Courseiva
Securing Traffic →mediumMultiple Select

PCNSA Securing Traffic Practice Question

When creating a security policy to block malware, which THREE profile types should be applied for comprehensive protection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Antivirus

Antivirus (A) is correct because it scans traffic for known malware signatures and malicious payloads, directly blocking viruses, worms, and trojans at the content level. Anti-Spyware (E) is correct because it detects and blocks spyware, keyloggers, and command-and-control traffic that antivirus signatures may not cover, providing complementary malware protection. Vulnerability Protection (C) is correct because it inspects traffic for exploits targeting software vulnerabilities, blocking the delivery mechanisms malware often uses to compromise hosts. URL Filtering (B) is not marked correct because it primarily controls web access by category or reputation rather than blocking malware itself, and File Blocking (D) is not marked correct because it restricts file transfers by type rather than detecting malicious content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Antivirus

    Why this is correct

    Antivirus profiles inspect traffic for known malware signatures and block malicious file transfers, satisfying the requirement to block malware at the content level. Applied alongside anti-spyware and vulnerability protection profiles, it forms the three-profile set Palo Alto Networks recommends for comprehensive threat coverage in a security policy.

  • ✗

    URL Filtering

    Why it's wrong here

    URL Filtering classifies web destinations by category and reputation; it inspects neither file payloads nor protocol exploits, so it cannot block malware delivery. It is tempting because malicious sites distribute malware, and URL Filtering is the right profile when policy must restrict browsing to approved categories.

  • ✓

    Vulnerability Protection

    Why this is correct

    Vulnerability Protection profiles block exploits targeting known software flaws, such as buffer overflows and code-execution attempts, by inspecting traffic against signatures for specific CVEs. This satisfies the stem's requirement for comprehensive malware defence, since exploit prevention stops the initial compromise vector that antivirus alone cannot reliably catch.

  • ✗

    File Blocking

    Why it's wrong here

    File Blocking controls file transfers by type, not malware signatures or exploit behaviour, so it cannot inspect payloads for threats. It is tempting because blocking executables and archives sounds protective, and it is correct when policy must prevent specific file types leaving the network.

  • ✓

    Anti-Spyware

    Why this is correct

    Anti-Spyware profiles satisfy the malware-blocking requirement by scanning traffic for known spyware signatures and command-and-control callbacks, then applying block or alert actions. Combined with Antivirus, Vulnerability, URL Filtering, and WildFire profiles, it forms the layered content inspection the stem demands for comprehensive protection.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PCNSA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO security profile types are used to block known malware? (Choose two.)

easy
  • ✓ A.File Blocking
  • B.URL Filtering
  • C.Anti-Spyware
  • ✓ D.Antivirus
  • E.Vulnerability Protection

Why A: Antivirus (D) is correct because it scans traffic for known malware signatures and blocks or alerts on files containing viruses, worms, and trojans as they pass through the firewall. File Blocking (A) is correct because it blocks file transfers based on file type, and it can be configured to block files that are known to carry malware, such as executables, thereby preventing known malicious file types from entering the network. URL Filtering (B) is not correct because it controls access to websites based on URL categories rather than blocking malware itself. Anti-Spyware (C) is not correct because it targets spyware, adware, and command-and-control traffic, not known malware files. Vulnerability Protection (E) is not correct because it blocks exploits targeting software vulnerabilities rather than known malware signatures.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.