PCNSE · Question #869
During a routine security audit, the risk and compliance team notices a series of WildFire logs that contain a "malicious" verdict and the action "allow." Upon further inspection, the team confirms th
The correct answer is B. Configure the appropriate actions in the Antivirus security profile. WildFire with an active subscription delivers updated malware signatures to firewalls within minutes of identifying a new threat - not just once per day. The reason threats show 'malicious' verdict but an 'allow' action is that the action is controlled by the Antivirus security p
Question
During a routine security audit, the risk and compliance team notices a series of WildFire logs that contain a "malicious" verdict and the action "allow." Upon further inspection, the team confirms that these same threats are automatically blocked by the firewalls the following day. How can the existing configuration be adjusted to ensure that new threats are blocked within minutes instead of having to wait until the following day?
Options
- AConfirm the file types and direction are configured correctly in the WildFire analysis profile
- BConfigure the appropriate actions in the Antivirus security profile
- CConfigure the appropriate actions in the File Blocking profile
- DConfirm the file size limits are configured correctly in the WildFire general settings
How the community answered
(41 responses)- A17% (7)
- B71% (29)
- C5% (2)
- D7% (3)
Explanation
WildFire with an active subscription delivers updated malware signatures to firewalls within minutes of identifying a new threat - not just once per day. The reason threats show 'malicious' verdict but an 'allow' action is that the action is controlled by the Antivirus security profile, not WildFire itself. WildFire only performs analysis and delivers signatures; it is the Antivirus security profile that defines what action (allow, alert, block, drop) to take on files matching WildFire verdicts. By configuring the appropriate block actions in the Antivirus security profile (B) for WildFire-detected threats, the firewall will enforce blocking within minutes of a signature update, rather than waiting for the next daily content update cycle.
Topics
Community Discussion
No community discussion yet for this question.