Exam PCNSA All QuestionsBrowse all questions from this exam
Question 190

You receive notification about a new malware that infects hosts. An infection results in the infected host attempting to contact command-and-control server.

Which Security Profile, when applied to outbound Security policy rules, detects and prevents this threat from establishing a command-and-control connection?

    Correct Answer: A

    The Anti-Spyware Profile is designed to detect and prevent communications between infected hosts and command-and-control servers. This profile specifically targets and blocks spyware activities, including attempts by compromised hosts to contact external command-and-control (C2) servers, which is the issue described in the question.

Discussion
HyayOption: A

"Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers"

ZeruzOption: A

A: Anti-spyware does C2 traffic blocking.

NajmmmOption: A

"Anti-Spyware profiles blocks spyware on compromised hosts from trying to phone-home or beacon out to external command-and-control (C2) servers"

guuillauumeOption: C

why not antivirus ?

[Removed]Option: A

correct

Alex48694Option: A

Anti-Spyware Profile

TheMaster01Option: A

A is correct