PCNSE · Question #761
Following a review of firewall logs for traffic generated by malicious activity, how can an administrator confirm that WildFire has identified a virus?
The correct answer is C. By navigating to Monitor > Logs > Threat, applying filter "(subtype eq wildfire-virus)". To confirm that WildFire has identified a virus, an administrator should review the Threat logs and apply a filter for (subtype eq wildfire-virus).
Question
Following a review of firewall logs for traffic generated by malicious activity, how can an administrator confirm that WildFire has identified a virus?
Options
- ABy navigating to Monitor > Logs > Traffic, applying filter "(subtype eq virus)"
- BBy navigating to Monitor > Logs > Threat, applying filter "(subtype eq virus)"
- CBy navigating to Monitor > Logs > Threat, applying filter "(subtype eq wildfire-virus)"
- DBy navigating to Monitor > Logs > WildFire Submissions, applying filter "(subtype eq wildfire-
How the community answered
(31 responses)- B3% (1)
- C90% (28)
- D6% (2)
Why each option
To confirm that WildFire has identified a virus, an administrator should review the `Threat logs` and apply a filter for `(subtype eq wildfire-virus)`.
`Traffic logs` show general connection information and would not specifically confirm a WildFire virus detection with the provided filter.
While `Threat logs` are the correct place, the filter `(subtype eq virus)` is less precise than `(subtype eq wildfire-virus)` for confirming a WildFire-specific detection.
WildFire detections of malicious files, specifically viruses, are logged in the `Threat logs` with the specific `subtype` of `wildfire-virus`. Filtering the Threat logs for this subtype provides a direct and accurate method to confirm WildFire's identification of a virus.
`WildFire Submissions logs` show information about files submitted to WildFire, not the actual detection results or confirmations of a virus; those are found in Threat logs.
Concept tested: WildFire virus detection in logs
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/wildfire/wildfire-log-fields
Topics
Community Discussion
No community discussion yet for this question.