PSE-STRATA · Question #171
WildFire can discover zero-day malware in which three types of traffic? (Choose three)
The correct answer is A. SMTP B. HTTPS C. FTP. WildFire, Palo Alto Networks' cloud-based malware analysis service, inspects files transmitted over SMTP (email attachments), HTTPS (encrypted web traffic), and FTP (file transfers) - the three protocols most commonly exploited to deliver malicious payloads to endpoints. These…
Question
WildFire can discover zero-day malware in which three types of traffic? (Choose three)
Options
- ASMTP
- BHTTPS
- CFTP
- DDNS
- ETFTP
How the community answered
(19 responses)- A79% (15)
- D16% (3)
- E5% (1)
Explanation
WildFire, Palo Alto Networks' cloud-based malware analysis service, inspects files transmitted over SMTP (email attachments), HTTPS (encrypted web traffic), and FTP (file transfers) - the three protocols most commonly exploited to deliver malicious payloads to endpoints. These are high-value attack vectors where threat actors embed zero-day malware in attachments, downloads, and file uploads.
DNS (D) is a name resolution protocol that carries query/response data, not file payloads - WildFire doesn't perform sandbox analysis on DNS traffic (though other PAN-OS features like DNS Security handle DNS-based threats). TFTP (E) is a lightweight, rarely monitored transfer protocol not included in WildFire's supported traffic types for malware analysis.
Memory tip: Think of the three as the "email, web, file" trio - SMTP = email, HTTPS = web, FTP = file server. If you can attach or download a file through it in everyday business use, WildFire likely covers it. TFTP and DNS are edge-case or infrastructure protocols that don't fit that pattern.
Topics
Community Discussion
No community discussion yet for this question.