nerdexam
Palo_Alto_Networks

PCDRA · Question #105

A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?

The correct answer is B. It is false positive. In detection terminology, the ground truth is what the file actually is. The question states to assume WildFire is accurate, meaning the file is genuinely Benign (ground truth = negative/safe). However, the Local Analysis module classified it as Malware (a positive detection)…

Submitted by satoshi_tk· Apr 18, 2026Detection and Alert Management

Question

A file is identified as malware by the Local Analysis module whereas WildFire verdict is Benign, Assuming WildFire is accurate. Which statement is correct for the incident?

Options

  • AIt is true positive.
  • BIt is false positive.
  • CIt is a false negative.
  • DIt is true negative.

How the community answered

(60 responses)
  • A
    5% (3)
  • B
    83% (50)
  • C
    10% (6)
  • D
    2% (1)

Explanation

In detection terminology, the ground truth is what the file actually is. The question states to assume WildFire is accurate, meaning the file is genuinely Benign (ground truth = negative/safe). However, the Local Analysis module classified it as Malware (a positive detection). Since the system raised an alert (positive) on something that is actually safe (negative), this is a False Positive. A True Positive would be a correct detection of actual malware. A False Negative would be failing to detect actual malware. A True Negative would be correctly identifying a benign file as benign. In this case: detected as malicious but actually benign = False Positive (B).

Topics

#False Positive#Alert Analysis#WildFire#Local Analysis

Community Discussion

No community discussion yet for this question.

Full PCDRA Practice