PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 121


An administrator just submitted a newly found piece of spyware for WildFire analysis. The spyware passively monitors behavior without the user's knowledge.

What is the expected verdict from WildFire?

Show Answer
Correct Answer: B

Grayware is the correct verdict when dealing with spyware in WildFire analysis. Although spyware passively monitors user behavior, it does not pose a direct security threat but might display otherwise obtrusive behavior. WildFire categorizes files that include adware, spyware, and Browser Helper Objects (BHOs) under the grayware category.

Discussion

17 comments
Sign in to comment
bartberniniOption: D
Feb 4, 2022

D. Grayware. Although this *is* an example of spyware, that is not one of the four possible WildFire verdicts. From Palo Alto, "Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs)." https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/wildfire-concepts/verdicts.html

eyelasers1
Feb 22, 2022

Don't you mean B. Grayware?

Chris71Mach1
Jan 12, 2023

THIS is the explanation we all need. Thank you.

TAKUM1yOption: B
Oct 7, 2022

https://docs.paloaltonetworks.com/wildfire/10-0/wildfire-admin/wildfire-overview/wildfire-concepts/verdicts

gully300Option: B
Jan 15, 2023

bartbernini Highly Voted 11 months, 2 weeks ago <correction>B</correction> Grayware. Although this *is* an example of spyware, that is not one of the four possible WildFire verdicts. From Palo Alto, "Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs)." https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/wildfire-overview/wildfire-concepts/verdicts.html

UFanatOption: B
Jun 12, 2022

Grayware—The sample does not pose a direct security threat, but might display otherwise obtrusive behavior. Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs).

weze1336Option: B
May 29, 2024

Answer is GRAYWARE. The question is specifically asking for "VERDICT". There is NO verdict called "SPYWARE". "Spyware" is included within the "Grayware" Verdict. See Below. Benign Indicates that the entry received a WildFire analysis verdict of benign. Files categorized as benign are safe and do not exhibit malicious behavior. Grayware Indicates that the entry received a WildFire analysis verdict of grayware. Files categorized as grayware do not pose a direct security threat but might display otherwise obtrusive behavior. Grayware can include adware, spyware, and Browser Helper Objects (BHOs). Phishing Indicates that WildFire assigned a link and analysis verdict of phishing. A phishing verdict indicates that the site to which the link directs users displayed credential phishing activity. Malicious Indicates that the entry received a WildFire analysis verdict of malicious. Samples categorized as malicious can pose a security threat. Malware can include viruses, C2 (command-and-control), worms, Trojans, Remote Access Tools (RATs), rootkits, and botnets. For samples that are identified as malware, the WildFire cloud generates and distributes a signature to prevent against future exposure.

awtsuritacunaOption: B
Dec 4, 2022

Answer is B Grayware —The sample does not pose a direct security threat, but might display otherwise obtrusive behavior. Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs).

Sammy3637Option: B
Dec 10, 2023

Spyware is a type of Grayware

MarshpillowzOption: B
Jan 24, 2024

Apologies correct answer is B

MarshpillowzOption: D
Jan 24, 2024

Answer is D

LoloshikovichevOption: B
Apr 29, 2024

There is no "Spyware" verdict.

123XYZTOption: D
May 10, 2024

D is correct, the possible verdicts from Palo Alto are Benign, Graygare, Phishing and Malicious.

123XYZTOption: B
May 10, 2024

I meant B is correct

0d2fdfaOption: B
May 14, 2024

Verdict categories are Benign, Grayware , Phishing, Malicious https://docs.paloaltonetworks.com/advanced-wildfire/administration/advanced-wildfire-overview/advanced-wildfire-concepts/verdicts

weze1336Option: B
May 29, 2024

answer B Grayware

hcirOption: B
Jun 16, 2024

malware and spyware verdicts do not exist in wildfire: and it is not phishing, so the only left is grayware. Answer B

apiloranOption: B
Jul 12, 2024

Grayware —The sample does not pose a direct security threat, but might display otherwise obtrusive behavior. Grayware typically includes adware, spyware, and Browser Helper Objects (BHOs).

apiloranOption: B
Jul 17, 2024

B. Grayware