NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture
An enterprise architect is troubleshooting an issue where an internal host is successfully executing a DNS tunneling attack through corporate firewalls. Standard DNS security profiles are enabled, but the attacker is using a randomized, low-frequency query rate that avoids triggering high-volume DNS tunneling signatures. Which advanced CDSS architectural feature must the architect configure to mitigate this threat?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable DNS Security with advanced machine learning-based categorization and predictive domain analysis within the Anti-Spyware profile.
DNS Security cloud-delivered service utilizes predictive analytics and machine learning models in the cloud to analyze patterns, domain generation algorithms (DGAs), and low-frequency DNS tunneling behavior that static signatures miss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforce strict TCP proxying for all DNS traffic passing through the firewall dataplane.
Why it's wrong here
Standard DNS traffic operates over UDP port 53, and forcing TCP proxying does not provide predictive threat analytics.
- ✗
Write a custom URL Filtering category blocking all domains with more than three subdomains.
Why it's wrong here
URL Filtering categorizes web browsing traffic and does not analyze raw DNS packet payloads or tunneling protocols effectively.
- ✓
Enable DNS Security with advanced machine learning-based categorization and predictive domain analysis within the Anti-Spyware profile.
Why this is correct
Machine learning models in DNS Security detect subtle, low-frequency DGA and tunneling patterns that evade standard signature detection.
- ✗
Configure a custom Threat Prevention vulnerability signature with an extremely low threshold for UDP port 53 packet counts.
Why it's wrong here
Low-frequency DNS tunneling specifically evades volume-based thresholds by design.
Visual reference
About these practice questions
Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.