force login attempts
Correct answer: Command-and-control (C2) traffic and spyware phone-home activity
The Anti-Spyware profile detects and blocks spyware communications, including C2 traffic from compromised hosts.
Question 5: In Palo Alto Networks threat prevention, what is a 'signature exception' used for?
- To create custom threat signatures
- To exempt a specific threat ID from a profile's action (Correct answer)
- To schedule when threat signatures are updated
- To share signatures across multiple firewalls
Correct answer: To exempt a specific threat ID from a profile's action
A signature exception allows administrators to override the default action for a specific threat ID within a security profile.
Question 6: Which Palo Alto Networks feature uses machine learning to identify and block unknown threats in real time?
- App-ID
- WildFire (Correct answer)
- Zone Protection
- Security Zones
Correct answer: WildFire
WildFire uses cloud-based sandboxing and machine learning to analyze and block unknown, zero-day threats.
Which Palo Alto Networks security profile is used to detect and block known vulnerability exploits targeting applications?