Courseiva

NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture

An enterprise architect is troubleshooting an issue where an internal host is successfully executing a DNS tunneling attack through corporate firewalls. Standard DNS security profiles are enabled, but the attacker is using a randomized, low-frequency query rate that avoids triggering high-volume DNS tunneling signatures. Which advanced CDSS architectural feature must the architect configure to mitigate this threat?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable DNS Security with advanced machine learning-based categorization and predictive domain analysis within the Anti-Spyware profile.

DNS Security cloud-delivered service utilizes predictive analytics and machine learning models in the cloud to analyze patterns, domain generation algorithms (DGAs), and low-frequency DNS tunneling behavior that static signatures miss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enforce strict TCP proxying for all DNS traffic passing through the firewall dataplane.

    Why it's wrong here

    Standard DNS traffic operates over UDP port 53, and forcing TCP proxying does not provide predictive threat analytics.

  • Write a custom URL Filtering category blocking all domains with more than three subdomains.

    Why it's wrong here

    URL Filtering categorizes web browsing traffic and does not analyze raw DNS packet payloads or tunneling protocols effectively.

  • Enable DNS Security with advanced machine learning-based categorization and predictive domain analysis within the Anti-Spyware profile.

    Why this is correct

    Machine learning models in DNS Security detect subtle, low-frequency DGA and tunneling patterns that evade standard signature detection.

  • Configure a custom Threat Prevention vulnerability signature with an extremely low threshold for UDP port 53 packet counts.

    Why it's wrong here

    Low-frequency DNS tunneling specifically evades volume-based thresholds by design.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.