Palo Alto Networks Certified Network Security Administrator (PCNSA) — Question 229
An administrator configured a Security policy rule with an Antivirus Security profile. The administrator did not change the action for the profile.
If a virus gets detected, how will the firewall handle the traffic?
Answer options
- A. It allows the traffic but generates an entry in the Threat logs.
- B. It drops the traffic because the profile was not set to explicitly allow the traffic.
- C. It allows the traffic because the profile was not set the explicitly deny the traffic.
- D. It uses the default action assigned to the virus signature.
Correct answer: D
Explanation
The correct answer is D because when no explicit action is defined in the Antivirus Security profile, the firewall defaults to the action assigned to the virus signature. Options A, B, and C are incorrect as they misinterpret the behavior of the firewall when the profile's action is not modified.