PCNSA Securing Traffic Practice Question
An organization wants to prevent data exfiltration via DNS tunneling. Which security profile should be applied to the outbound DNS traffic?
⚠ Common exam trap
A common mix-up: candidates confuse DNS Security with Anti-Spyware, assuming that spyware signatures will catch tunneling, but DNS tunneling is a protocol-level evasion technique that requires dedicated DNS inspection, not just signature-based malware detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS Security profile
DNS Security profile is specifically designed to detect and block DNS tunneling, which is a technique used to exfiltrate data by encoding it within DNS queries and responses. By inspecting DNS traffic for anomalies such as high query rates, unusual domain names, or non-standard record types, the DNS Security profile can identify and prevent data exfiltration attempts. Other security profiles do not have the specialized DNS-layer inspection capabilities required to counter this threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DNS Security profile
Why this is correct
DNS tunnelling encodes stolen data within DNS queries and responses, which the DNS Security profile detects and blocks by inspecting DNS payloads for malicious patterns, including tunnelling signatures and anomalous query behaviour. Applying it to outbound DNS traffic directly satisfies the requirement to prevent exfiltration.
- ✗
Vulnerability Protection profile
Why it's wrong here
Vulnerability Protection detects exploits against hosts, such as buffer overflows and malformed packets, and does not inspect DNS query contents for tunnelled data. It is tempting because it guards servers against known attack signatures, correct when protecting internal hosts from exploitation attempts.
- ✗
URL Filtering profile
Why it's wrong here
URL Filtering classifies HTTP/S requests against categories and threat feeds; it does not inspect DNS query payloads for tunnelled data, so exfiltration via encoded DNS records passes through. It is tempting because URL Filtering does block malicious domains, which would be the right control for stopping outbound web access to known bad sites.
- ✗
Anti-Spyware profile
Why it's wrong here
Anti-Spyware detects command-and-control callbacks and spyware signatures in allowed traffic, but DNS tunnelling hides data inside legitimate-looking queries that signature matching misses. It is tempting because Anti-Spyware profiles do inspect DNS for known malicious domains, making them the correct choice when blocking identified spyware C2 domains rather than tunnelling patterns.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.