nerdexam
Palo_Alto_Networks

PCNSA · Question #322

Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?

The correct answer is B. imap. This question references a screenshot of an Anti-Spyware or threat profile configuration showing protocol decoder actions. The IMAP decoder is configured with an action of 'allow' (permit traffic) while also having machine-learning (ML) inline detection enabled and logging…

Submitted by amina.ke· Apr 18, 2026Securing Traffic

Question

Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?

Exhibit

PCNSA question #322 exhibit

Options

  • Asmb
  • Bimap
  • Cftp
  • Dhttp2

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    80% (32)
  • C
    13% (5)
  • D
    5% (2)

Explanation

This question references a screenshot of an Anti-Spyware or threat profile configuration showing protocol decoder actions. The IMAP decoder is configured with an action of 'allow' (permit traffic) while also having machine-learning (ML) inline detection enabled and logging turned on (creating a Threat log entry). The other decoders (SMB, FTP, HTTP2) have different actions configured - such as block or reset - that would not permit the traffic. The combination of ML detection + Threat logging + allow action uniquely identifies IMAP in the referenced screenshot.

Topics

#Threat Prevention#Application Identification#Logging#Machine Learning Security

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice