Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A company policy dictates that all outbound web traffic (HTTP/HTTPS) from the internal network to the internet must be inspected for malware, spyware, and vulnerability exploits. Which security profile should be applied to the outbound security policy rule to enforce this requirement comprehensively?

  1. ASecurity Profile Group
  2. BAnti-Spyware Profile
  3. CURL Filtering Profile
  4. DVulnerability Protection Profile
Show answer & explanation

Correct answer: A. Security Profile Group

To inspect for malware, spyware, and vulnerability exploits comprehensively, multiple security profiles are needed. A Security Profile Group allows bundling Anti-Virus, Anti-Spyware, and Vulnerability Protection profiles (among others) into a single entity for easy application to a security policy rule.

Why the other options are wrong

  • B. Anti-Spyware profile specifically protects against spyware but doesn't cover general malware or vulnerability exploits.
  • C. URL Filtering primarily controls access to websites based on categories, not for malware or vulnerability exploits.
  • D. Vulnerability Protection profile specifically protects against known exploits but doesn't cover malware or spyware.

Security Profile Group

A Security Profile Group is a collection of individual security profiles (e.g., Anti-Virus, Anti-Spyware, Vulnerability Protection) that can be applied together to a security policy rule.

  • Simplifies policy management.
  • Ensures consistent application of multiple protections.
  • Includes threat prevention, URL filtering, file blocking, and data filtering profiles.

Memory trick: Group Profiles for Total Protection.

More Security Policy Configuration questions