Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A network security administrator needs to ensure that all outbound HTTP/HTTPS traffic from the internal network to the internet is protected against known malware and exploits. Additionally, the company policy dictates that users should be prevented from accessing websites categorized as 'Gambling' or 'Malware'. Which security profiles should be applied to the outbound security policy rule to meet these requirements?
- AAntivirus and URL Filtering
- BThreat Prevention and File Blocking
- CAnti-Spyware and Data Filtering
- DWildFire Analysis and DoS Protection
Show answer & explanationAnswer & explanation
Correct answer: A. Antivirus and URL Filtering
Antivirus protects against known malware, while URL Filtering prevents access to specific website categories like 'Gambling' or 'Malware'. Both are essential for the stated requirements for outbound web traffic.
Why the other options are wrong
- B. Threat Prevention includes Antivirus, Anti-Spyware, and Vulnerability Protection, so it would cover 'malware and exploits'. However, File Blocking prevents specific file types, not website categories.
- C. Anti-Spyware is part of threat prevention, but Data Filtering prevents sensitive data exfiltration, which is not a stated requirement here.
- D. WildFire Analysis identifies unknown malware, and DoS Protection defends against denial-of-service attacks, neither of which directly addresses preventing access to 'Gambling' or 'Malware' URL categories.
Common Security Profiles
Palo Alto Networks firewalls use various security profiles to protect traffic. Antivirus detects known malware, and URL Filtering controls access to web categories.
- Antivirus: Blocks known viruses, worms, and spyware.
- URL Filtering: Controls web access based on categories or specific URLs.
- Threat Prevention: Comprehensive protection against exploits, malware, spyware.
Memory trick: Scan for Bugs, Block Bad Sites.