PCNSE · Question #383
Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?
The correct answer is C. Yes, because the action is set to "alert". The correct answer is (C): Yes, because the action is set to 'alert'. In PAN-OS, a WildFire submission log entry with an action of 'alert' means the firewall logged the event and generated an alert, but still allowed the traffic and file transfer to proceed. The file was…
Question
Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?
Exhibit
Options
- AYes, because the action is set to "allow''
- BNo, because WildFire categorized a file with the verdict "malicious"
- CYes, because the action is set to "alert"
- DNo, because WildFire classified the seventy as "high."
How the community answered
(51 responses)- A8% (4)
- B4% (2)
- C86% (44)
- D2% (1)
Explanation
The correct answer is (C): Yes, because the action is set to 'alert'. In PAN-OS, a WildFire submission log entry with an action of 'alert' means the firewall logged the event and generated an alert, but still allowed the traffic and file transfer to proceed. The file was submitted to WildFire for analysis, but the user was not blocked from accessing the content. This is different from an action of 'block' or 'reset-both', which would prevent access. (A) is also technically true in effect but 'alert' is the precise action shown, making C the best answer. (B) is incorrect because a 'malicious' verdict from WildFire only blocks future instances after the verdict is returned - the initial session with an 'alert' action was allowed. (D) is incorrect because severity alone does not determine whether traffic is blocked; the action field does.
Topics
Community Discussion
No community discussion yet for this question.
