nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #171

WildFire can discover zero-day malware in which three types of traffic? (Choose three)

The correct answer is A. SMTP B. HTTPS C. FTP. WildFire, Palo Alto Networks' cloud-based malware analysis service, inspects files transmitted over SMTP (email attachments), HTTPS (encrypted web traffic), and FTP (file transfers) - the three protocols most commonly exploited to deliver malicious payloads to endpoints. These…

Threat Prevention

Question

WildFire can discover zero-day malware in which three types of traffic? (Choose three)

Options

  • ASMTP
  • BHTTPS
  • CFTP
  • DDNS
  • ETFTP

How the community answered

(19 responses)
  • A
    79% (15)
  • D
    16% (3)
  • E
    5% (1)

Explanation

WildFire, Palo Alto Networks' cloud-based malware analysis service, inspects files transmitted over SMTP (email attachments), HTTPS (encrypted web traffic), and FTP (file transfers) - the three protocols most commonly exploited to deliver malicious payloads to endpoints. These are high-value attack vectors where threat actors embed zero-day malware in attachments, downloads, and file uploads.

DNS (D) is a name resolution protocol that carries query/response data, not file payloads - WildFire doesn't perform sandbox analysis on DNS traffic (though other PAN-OS features like DNS Security handle DNS-based threats). TFTP (E) is a lightweight, rarely monitored transfer protocol not included in WildFire's supported traffic types for malware analysis.

Memory tip: Think of the three as the "email, web, file" trio - SMTP = email, HTTPS = web, FTP = file server. If you can attach or download a file through it in everyday business use, WildFire likely covers it. TFTP and DNS are edge-case or infrastructure protocols that don't fit that pattern.

Topics

#WildFire#zero-day detection#malware inspection#protocol inspection

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice