Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 559 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 559
Topic #: 1
[All PCNSE Questions]

Given the following snippet of a WildFire submission log, did the end user successfully download a file?

  • A. Yes, because the final action is set to "allow."
  • B. No, because the action for the wildfire-virus is "reset-both."
  • C. No, because the URL generated an alert.
  • D. Yes, because both the web-browsing application and the flash file have the "alert" action.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
hcir
2 weeks, 1 day ago
it is B. Type Wildfire tells what is the cached verdict (malicious in this case with an action of block). Type wildfire-virus tells what actually the antivirus engine did to the traffic
upvoted 1 times
...
SRowe
2 months, 1 week ago
Selected Answer: B
Answer is B. WildFire Virus is a sub-type of the AV signatures. Data Filtering allowed the flash file but it was blocked by the AV signatures as a known WildFire Virus.
upvoted 3 times
...
Thunnu
2 months, 4 weeks ago
What's the correct answer?
upvoted 1 times
...
jayessarre
3 months, 1 week ago
(A) maybe but I could be wrong. "did the end user successfully downloaded file?" - technically YES. "It takes about 10 to 15 minutes to download the signature by WF dynamic update, no signature, no blocking" - per screenshot, primarily action is set to "allow". If no other means was used for mitigating this, then yes, the file was downloaded then probably mitigated later after WF sends its update
upvoted 1 times
...
Marshpillowz
3 months, 1 week ago
Selected Answer: D
I think D
upvoted 1 times
...
Merlin0o
3 months, 3 weeks ago
Selected Answer: D
I Think the below Article could be of help: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UshCAE&lang=en_US%E2%80%A9
upvoted 1 times
Merlin0o
3 months, 3 weeks ago
Also see: https://www.youtube.com/watch?v=xK8cRFCVlrQ&list=PLD6FJ8WNiIqUnbuVfcoa2fXh_rcIgcIwX&index=3
upvoted 1 times
...
...
franko_72
4 months, 1 week ago
Have to be D surely? I cannot seem to find a definitive answer on Palo Alto!
upvoted 1 times
...
omgt2k2
4 months, 2 weeks ago
Selected Answer: A
i had this one in December 2023. i think it is A but i am not shure and whould like to know.
upvoted 1 times
...
franko_72
5 months ago
This was on the exam September 2023, I would suggest knowing this one.
upvoted 2 times
...
joquin0020
5 months, 2 weeks ago
Selected Answer: D
OPtion D, The first file was downloaded, the wildfire verdict came later to block it, later.
upvoted 1 times
...
skullomania
5 months, 2 weeks ago
Selected Answer: B
Answer is B. Wildfire-virus is a subtype used for wildfire signatures delivered using wildfire signature database, to differentiate from regular anti-virus signatures. In short, AV signatures are identified using subtype virus. Wildfire signatures are identified using subtype wildfire-virus. Source: https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/td-p/63337
upvoted 2 times
...
regnojispi
6 months, 2 weeks ago
Selected Answer: D
I think D because WildFire does not stop the file from being downloaded
upvoted 3 times
...
dgonz
7 months, 4 weeks ago
Selected Answer: B
i think it was not allowed
upvoted 1 times
...
Merlin0o
7 months, 4 weeks ago
Selected Answer: D
I have guessed D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...