A company requires that all outbound traffic from its internal network must be subject to threat prevention, including antivirus, anti-spyware, and vulnerability protection. Additionally, WildFire analysis should be performed on all executable files. Which security profile group should be created and applied to achieve this comprehensive threat prevention?
- AA profile group containing Antivirus, Anti-Spyware, Vulnerability Protection, and URL Filtering profiles.
- BA profile group containing Antivirus, Anti-Spyware, Vulnerability Protection, and File Blocking profiles.
- CA profile group containing a custom Threat Prevention profile and a Data Filtering profile.
- DA profile group containing Antivirus, Anti-Spyware, Vulnerability Protection, and WildFire Analysis profiles.
Show answer & explanationAnswer & explanation
Correct answer: D. A profile group containing Antivirus, Anti-Spyware, Vulnerability Protection, and WildFire Analysis profiles.
The requirement specifically calls for antivirus, anti-spyware, vulnerability protection, and WildFire analysis for executable files. These functions are directly provided by the Antivirus, Anti-Spyware, Vulnerability Protection, and WildFire Analysis security profiles, respectively. A Security Profile Group allows combining these into a single entity for easy application to security rules.
Why the other options are wrong
- A. URL Filtering is for web category control, not core threat prevention or WildFire analysis.
- B. File Blocking controls file types but doesn't perform WildFire analysis for unknown threats.
- C. A custom Threat Prevention profile combines antivirus, anti-spyware, and vulnerability protection, but Data Filtering is for sensitive data, not WildFire analysis.
Security Profile Groups
Security Profile Groups allow administrators to bundle multiple security profiles (e.g., Antivirus, Threat Prevention, URL Filtering, WildFire) into a single object that can be applied to security policy rules.
- Simplifies policy management by applying multiple profiles simultaneously.
- Ensures consistent application of security best practices.
- Can combine different types of profiles (threat, content, data filtering).
- Applied in the 'Actions' tab of a security policy rule.
Memory trick: Groups bundle profiles, for easy apply, keep networks safe, reach for the sky.