Palo Alto Networks Certified Network Security Administrator (PCNSA) — Question 403

An administrator needs to add capability to perform real time signature lookups to block or sinkhole all known malware domains.
Which type of single, unified engine will get this result?

Answer options

Correct answer: A

Explanation

The correct answer is A, Content ID, as it is specifically designed to perform real-time signature lookups for identifying and blocking known malware domains. The other options, App-ID, Security Processing Engine, and User-ID, do not provide the same functionality related to signature lookups and malware domain management.