ExamGecko
Question list
Search
Search

Related questions











Question 360 - PCNSE discussion

Report
Export

You are auditing the work of a co-worker and need to verify that they have matched the Palo Alto Networks Best Practices for Anti-Spyware Profiles.

For which three severity levels should single-packet captures be enabled to meet the Best Practice standard? (Choose three.)

A.
Low
Answers
A.
Low
B.
High
Answers
B.
High
C.
Critical
Answers
C.
Critical
D.
Informational
Answers
D.
Informational
E.
Medium
Answers
E.
Medium
Suggested answer: B, C, E

Explanation:

https://docs.paloaltonetworks.com/best-practices/10-2/data-center-best-practices/data-center-best-practice-security-policy/how-to-create-data-center-best-practice-security-profiles/create-the-data-center-best-practice-anti-spyware-profile

The Palo Alto Networks Best Practices for Anti-Spyware Profiles recommend enabling single-packet captures (PCAP) for medium, high, and critical severity threats. This allows for capturing the first packet of the malicious traffic for further analysis and investigation.PCAP should not be enabled for low and informational severity threats, as they generate a relatively high volume of traffic and are not particularly useful compared to potential threats2.Reference:Create the Data Center Best Practice Anti-Spyware Profile,Security Profile: Anti-Spyware, PCNSE Study Guide (page 57)

asked 23/09/2024
Alexander Goris
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first