PCNSE URL Filtering and Application Control 1 — Questions and Answers
Question 1: What is the function of a URL Filtering profile in Palo Alto Networks?
- To decrypt HTTPS traffic for deep packet inspection
- To control user access to websites based on URL categories (Correct answer)
- To identify applications using behavioral analysis
- To block malicious IP addresses using threat intelligence
Correct answer: To control user access to websites based on URL categories
A URL Filtering profile allows administrators to allow, block, alert, or override access to websites based on PAN-DB URL categories.
Question 2: Which database does Palo Alto Networks use to classify URLs into categories for URL Filtering?
- Brightcloud
- PAN-DB (Correct answer)
- MaxMind
- Umbrella
Correct answer: PAN-DB
PAN-DB is Palo Alto Networks' proprietary URL categorization database, which classifies billions of URLs into categories that can be used in URL Filtering profiles.
Question 3: What does the 'continue' action do in a URL Filtering profile?
- Automatically allows the user to access the site without interruption
- Displays a warning page requiring the user to click through before accessing the site (Correct answer)
- Blocks the site entirely and logs the attempt
- Forwards the request to a SIEM for analysis
Correct answer: Displays a warning page requiring the user to click through before accessing the site
The 'continue' action presents the user with a warning page acknowledging the site category, requiring a manual click-through to proceed, while logging the access.
Question 4: Which URL category should be blocked in most enterprise environments to prevent malware distribution?
- News
- Malware (Correct answer)
- Shopping
- Social Networking
Correct answer: Malware
The 'Malware' URL category includes sites known to distribute malicious software and should be blocked in all enterprise URL Filtering profiles.
Question 5: What is the 'override' action in URL Filtering used for?
- To allow IT administrators to bypass all security policies
- To allow authorized users to access blocked sites after entering a password (Correct answer)
- To whitelist an entire URL category
- To reset the PAN-DB cache on the firewall
Correct answer: To allow authorized users to access blocked sites after entering a password
The 'override' action allows specific users to enter an administrator-configured password to temporarily bypass a URL block for a particular site or category.
Question 6: In Palo Alto Networks, which component must be enabled for URL Filtering to inspect HTTPS websites?
- App-ID
- SSL/TLS Decryption (Correct answer)
- WildFire
- DNS Security
Correct answer: SSL/TLS Decryption
SSL/TLS Decryption must be configured to allow the firewall to inspect the URLs within encrypted HTTPS sessions, as without decryption only the SNI hostname is visible.
What is the function of a URL Filtering profile in Palo Alto Networks?