Palo Alto Networks Network Security Analyst (NetSec-Analyst) Exam Materials-Question 13 Discussion
Comment Image Comment Image Comment Image

A company requires that all file transfers only over HTTP (tcp/80 and tcp/8080) to SaaS storage must be inspected for data exfiltration. Traffic to encrypted HTTPS SaaS storage cannot be inspected based on the company decryption restrictions. When using a security profile group, which Security policy configuration meets this requirement? (Choose one answer)

  • A. One with data filtering and the service set to tcp/80 and tcp/8080, then verify block threshold is set to “1” to stop exfiltration.
  • B. One with URL filtering and file blocking to block all file uploads to the URL category online-storage-and-backup, then set the service to tcp/80 and tcp/8080.
  • C. One with data filtering to inspect all HTTP traffic on the web-browsing application using application-default for the service.
  • D. One with data filtering and an application filter that matches “file-sharing” applications, then set the service to tcp/80 and tcp/8080.
Correct Answer: A

Brave-Dump Clients Votes

D 100%

Comments



Yuriko Septyadi 2026-06-17 12:09:46

Selected Answers: D


it should D