Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Palo Alto Networks TechnologiesMedium
A security analyst is investigating a potential data exfiltration attempt. They observe unusual outbound traffic patterns from a server containing sensitive intellectual property. Which Palo Alto Networks Next-Generation Firewall (NGFW) feature is most effective in preventing this type of activity by inspecting application content for sensitive data?
- AURL Filtering
- BThreat Prevention
- CApp-ID
- DData Filtering
Show answer & explanationAnswer & explanation
Correct answer: D. Data Filtering
Data Filtering on a Palo Alto Networks NGFW allows administrators to identify and block the transfer of sensitive information based on patterns, file types, or keywords, making it ideal for preventing data exfiltration.
Why the other options are wrong
- A. URL Filtering blocks access to malicious or inappropriate websites, not outbound sensitive data transfer.
- B. Threat Prevention protects against known vulnerabilities and malware, but isn't primarily designed for preventing sensitive data from leaving the network.
- C. App-ID identifies applications regardless of port, but doesn't specifically inspect content for sensitive data patterns.
Data Filtering (DLP)
A Next-Generation Firewall feature that inspects network traffic for sensitive information (e.g., credit card numbers, PII, intellectual property) and prevents its unauthorized transmission.
- Uses predefined or custom data patterns and profiles.
- Can block, alert, or log detected sensitive data.
- Crucial for preventing data exfiltration.
Memory trick: To stop data from leaking, you need a filter, not just an ID.