Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCCET Topic 8 Question 36 Discussion

Actual exam question for Palo Alto Networks's PCCET exam
Question #: 36
Topic #: 8
[All PCCET Questions]

Under which category does an application that is approved by the IT department, such as Office 365, fall?

Show Suggested Answer Hide Answer
Suggested Answer: D

Attack communication traffic is usually hidden with various techniques and

tools, including:

Encryption with SSL, SSH (Secure Shell), or some other custom or proprietary encryption

Circumvention via proxies, remote access tools, or tunneling. In some instances, use of

cellular networks enables complete circumvention of the target network for attack C2 traffic.

Port evasion using network anonymizers or port hopping to traverse over any available open

ports

Fast Flux (or Dynamic DNS) to proxy through multiple infected endpoints or multiple,

ever-changing C2 servers to reroute traffic and make determination of the true destination

or attack source difficult

DNS tunneling is used for C2 communications and data infiltration


Contribute your Thoughts:

Aracelis
3 days ago
I'm not sure, but I think it could also be C) tolerated, depending on the organization's policies.
upvoted 0 times
...
Elinore
4 days ago
I'm gonna go with C) tolerated. The IT department may not be thrilled about it, but they're probably too busy dealing with the 'unsanctioned' apps to really care about Office 365.
upvoted 0 times
...
Cordelia
5 days ago
Haha, I bet the IT guys wish they could just 'tolerate' us using Office 365. As if they have a choice, it's a sanctioned app for sure!
upvoted 0 times
...
Jamey
6 days ago
Definitely D) sanctioned. Office 365 is a productivity suite approved by the IT department, not some shady app we're hiding from them.
upvoted 0 times
...
Marnie
9 days ago
I agree with Billy, because if it's approved by the IT department, it must be sanctioned.
upvoted 0 times
...
Billy
17 days ago
I think the answer is D) sanctioned.
upvoted 0 times
...

Save Cancel