exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 585 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 585
Topic #: 1
[All PCNSE Questions]

Following a review of firewall logs for traffic generated by malicious activity, how can an administrator confirm that WildFire has identified a virus?

  • A. By navigating to Monitor > Logs > Traffic, applying filter “(subtype eq virus)”
  • B. By navigating to Monitor > Logs > Threat, applying filter “(subtype eq virus)”
  • C. By navigating to Monitor > Logs > Threat, applying filter “(subtype eq wildfire-virus)”
  • D. By navigating to Monitor > Logs > WildFire Submissions, applying filter “(subtype eq wildfire-virus)”
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nebulanerd
10 months, 2 weeks ago
Selected Answer: C
wildfire-virus is a subtype used for wildfire signatures delivered using wildfire signature database, to differentiate from regular anti-virus signatures. In short, AV signatures are identified using subtype virus. Wildfire signatures are identified using subtype wildfire-virus.
upvoted 1 times
...
jaypogi16
1 year, 1 month ago
Selected Answer: C
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields
upvoted 3 times
...
poiuytr
1 year, 1 month ago
Selected Answer: C
"wildfire-virus is a subtype used for wildfire signatures delivered using wildfire signature database, to differentiate from regular anti-virus signatures. In short, AV signatures are identified using subtype virus. Wildfire signatures are identified using subtype wildfire-virus."
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago