ExamGecko
Question list
Search
Search

List of questions

Search

Question 211 - PCCSE discussion

Report
Export

Which policy type should be used to detect and alert on cryptominer network activity?

A.
Audit event
Answers
A.
Audit event
B.
Anomaly
Answers
B.
Anomaly
C.
Config-build
Answers
C.
Config-build
D.
Config-run
Answers
D.
Config-run
Suggested answer: B

Explanation:

To detect and alert on cryptominer network activity, the policy type that should be used is an Anomaly policy. Anomaly policies in Prisma Cloud are designed to identify unusual and potentially malicious activities, including the network patterns typical of cryptomining operations. These policies leverage behavioral analytics to spot deviations from normal operations, making Option B the correct answer.

Suspicious network actors---Exposes suspicious connections by inspecting the network traffic to and from your cloud environment and correlating it with AutoFocus, Palo Alto Networks threat intelligence feed. AutoFocus identifies IP addresses involved in suspicious or malicious activity and classifies them into one of eighteen categories. Some examples of the categories are Backdoor, Botnet, Cryptominer, DDoS, Ransomware, Rootkit, and Worm. There are thirty-six policies, two for each of the eighteen categories---internal and external. https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-policies/anomaly-policies

asked 23/09/2024
John Doe
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first