PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 559


Given the following snippet of a WildFire submission log, did the end user successfully download a file?

Show Answer
Correct Answer: B

The final action taken in the WildFire submission log is a reset-both action for the wildfire-virus type, indicating that the traffic for this file was reset. Additionally, the wildfire type shows that the file was deemed malicious. These reset actions typically mean that the connection was terminated to prevent the file from being successfully downloaded by the end user. Therefore, the end user did not successfully download the file.

Discussion

16 comments
Sign in to comment
SRoweOption: B
Mar 10, 2024

Answer is B. WildFire Virus is a sub-type of the AV signatures. Data Filtering allowed the flash file but it was blocked by the AV signatures as a known WildFire Virus.

hcirOption: B
May 2, 2024

it is B. Type Wildfire tells what is the cached verdict (malicious in this case with an action of block). Type wildfire-virus tells what actually the antivirus engine did to the traffic

regnojispiOption: D
Nov 1, 2023

I think D because WildFire does not stop the file from being downloaded

Merlin0oOption: D
Sep 21, 2023

I have guessed D

skullomaniaOption: B
Nov 29, 2023

Answer is B. Wildfire-virus is a subtype used for wildfire signatures delivered using wildfire signature database, to differentiate from regular anti-virus signatures. In short, AV signatures are identified using subtype virus. Wildfire signatures are identified using subtype wildfire-virus. Source: https://live.paloaltonetworks.com/t5/general-topics/question-about-threat-logs-type-wildfire-virus/td-p/63337

franko_72
Dec 17, 2023

This was on the exam September 2023, I would suggest knowing this one.

betko
Jun 17, 2024

This question was on exam in June 24.

dgonzOption: B
Sep 22, 2023

i think it was not allowed

joquin0020Option: D
Dec 3, 2023

OPtion D, The first file was downloaded, the wildfire verdict came later to block it, later.

omgt2k2Option: A
Jan 3, 2024

i had this one in December 2023. i think it is A but i am not shure and whould like to know.

franko_72Option: D
Jan 8, 2024

Have to be D surely? I cannot seem to find a definitive answer on Palo Alto!

Merlin0oOption: D
Jan 24, 2024

I Think the below Article could be of help: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UshCAE&lang=en_US%E2%80%A9

Merlin0o
Jan 24, 2024

Also see: https://www.youtube.com/watch?v=xK8cRFCVlrQ&list=PLD6FJ8WNiIqUnbuVfcoa2fXh_rcIgcIwX&index=3

MarshpillowzOption: D
Feb 4, 2024

I think D

jayessarreOption: A
Feb 7, 2024

(A) maybe but I could be wrong. "did the end user successfully downloaded file?" - technically YES. "It takes about 10 to 15 minutes to download the signature by WF dynamic update, no signature, no blocking" - per screenshot, primarily action is set to "allow". If no other means was used for mitigating this, then yes, the file was downloaded then probably mitigated later after WF sends its update

Thunnu
Feb 18, 2024

What's the correct answer?

8f3e6caOption: D
Jun 26, 2024

The initial entry is UL set to allow and then file, also set to allow. It wasn't ID'd as a virus until after the file was downloaded