Zone Security, Security and NAT Policies
UPDATED ACTUAL Exam Questions and
CORRECT Answers
C2 - CORRECT ANSWER - At which point of the cyberattack lifecycle stage does the
attacker achieve "hands on keyboard" control of the target device?
They are pervasive .
They often are used as part of an APT . - CORRECT ANSWER - Which two
characteristics are common among commodity threats ? ( Choose two . )
Port scanning
Ping sweep - CORRECT ANSWER - Name 2 examples of active reconnaissance.
Network segmentation
Zone protection
External dynamic lists
Security policy rules - CORRECT ANSWER - Name 4 Palo Alto features that help
prevent or mitigate reconnaissance.
Host sweeps
Port scan protection - CORRECT ANSWER - How do zone protection profiles
protect/mitigate reconnaissance attacks?
Weaponization Stage - CORRECT ANSWER - The attacker prepares the malware that
they will deliver to the target machine in a later stage .
Enticing the user
, Direct access to service or application - CORRECT ANSWER - What are 2 ways an
attacker can deliver weaponized malware to a target?
Exploitation stage - CORRECT ANSWER - At what stage of the cyberattack lifecycle is
the delivered malware executed?
Security Policy rules
URL Filtering
File Blocking Profile
Wildfire Profile - CORRECT ANSWER - What are 4 ways that a firewall protections at
the installation stage?
Allow only known application traffic Control access to unknown websites and domains
Block access using EDLS
Decrypt and inspect encrypted traffic - CORRECT ANSWER - Name 4 ways a firewall
blocks C2 traffic.
Exfiltrate Data
Corrupt data
Encrypt data
Initiate DoS attack
Reach Actual Target - CORRECT ANSWER - What are some reasons that an attack might
occur?
File blocking profiles
Data filtering profiles - CORRECT ANSWER - What are some ways a firewall can
prevent exfiltration?
UPDATED ACTUAL Exam Questions and
CORRECT Answers
C2 - CORRECT ANSWER - At which point of the cyberattack lifecycle stage does the
attacker achieve "hands on keyboard" control of the target device?
They are pervasive .
They often are used as part of an APT . - CORRECT ANSWER - Which two
characteristics are common among commodity threats ? ( Choose two . )
Port scanning
Ping sweep - CORRECT ANSWER - Name 2 examples of active reconnaissance.
Network segmentation
Zone protection
External dynamic lists
Security policy rules - CORRECT ANSWER - Name 4 Palo Alto features that help
prevent or mitigate reconnaissance.
Host sweeps
Port scan protection - CORRECT ANSWER - How do zone protection profiles
protect/mitigate reconnaissance attacks?
Weaponization Stage - CORRECT ANSWER - The attacker prepares the malware that
they will deliver to the target machine in a later stage .
Enticing the user
, Direct access to service or application - CORRECT ANSWER - What are 2 ways an
attacker can deliver weaponized malware to a target?
Exploitation stage - CORRECT ANSWER - At what stage of the cyberattack lifecycle is
the delivered malware executed?
Security Policy rules
URL Filtering
File Blocking Profile
Wildfire Profile - CORRECT ANSWER - What are 4 ways that a firewall protections at
the installation stage?
Allow only known application traffic Control access to unknown websites and domains
Block access using EDLS
Decrypt and inspect encrypted traffic - CORRECT ANSWER - Name 4 ways a firewall
blocks C2 traffic.
Exfiltrate Data
Corrupt data
Encrypt data
Initiate DoS attack
Reach Actual Target - CORRECT ANSWER - What are some reasons that an attack might
occur?
File blocking profiles
Data filtering profiles - CORRECT ANSWER - What are some ways a firewall can
prevent exfiltration?