nerdexam
Palo_Alto_Networks

PCNSE · Question #544

Cortex XDR notifies an administrator about grayware on the endpoints. There are no entries about grayware in any of the logs of the corresponding firewall. Which setting can the administrator…

The correct answer is C. in WildFire General Settings, select "Report Grayware Files". To enable the firewall to log grayware verdicts detected by WildFire, the specific option to report grayware files must be activated within the WildFire General Settings.

Submitted by jian89· Apr 18, 2026Deploy and Configure

Question

Cortex XDR notifies an administrator about grayware on the endpoints. There are no entries about grayware in any of the logs of the corresponding firewall. Which setting can the administrator configure on the firewall to log grayware verdicts?

Options

  • Awithin the log forwarding profile attached to the Security policy rule
  • Bwithin the log settings option in the Device tab
  • Cin WildFire General Settings, select "Report Grayware Files"
  • Din Threat General Settings, select "Report Grayware Files"

How the community answered

(60 responses)
  • A
    7% (4)
  • B
    13% (8)
  • C
    77% (46)
  • D
    3% (2)

Why each option

To enable the firewall to log grayware verdicts detected by WildFire, the specific option to report grayware files must be activated within the WildFire General Settings.

Awithin the log forwarding profile attached to the Security policy rule

A log forwarding profile determines *where* logs are sent (e.g., syslog server, Panorama) but does not control *what specific content* (like grayware verdicts) is generated and logged by the firewall itself.

Bwithin the log settings option in the Device tab

The 'log settings' option in the Device tab typically configures general logging preferences, such as log quota or database settings, but not specific content like grayware verdicts which are handled by dedicated security services.

Cin WildFire General Settings, select "Report Grayware Files"Correct

The 'Report Grayware Files' option (or similar setting to enable grayware analysis and reporting) within the WildFire General Settings (typically under Device > WildFire > General Settings) explicitly enables the firewall to send grayware samples to WildFire for analysis and to generate logs pertaining to grayware verdicts. This setting is crucial for the firewall to identify and log grayware detections.

Din Threat General Settings, select "Report Grayware Files"

'Threat General Settings' primarily relate to general threat prevention features like antivirus, anti-spyware, and vulnerability protection, not specifically the logging of grayware analysis provided by the WildFire cloud service.

Concept tested: WildFire Grayware Logging Configuration

Source: https://docs.paloaltonetworks.com/wildfire/10-2/wildfire-admin/wildfire-overview/wildfire-grayware-detection.html

Topics

#WildFire#Grayware#Logging#Firewall Configuration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice