Exam PCNSE All QuestionsBrowse all questions from this exam
Question 266

Cortex XDR notifies an administrator about grayware on the endpoints. There are no entries about grayware in any of the logs of the corresponding firewall. Which setting can the administrator configure on the firewall to log grayware verdicts?

    Correct Answer: C

    To log grayware verdicts on the firewall, the administrator should configure the setting in WildFire General Settings to select 'Report Grayware Files'. This setting ensures that files analyzed by WildFire and determined to be grayware are logged appropriately.

Discussion
nose999Option: C

https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/monitor-wildfire-activity/use-the-firewall-to-monitor-malware/configure-wildfire-submissions-log-settings/enable-logging-for-benign-and-grayware-samples

confusionOption: C

Definitely C, otherwise they won't be logged.

TAKUM1yOption: C

https://docs.paloaltonetworks.com/wildfire/10-2/wildfire-admin/monitor-wildfire-activity/use-the-firewall-to-monitor-malware/configure-wildfire-submissions-log-settings/enable-logging-for-benign-and-grayware-samples

123XYZTOption: D

D Log Forwarding Profile Match List Log Type: wildfire Filter verdict eq grayware

WhizdhumOption: C

Answer is C. When this option is enabled (disabled by default), files analyzed by WildFire that are determined to be grayware will appear in the Monitor > WildFire Submissions log.

SarbiOption: C

Looks c is more accurate.As first we have to select report grayware . The only it will logs

KuronekosamaOption: D

C turn on verdicts. D turns on the logging. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTqCAK

Kuronekosama

Nevermind. Answer is C. It turns on logging to wildfire submissions upon report Gray ware Files.

1f2c588Option: C

answer is C: configure report graware files on the device, setup, wildfire, general setings

Sammy3637Option: C

Under Wildfire settings -->Report Grayware