Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCCSE Topic 5 Question 82 Discussion

Actual exam question for Palo Alto Networks's PCCSE exam
Question #: 82
Topic #: 5
[All PCCSE Questions]

An administrator sees that a runtime audit has been generated for a host. The audit message is:

''Service postfix attempted to obtain capability SHELL by executing /bin/sh /usr/libexec/postfix/postfix- script.stop. Low severity audit, event is automatically added to the runtime model''

Which runtime host policy rule is the root cause for this runtime audit?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Odelia
2 days ago
Hmm, I'm not sure about this one. The audit message doesn't mention anything about file integrity or networking, so A) and B) don't seem to be the right answers. I'll have to think about this a little more.
upvoted 0 times
...
Luz
10 days ago
The runtime audit message suggests that the postfix service tried to obtain the SHELL capability, which is a suspicious runtime behavior. So, I think the correct answer is D) Default rule that alerts on suspicious runtime behavior.
upvoted 0 times
...
Marguerita
10 days ago
I agree with Delisa, it seems like the default rule for capabilities is the root cause.
upvoted 0 times
...
Delisa
12 days ago
I believe it could be a default rule that alerts on capabilities.
upvoted 0 times
...
Miesha
17 days ago
I think the root cause is a custom rule for file integrity.
upvoted 0 times
...

Save Cancel