ExamGecko
Question list
Search
Search

Related questions











Question 291 - PCNSE discussion

Report
Export

Given the following snippet of a WildFire submission log did the end-user get access to the requested information and why or why not?

A.
Yes, because the action is set to alert
Answers
A.
Yes, because the action is set to alert
B.
No, because this is an example from a defeated phishing attack
Answers
B.
No, because this is an example from a defeated phishing attack
C.
No, because the severity is high and the verdict is malicious.
Answers
C.
No, because the severity is high and the verdict is malicious.
D.
Yes, because the action is set to allow.
Answers
D.
Yes, because the action is set to allow.
Suggested answer: D

Explanation:

As long as the action is set to allow, then it will still allow it. Threats that have the ability to become critical but have mitigating factors; for example, they may be difficult to exploit, do not result in elevated privileges, or do not have a large victim pool. WildFire Submissions log entries with a malicious verdict and an action set to allow are logged as High.

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/monitoring/view-and-managelogs/log-types-and-severity-levels/threat-logs#id5cea1511-a153-4005-9d5f-ab2482e838ae

asked 23/09/2024
Nandor Gombos
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first