PCNSE · Question #666
Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?
The correct answer is B. Yes, because the action is set to "allow? In a WildFire submission log, the 'action' field reflects what the firewall actually did with the session at the time of the traffic event. An action of 'allow' means the firewall permitted the session and the user received the requested content. WildFire analysis (including…
Question
Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?
Exhibit
Options
- ANo, because this is an example from a defeated phishing attack.
- BYes, because the action is set to "allow?
- CNo, because the severity is "high" and the verdict "malicious?
- DYes, because the action is set to "alert?
How the community answered
(58 responses)- A5% (3)
- B91% (53)
- C2% (1)
- D2% (1)
Explanation
In a WildFire submission log, the 'action' field reflects what the firewall actually did with the session at the time of the traffic event. An action of 'allow' means the firewall permitted the session and the user received the requested content. WildFire analysis (including verdict and severity) occurs asynchronously - the file is submitted to WildFire for analysis, but the traffic is already allowed or blocked based on the action taken at the time. If the action shows 'allow', the user got access regardless of the severity or verdict returned later. The 'alert' action (choice D) would also allow traffic but generate an alert; however, the question states the action is 'allow', making B the correct and precise answer.
Topics
Community Discussion
No community discussion yet for this question.
