Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PSE-Endpoint Topic 2 Question 69 Discussion

Actual exam question for Palo Alto Networks's PSE-Endpoint exam
Question #: 69
Topic #: 2
[All PSE-Endpoint Questions]

A customer plans to test the malware prevention capabilities of Traps. It has defined this policy.

* Local analysis is enabled

* Quarantining of malicious files is enabled

* Files are to be uploaded to WildFire

No executables have been whitelisted or blacklisted in the ESM Console Hash Control screen.

Malware sample A has a verdict of Malicious in the WildFire service. Malware sample B is unknown to WildFire.

Which behavior will result?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Gary
3 hours ago
Haha, I bet the guy who wrote option C is the same one who thought it was a good idea to let the unknown sample through. What a rookie mistake!
upvoted 0 times
...
Colette
15 days ago
Woah, C is definitely wrong. There's no way the unknown sample B would compromise the endpoint if ESM hasn't got the signatures yet. That's just crazy talk!
upvoted 0 times
Peggy
1 days ago
A) WildFire will block sample A as known malware; sample B will be blocked as an unknown binary while the file is analyzed by WildFire for a final verdict.
upvoted 0 times
...
...
Pura
17 days ago
Hmm, I'm not sure about this one. I think B might be the right answer, since the endpoint cache should already know about sample A.
upvoted 0 times
...
Bettina
21 days ago
But if WildFire already knows sample A as malicious, it should block it immediately, right?
upvoted 0 times
...
Broderick
23 days ago
I think the correct answer is D. WildFire will block the known malware, while the unknown sample will be evaluated by the local analysis engine until WildFire provides a final verdict.
upvoted 0 times
...
Lynette
26 days ago
I disagree, I believe the correct answer is D.
upvoted 0 times
...
Bettina
29 days ago
I think the answer is A.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77