PSE-STRATA · Question #186
Which two features are key in preventing unknown targeted attacks? (Choose two)
The correct answer is B. App-ID with the Zero Trust model C. WildFire Cloud threat analysis. App-ID with Zero Trust (B) and WildFire Cloud threat analysis (C) together address both sides of the unknown targeted attack problem. App-ID identifies applications regardless of port or protocol, and pairing it with Zero Trust's "never trust, always verify" principle ensures…
Question
Which two features are key in preventing unknown targeted attacks? (Choose two)
Options
- Anighty botnet report
- BApp-ID with the Zero Trust model
- CWildFire Cloud threat analysis
- DSingle Pass Parallel Processing (SP3)
How the community answered
(26 responses)- A4% (1)
- B85% (22)
- D12% (3)
Explanation
App-ID with Zero Trust (B) and WildFire Cloud threat analysis (C) together address both sides of the unknown targeted attack problem. App-ID identifies applications regardless of port or protocol, and pairing it with Zero Trust's "never trust, always verify" principle ensures only explicitly authorized applications can traverse the network - blocking unknown or unauthorized app-based attack vectors. WildFire complements this by sending unknown files and URLs to a cloud sandbox for dynamic analysis, using machine learning and behavioral analysis to detect zero-day malware and novel threats before they execute.
Why the distractors are wrong:
- A (Nightly botnet report): This is a retrospective reporting tool - it shows botnet activity that already happened, offering visibility but no active prevention of unknown attacks.
- D (SP3 - Single Pass Parallel Processing): SP3 is a performance architecture that processes traffic through all security engines in a single pass efficiently. It improves throughput, not threat detection capability.
Memory tip: Think "Wild App stops the unknown" - WildFire catches unknown files in the cloud, App-ID + Zero Trust catches unknown/unauthorized applications on the wire. The other two options are about reporting performance and hardware efficiency - neither identifies or blocks a new threat.
Community Discussion
No community discussion yet for this question.