nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #322

Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?

The correct answer is B. imap. According to the screenshot, only imap, pop3 and smtp have a default (alert) action, which generates an alert for each application traffic flow. The alert is saved in the threat log. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-profiles

Threat Prevention

Question

Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?

Exhibit

NETSEC-ANALYST question #322 exhibit

Options

  • Asmb
  • Bimap
  • Cftp
  • Dhttp2

How the community answered

(44 responses)
  • A
    16% (7)
  • B
    75% (33)
  • C
    5% (2)
  • D
    5% (2)

Explanation

According to the screenshot, only imap, pop3 and smtp have a default (alert) action, which generates an alert for each application traffic flow. The alert is saved in the threat log. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-profiles

Topics

#protocol decoders#WildFire ML#Threat logs#traffic inspection

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice