Exam PCNSE All QuestionsBrowse all questions from this exam
Question 164

How can an administrator configure the firewall to automatically quarantine a device using GlobalProtect?

    Correct Answer: C

    To automatically quarantine a device using GlobalProtect, an administrator can leverage security policies, log forwarding profiles, and log settings. These components allow for the automatic identification and quarantine of potentially compromised devices without manual intervention.

Discussion
mmedOption: C

confirm c https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html

NLTOption: A

After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings.

lol12Option: C

C https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device

Plato22Option: C

Answer is C. Read the wording of the question and then find the answer here: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/globalprotect-features/identification-and-quarantine-of-compromised-devices.html

MarshpillowzOption: C

C is correct

GilmarcioOption: C

Correct "C" https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/host-information/quarantine-devices-using-host-information/automatically-quarantine-a-device.html#idb42b2b82-b253-4be7-9840-1efa49dba3da

prosto_marussiaOption: A

After you identify a device as compromised (for example, if a device has been infected with malware and is performing command and control actions), you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device. You can also automatically quarantine the device using security policies, log forwarding profiles, and log settings. Both A and C kinda work.

Martian89

A is not automatic though (question is about automatic quarantine)

Biz90Option: A

Hi Team, the answer is A based on the KB below it even tells you that: 'you can manually add the device’s Host ID to a quarantine list and configure GlobalProtect to prevent users from connecting to the GlobalProtect gateway from a quarantined device'

Breyarg

i agree but then re-read the question it implies "automatically" which suggests no manual intervention. so only "C" can be correct now.