exam questions

Exam PCCSA All Questions

View all questions & answers for the PCCSA exam

Exam PCCSA topic 1 question 33 discussion

Actual exam question from Palo Alto Networks's PCCSA
Question #: 33
Topic #: 1
[All PCCSA Questions]

What does Palo Alto Networks Traps do first when an endpoint is asked to run an executable?

  • A. send the executable to WildFire
  • B. run a static analysis
  • C. run a dynamic analysis
  • D. check its execution policy
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Aragorn_360
4 years, 3 months ago
May be D, "When a user attempts to run an executable, the operating system attempts to run the executable as a process. If the process tries to launch any child processes, Traps first evaluates the child process protection policy." https://docs.paloaltonetworks.com/traps/tms/traps-management-service-admin/traps-management-service-overview/traps-evaluation-and-protection-flow.html
upvoted 2 times
...
joxl01
4 years, 4 months ago
Traps is deprecated. Migrated to Cortex XDR, I replied on previous post, not realizing that at some point Palo Alto had a Traps program (I was thinking SNMP Traps). There is no reference to Traps in Palo Alto Cybersecurity Guide anymore, except for SNMP Traps. So, answers will likely change on the test to either Cortex XDR or AutoFocus: "The migration of Traps management service to Cortex XDR is now complete. See Cortex XDR for more information." https://docs.paloaltonetworks.com/traps
upvoted 2 times
...
CiscoSannin
4 years, 9 months ago
D. "When a user or endpoint attempts to open an executable, Traps first verifies that the executable doesn’t violate any policy-based restrictions." Source: Cybersecurity Survival Guide
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago