6.5 Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use

Information

Enable passive DNS monitoring within all anti-spyware profiles in use.
Rationale:
Enabling passive DNS monitoring improves PANs threat prevention and threat intelligence capabilities. This is performed without source information delivered to PAN to ensure sensitive DNS information of the organization is not compromised.

Solution

Navigate to Device > Setup > Telemetry. Set Passive DNS Monitoring to enabled
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/2104

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-3, 800-53|SI-3, 800-53|SI-4, CSCv6|8.5, CSCv6|8.6, CSCv7|8, CSCv7|8.7

Plugin: Palo_Alto

Control ID: 8c976682aca8c4745af170994ed10e6ea1780481a6ae41b0d9b63706af41223a