nerdexam
Palo_Alto_Networks

PCNSE · Question #869

During a routine security audit, the risk and compliance team notices a series of WildFire logs that contain a "malicious" verdict and the action "allow." Upon further inspection, the team confirms th

The correct answer is B. Configure the appropriate actions in the Antivirus security profile. WildFire with an active subscription delivers updated malware signatures to firewalls within minutes of identifying a new threat - not just once per day. The reason threats show 'malicious' verdict but an 'allow' action is that the action is controlled by the Antivirus security p

Submitted by haruto_sh· Apr 18, 2026Operate

Question

During a routine security audit, the risk and compliance team notices a series of WildFire logs that contain a "malicious" verdict and the action "allow." Upon further inspection, the team confirms that these same threats are automatically blocked by the firewalls the following day. How can the existing configuration be adjusted to ensure that new threats are blocked within minutes instead of having to wait until the following day?

Options

  • AConfirm the file types and direction are configured correctly in the WildFire analysis profile
  • BConfigure the appropriate actions in the Antivirus security profile
  • CConfigure the appropriate actions in the File Blocking profile
  • DConfirm the file size limits are configured correctly in the WildFire general settings

How the community answered

(41 responses)
  • A
    17% (7)
  • B
    71% (29)
  • C
    5% (2)
  • D
    7% (3)

Explanation

WildFire with an active subscription delivers updated malware signatures to firewalls within minutes of identifying a new threat - not just once per day. The reason threats show 'malicious' verdict but an 'allow' action is that the action is controlled by the Antivirus security profile, not WildFire itself. WildFire only performs analysis and delivers signatures; it is the Antivirus security profile that defines what action (allow, alert, block, drop) to take on files matching WildFire verdicts. By configuring the appropriate block actions in the Antivirus security profile (B) for WildFire-detected threats, the firewall will enforce blocking within minutes of a signature update, rather than waiting for the next daily content update cycle.

Topics

#WildFire#Antivirus Profile#Threat Prevention#Security Profiles

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice