Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard

A network security team is implementing a new threat prevention profile. After applying the profile, users report intermittent connectivity issues and unexpected application behavior for a critical internal application. The threat logs show numerous 'vulnerability' alerts for the internal application's traffic, but the application developers confirm the traffic is legitimate and safe. Which action should the security team take FIRST to mitigate the immediate impact while investigating the false positives?

  1. ADisable the entire threat prevention profile for all traffic.
  2. BChange the action of the vulnerability signatures from 'block' to 'alert' for the specific application.
  3. CCreate a new security policy to allow the application traffic without any threat profiles.
  4. DConfigure a vulnerability protection exception for the specific signature(s) on the affected application.
Show answer & explanation

Correct answer: D. Configure a vulnerability protection exception for the specific signature(s) on the affected application.

The most targeted and least impactful first step to mitigate immediate issues from false positives in threat prevention is to create a vulnerability protection exception. This allows you to specifically bypass detection for the problematic signatures on the legitimate application's traffic, while keeping the rest of the threat prevention profile active for other traffic, minimizing exposure.

Why the other options are wrong

  • A. Disabling the entire profile is too broad; it removes all threat protection, creating a significant security gap.
  • B. Changing the action to 'alert' would stop blocking but still generate logs, which might still consume resources and doesn't fully resolve the 'unexpected application behavior' if the firewall is still inspecting/modifying traffic based on the signature. An exception is cleaner for false positives.
  • C. Creating a new security policy without threat profiles is also too broad and removes all threat protection for that application, which is not ideal for a 'first' step to mitigate false positives.

Threat Prevention False Positive Mitigation

When legitimate application traffic is incorrectly flagged by threat prevention signatures, the most effective immediate mitigation is to create a targeted exception for the specific signature(s) and application.

  • Aims for minimal security posture reduction.
  • Exceptions are granular, not global.
  • Allows continued protection for other traffic.

Memory trick: False Positives: 'Fine-tune' the 'Filters', don't 'Flee'.

More Troubleshoot questions