ExamGecko
Question list
Search
Search

Related questions











Question 101 - PCNSE discussion

Report
Export

A firewall administrator needs to be able to inspect inbound HTTPS traffic on servers hosted in theirDMZ to prevent the hosted service from being exploited. Which combination of features can allowPAN-OS to detect exploit traffic in a session with TLS encapsulation?

A.
Decryption policy and a Data Filtering profile
Answers
A.
Decryption policy and a Data Filtering profile
B.
a WildFire profile and a File Blocking profile
Answers
B.
a WildFire profile and a File Blocking profile
C.
Vulnerability Protection profile and a Decryption policy
Answers
C.
Vulnerability Protection profile and a Decryption policy
D.
a Vulnerability Protection profile and a QoS policy
Answers
D.
a Vulnerability Protection profile and a QoS policy
Suggested answer: C

Explanation:

A vulnerability protection profile enables the firewall to detect and prevent exploit attempts against known vulnerabilities in network protocols and applications. A decryption policy allows the firewall to decrypt and inspect inbound HTTPS traffic for potential threats. A data filtering profile is used for detecting and controlling the transfer of sensitive data such as credit card numbers or social security numbers. A WildFire profile is used for submitting unknown files or email links to the WildFire cloud for analysis and verdict. A file blocking profile is used for blocking or allowing the transfer of files based on their type, direction, or application. A QoS policy is used for managing the bandwidth allocation and priority of network traffic based on various criteria. Reference: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts/ssl- inbound-inspection https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/threat-prevention/set-up- vulnerability-protection.html

asked 23/09/2024
Piroon Dechates
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first