exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 300 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 300
Topic #: 1
[All PCNSE Questions]

Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?

  • A. No, because WildFire classified the severity as ג€highג€
  • B. Yes, because the action is set to ג€allowג€
  • C. No, because WildFire categorized a file with the verdict ג€maliciousג€
  • D. Yes, because the action is set to ג€alertג€
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PaloGuy
6 days, 4 hours ago
Selected Answer: B
A bit of a tricky one because the oldest is at the bottom and newest at the top the question doesn't specify whether the first or last submitted was allowed or why the first because of an "alert" Last because of an "allow" It would appear that the Action on the rule has been changed from alert to allow - it's the same rule for all of the submissions, same UUID - It can't have two actions so it's been changed since the first two submissions If this was current it would be "allow" That's my logic for answer B anyway
upvoted 1 times
...
Whizdhum
8 months, 1 week ago
Selected Answer: B
Answer is B. The submission logs include details about a given sample, including the following information: 1) The Verdict column indicates whether the sample is benign, malicious, phishing, or grayware. 2) The Action column indicates whether the firewall allowed or blocked the sample. 3) The Severity column indicates how much of a threat a sample poses to an organization using the following values: critical, high, medium, low, and informational. The values for the severity levels are determined by a combination of verdict and action values. For example, High is a result of a malicious sample with the action set to allow.
upvoted 2 times
...
Sammy3637
8 months, 2 weeks ago
Selected Answer: B
Also going with B , below link somewhat explains it https://live.paloaltonetworks.com/t5/threat-vulnerability-discussions/wildfire-not-blocking-file-with-malicious-verdict/td-p/203905
upvoted 1 times
...
franko_72
8 months, 2 weeks ago
On the exam July 2023
upvoted 3 times
...
Eiffelsturm
8 months, 3 weeks ago
Selected Answer: B
Tricky. I think it's B because it's about the WildFire Submissions log. There is no column for "Type" file.
upvoted 1 times
...
pavtoor
11 months, 3 weeks ago
Selected Answer: B
The answer is B
upvoted 1 times
...
Betty2022
1 year ago
Selected Answer: B
B) The Verdict column indicates whether the sample is benign, malicious, phishing, or grayware. The Action column indicates whether the firewall allowed or blocked the sample.
upvoted 1 times
...
kewokil120
1 year, 4 months ago
Selected Answer: B
B is the answer
upvoted 3 times
...
duckduckgooo
1 year, 4 months ago
Going to go with B https://live.paloaltonetworks.com/t5/general-topics/wildfire-submission-entries-with-severity-high-showing-action/td-p/143516
upvoted 4 times
...
kewokil120
1 year, 5 months ago
Selected Answer: B
B is the answer
upvoted 1 times
...
daytonadave2011
1 year, 5 months ago
Selected Answer: B
The answer is B. Look at kewokil120's link.
upvoted 2 times
...
kewokil120
1 year, 5 months ago
Selected Answer: B
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UshCAE&lang=en_US%E2%80%A9
upvoted 1 times
...
DenskyDen
1 year, 6 months ago
Selected Answer: C
I presume it is C. because the verdict is still malicious. WildFire Submission [Logs] verdict is "malicious" and traffic is "allowed", while configured action is "blocked" See TAKUM1y link.
upvoted 2 times
...
DenskyDen
1 year, 6 months ago
Selected Answer: C
I presume it is C. because the verdict is still malicious. WildFire Submission [Logs] verdict is "malicious" and traffic is "allowed", while configured action is "blocked" See TAKUM1y link.
upvoted 2 times
...
Carso2316
1 year, 6 months ago
Answer is B. "The Action column indicates whether the firewall allowed or blocked the sample." https://docs.paloaltonetworks.com/advanced-wildfire/administration/monitor-wildfire-activity/view-wildfire-logs-and-analysis-reports#idc0fcf921-6745-4e38-8599-f8d9b5f88c58
upvoted 3 times
sujss
1 year, 3 months ago
The above link clears any doubt with the action "allow".
upvoted 1 times
...
...
GohanF2
1 year, 6 months ago
Answer is B. With the Wildfire subscription you can have Inline Machine Learning for further analysis of the threat samples and the time for getting a verdict of the sample is within the same day but between 10 t 15 min. With no license, you can still get the verdict but within 24 hrs. However, the verdict of Wildfire is independent of the action of the security rule. if it is set to alert or allow, it will allow the traffic even if the verdict is malicious due that is not instant process ( which means in real -time the traffic won't get block ) now , this is a nasty question due that the columns has file and wildfire , for the wildfire rows , we have allow as an action and " allow" doesn't log any of the traffic but alert yes. I'll stick with B
upvoted 3 times
...
Ngalakata
1 year, 6 months ago
you can allow it yet its malicious, so B is correct, once you allow something everything else doesnt matter
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago