Palo Alto Networks PSE-Endpoint Exam - Topic 2 Question 69 Discussion
A customer plans to test the malware prevention capabilities of Traps. It has defined this policy.* Local analysis is enabled* Quarantining of malicious files is enabled* Files are to be uploaded to WildFireNo executables have been whitelisted or blacklisted in the ESM Console Hash Control screen.Malware sample A has a verdict of Malicious in the WildFire service. Malware sample B is unknown to WildFire.Which behavior will result?
B) Hash Control already knows sample A locally in the endpoint cache and will block it. Sample B will not be blocked by WildFire, but will be blocked by the local analysis engine.
A) WildFire will block sample A as known malware; sample B will be blocked as an unknown binary while the file is analyzed by WildFire for a final verdict.
C) WildFire will block sample A as known malware, and sample B will compromise the endpoint because it is new and ESM Server has not obtained the required signatures.
D) WildFire will block sample A as known malware; sample B will not be blocked by WildFire, but will be evaluated by the local analysis engine and will or will not be blocked, based on its verdict, until WildFire analysis determines the final verdict.
Shaunna
10 months agoRenato
10 months agoMinna
10 months agoTamesha
11 months agoNell
11 months agoGolda
11 months agoCeola
11 months agoKiera
11 months agoLucy
11 months agoKeneth
11 months agoFrancesco
12 months agoDawne
12 months agoFreeman
12 months agoNida
12 months agoLouvenia
12 months agoKaycee
12 months agoGary
1 year agoViki
1 year agoGaynell
1 year agoRasheeda
1 year agoColette
1 year agoGalen
1 year agoPeggy
1 year agoPura
1 year agoBettina
1 year agoBroderick
1 year agoTerrilyn
1 year agoLeota
1 year agoDick
1 year agoTijuana
1 year agoLynette
1 year agoBettina
1 year ago