PCNSE PCNSE Advanced Threat Prevention 2 — Questions and Answers
Question 1: Which WildFire verdict type indicates a file has been analyzed and found to contain malicious behavior?
- Benign
- Grayware
- Malicious (Correct answer)
- Phishing
Correct answer: Malicious
WildFire assigns a 'Malicious' verdict when dynamic or static analysis confirms the file contains harmful code or behavior.
Question 2: In a PAN-OS Antivirus security profile, what does the 'Wildfire Analysis' action do when set to 'Send' for unknown files?
- Blocks the file immediately
- Forwards the file to WildFire for analysis while allowing the session to continue (Correct answer)
- Quarantines the file on the endpoint
- Resets the TCP connection
Correct answer: Forwards the file to WildFire for analysis while allowing the session to continue
The 'Send' action uploads unknown files to WildFire for cloud-based analysis without blocking the in-progress session.
Question 3: What is the default WildFire public cloud update interval for signatures after a malicious verdict is issued?
- Every 24 hours
- Every 5 minutes
- Every 15 minutes (Correct answer)
- Every 60 minutes
Correct answer: Every 15 minutes
WildFire pushes updated antivirus signatures to subscribers every 15 minutes by default after issuing a malicious verdict.
Question 4: An administrator wants to use DNS Sinkholing. What must be configured on the firewall to enable this feature?
- A custom URL category
- An Anti-Spyware security profile with DNS Sinkhole enabled (Correct answer)
- A Vulnerability Protection profile with block action
- A QoS policy for DNS traffic
Correct answer: An Anti-Spyware security profile with DNS Sinkhole enabled
DNS Sinkholing is configured within an Anti-Spyware security profile, where you specify the sinkhole IP address for malicious DNS queries.
Question 5: Which log type shows WildFire submission and verdict information on a Palo Alto Networks firewall?
- Threat log
- WildFire Submissions log (Correct answer)
- Data Filtering log
- URL Filtering log
Correct answer: WildFire Submissions log
The WildFire Submissions log records file submissions, file types, verdicts, and associated session details.
Question 6: A company needs to prevent credential phishing but cannot decrypt HTTPS traffic. Which Threat Prevention feature can still help identify phishing sites?
- Anti-Spyware DNS Sinkhole
- URL Filtering with PAN-DB phishing category (Correct answer)
- File Blocking profiles
- Vulnerability Protection signatures
Correct answer: URL Filtering with PAN-DB phishing category
URL Filtering using PAN-DB can block or alert on known phishing URLs based on category, even without SSL/TLS decryption.
Question 7: When configuring WildFire in a private cloud deployment, which component receives file submissions from the firewall?
- Panorama
- WF-500 appliance (Correct answer)
- Expedition
- AutoFocus
Correct answer: WF-500 appliance
The WF-500 is the on-premises WildFire private cloud appliance that receives and analyzes file submissions locally.
Which WildFire verdict type indicates a file has been analyzed and found to contain malicious behavior?