Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A security auditor requires that all outbound HTTP/HTTPS traffic from the internal network must be inspected for malware, spyware, and command-and-control (C2) activity. Additionally, the auditor wants to ensure that no sensitive data leaves the network in these connections. Which security profile combination should be applied to the relevant security policy rule to meet these requirements?
- AAntivirus, Anti-Spyware, Vulnerability Protection, Data Filtering
- BAntivirus, Anti-Spyware, URL Filtering, Data Filtering
- CAntivirus, Anti-Spyware, URL Filtering, File Blocking
- DAntivirus, Anti-Spyware, Vulnerability Protection
Show answer & explanationAnswer & explanation
Correct answer: A. Antivirus, Anti-Spyware, Vulnerability Protection, Data Filtering
To inspect for malware (Antivirus), spyware and C2 (Anti-Spyware), and prevent sensitive data exfiltration (Data Filtering), these three profiles are essential. Vulnerability Protection adds an extra layer against exploits. URL Filtering and File Blocking are not explicitly requested as the primary mechanism for preventing sensitive data exfiltration or C2 activity in this context.
Why the other options are wrong
- B. URL Filtering is not the primary tool for C2 detection or sensitive data filtering in this scenario; Data Filtering is more direct for sensitive data.
- C. URL Filtering is for website categories and File Blocking is for file types, neither directly addresses preventing sensitive data exfiltration or comprehensive C2 detection as effectively as Anti-Spyware.
- D. This combination covers malware, spyware, C2, and exploits, but lacks a specific mechanism for preventing sensitive data exfiltration.
Content-ID Security Profiles
Content-ID leverages multiple security profiles to inspect traffic for threats and sensitive data, providing comprehensive protection.
- Antivirus: Blocks known malware.
- Anti-Spyware: Detects and blocks spyware and C2 traffic.
- Vulnerability Protection: Prevents exploits of known vulnerabilities.
- Data Filtering: Identifies and blocks sensitive data patterns.
- File Blocking: Controls transfer of specific file types.
Memory trick: Content-ID is like a meticulous security inspector, checking for every type of forbidden item (malware, spyware, sensitive data).