nerdexam
Palo_Alto_Networks

PCNSE · Question #666

Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?

The correct answer is B. Yes, because the action is set to "allow? In a WildFire submission log, the 'action' field reflects what the firewall actually did with the session at the time of the traffic event. An action of 'allow' means the firewall permitted the session and the user received the requested content. WildFire analysis (including…

Submitted by anjalisingh· Apr 18, 2026Operate

Question

Given the following snippet of a WildFire submission log, did the end-user get access to the requested information and why or why not?

Exhibit

PCNSE question #666 exhibit

Options

  • ANo, because this is an example from a defeated phishing attack.
  • BYes, because the action is set to "allow?
  • CNo, because the severity is "high" and the verdict "malicious?
  • DYes, because the action is set to "alert?

How the community answered

(58 responses)
  • A
    5% (3)
  • B
    91% (53)
  • C
    2% (1)
  • D
    2% (1)

Explanation

In a WildFire submission log, the 'action' field reflects what the firewall actually did with the session at the time of the traffic event. An action of 'allow' means the firewall permitted the session and the user received the requested content. WildFire analysis (including verdict and severity) occurs asynchronously - the file is submitted to WildFire for analysis, but the traffic is already allowed or blocked based on the action taken at the time. If the action shows 'allow', the user got access regardless of the severity or verdict returned later. The 'alert' action (choice D) would also allow traffic but generate an alert; however, the question states the action is 'allow', making B the correct and precise answer.

Topics

#WildFire#Log Analysis#Security Actions#Threat Prevention

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice