ExamGecko
Question list
Search
Search

Question 3 - PCCET discussion

Report
Export

Which security component can detect command-and-control traffic sent from multiple endpoints within a corporate data center?

A.
Personal endpoint firewall
Answers
A.
Personal endpoint firewall
B.
Port-based firewall
Answers
B.
Port-based firewall
C.
Next-generation firewall
Answers
C.
Next-generation firewall
D.
Stateless firewall
Answers
D.
Stateless firewall
Suggested answer: C

Explanation:

A next-generation firewall (NGFW) is a security component that can detect command-and-control (C2) traffic sent from multiple endpoints within a corporate data center. A NGFW is a network device that combines traditional firewall capabilities with advanced features such as application awareness, intrusion prevention, threat intelligence, and cloud-based analysis. A NGFW can identify and block C2 traffic by inspecting the application layer protocols, signatures, and behaviors of the network traffic, as well as correlating the traffic with external sources of threat intelligence. A NGFW can also leverage inline cloud analysis to detect and prevent zero-day C2 threats in real-time. A NGFW can provide granular visibility and control over the network traffic, as well as generate alerts and reports on the C2 activity.Reference:

Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)

Command and Control, Tactic TA0011 - Enterprise | MITRE ATT&CK

Advanced Threat Prevention: Inline Cloud Analysis - Palo Alto Networks

asked 23/09/2024
Gerrit Struik
54 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first