Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks CloudSec-Pro Exam - Topic 4 Question 2 Discussion

A customer has a requirement to restrict any container from resolving the name www.evil-url.com.How should the administrator configure Prisma Cloud Compute to satisfy this requirement?
D) Set www.evil-url.com as a blocklisted DNS name in the default Container policy and set the effect to prevent.
A) Choose ''copy into rule'' for any Container, set www.evil-url.com as a blocklisted DNS name in the Container policy and set the policy effect to alert.
B) Set www.evil-url.com as a blocklisted DNS name in the default Container runtime policy, and set the effect to block.
C) Choose ''copy into rule'' for any Container, set www.evil-url.com as a blocklisted DNS name, and set the effect to prevent.

Palo Alto Networks CloudSec-Pro Exam - Topic 4 Question 2 Discussion

Actual exam question for Palo Alto Networks's CloudSec-Pro exam
Question #: 2
Topic #: 4
[All CloudSec-Pro Questions]

A customer has a requirement to restrict any container from resolving the name www.evil-url.com.

How should the administrator configure Prisma Cloud Compute to satisfy this requirement?

Show Suggested Answer Hide Answer
Suggested Answer: D

To restrict any container from resolving the name www.evil-url.com, the administrator should set www.evil-url.com as a blocklisted DNS name in the default Container policy and set the effect to prevent. This configuration in Prisma Cloud, or similar CSPM tools, ensures that any attempt to resolve the specified blocklisted DNS name within any container will be prevented, thus enhancing security by proactively blocking potential communication with known malicious domains.

Reference to this feature can be found in the documentation of CSPM tools that offer runtime protection for containers. These tools allow administrators to define security policies that can include DNS-based controls to prevent containers from accessing known malicious or undesirable URLs, thereby preventing potential data exfiltration, malware communication, or other security threats


Contribute your Thoughts:

0/2000 characters
Edison
2 days ago
I prefer D. Preventing access is more secure.
upvoted 0 times
...
German
7 days ago
I think option B is the best. Blocking is crucial.
upvoted 0 times
...
Nadine
12 days ago
Not sure if blocking DNS is enough, what about IPs?
upvoted 0 times
...
Skye
17 days ago
I agree with B, it’s straightforward and effective.
upvoted 0 times
...
Tiera
2 months ago
Wait, can we really block DNS names like that? Sounds risky!
upvoted 0 times
...
Corinne
2 months ago
I think D is better, it uses the default policy for consistency.
upvoted 0 times
...
Art
2 months ago
Option B is the best choice, it blocks the DNS name directly.
upvoted 0 times
...
Paris
3 months ago
Copy into rule? That seems unnecessary for this case.
upvoted 0 times
...
Willodean
3 months ago
I agree with B, blocking is crucial for security!
upvoted 0 times
...
Glendora
3 months ago
Wait, can we really block DNS like that? Sounds risky.
upvoted 0 times
...
Lorrie
3 months ago
I think D is better, it’s more straightforward.
upvoted 0 times
...
Stevie
3 months ago
Option B is the best choice, definitely a block effect.
upvoted 0 times
...
Nan
3 months ago
I'm a bit confused about the difference between "block" and "prevent" in the context of these options. Do they mean the same thing?
upvoted 0 times
...
Stephen
4 months ago
I practiced a similar question where we had to block a URL, and I feel like the default policy is usually the way to go.
upvoted 0 times
...
Lucina
4 months ago
I think option D sounds right because it mentions setting the effect to prevent, which seems more effective than just alerting.
upvoted 0 times
...
Shaquana
4 months ago
I remember something about blocklisting DNS names, but I'm not sure if it should be in the default policy or a specific container rule.
upvoted 0 times
...

Save Cancel