Answer is B. WildFire Virus is a sub-type of the AV signatures.
Data Filtering allowed the flash file but it was blocked by the AV signatures as a known WildFire Virus.
it is B. Type Wildfire tells what is the cached verdict (malicious in this case with an action of block). Type wildfire-virus tells what actually the antivirus engine did to the traffic
URL profile action alert.
File Profile action alert.
AV and Wildfire action Reset-both
Policy Action Allow.
Content Inspection overrides the policy action meaning the answer is B.
Based on the WildFire submission log provided, let's break down the sequence:
TYPE: end - The action is allow.
TYPE: wildfire - The action is block with a verdict: malicious.
TYPE: wildfire-virus - The action is reset-both.
TYPE: virus - The action is reset-both.
TYPE: file - The action is alert.
TYPE: url - The action is alert.
Key points:
The log shows multiple actions taken on the file.
The wildfire-virus entry has the action reset-both, which means the connection was reset, preventing the download from completing.
Although the initial end type has an action of allow, subsequent security measures like the reset-both action for the wildfire-virus and virus types indicate that the download was interrupted.
Given this, the correct answer is:
B. No, because the action for the wildfire-virus is "reset-both."
(A) maybe but I could be wrong. "did the end user successfully downloaded file?" - technically YES.
"It takes about 10 to 15 minutes to download the signature by WF dynamic update, no signature, no blocking" - per screenshot, primarily action is set to "allow". If no other means was used for mitigating this, then yes, the file was downloaded then probably mitigated later after WF sends its update
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
SRowe
Highly Voted 11 months, 2 weeks agohcir
Highly Voted 9 months, 3 weeks agoJackyCCK
Most Recent 3 days, 13 hours agokewokil120
2 months, 1 week agojuankparra90
5 months agoMoadil_001
5 months, 2 weeks agothelittleyellowbirdie
6 months, 1 week ago[Removed]
8 months agobetko
8 months, 1 week agoThunnu
1 year agojayessarre
1 year agoMarshpillowz
1 year agoMerlin0o
1 year agoMerlin0o
1 year agofranko_72
1 year, 1 month agoomgt2k2
1 year, 1 month agofranko_72
1 year, 2 months agojoquin0020
1 year, 2 months ago