フリー問題

Palo Alto Networks Certified Network Security Analyst のフリー問題 10 / 20 問目

問題文

An analyst has to explain to an auditor why threat inspection is configured on rules that permit traffic and not on the rules that deny it. What is the reason?

選択肢

  1. Denied sessions are inspected by a separate profile type that is attached to the zone instead of the rule, and that is why the deny rules in the rulebase do not carry any profile of their own.
  2. Deny rules cannot reference any object so a profile has to be attached at the zone level if the denied sessions are to be recorded at all in the threat log.
  3. Inspection of the content happens on sessions that are allowed to proceed, so a rule that denies the session has nothing left to inspect.
  4. Inspection is disabled on deny rules to save resources so that the analyst turns it on again only when a denied session has to be studied in detail.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。