Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium
A cybersecurity incident response team is investigating a potential malware outbreak. They need to quickly determine if any files submitted to WildFire from the internal network (192.168.1.0/24) were identified as malicious and, if so, which users initiated the connections. Which log type should the team focus on for this investigation?
- AWildFire Submissions logs
- BData Filtering logs
- CURL Filtering logs
- DThreat logs
Show answer & explanationAnswer & explanation
Correct answer: A. WildFire Submissions logs
WildFire Submissions logs specifically record details about files sent to the WildFire cloud for analysis, including the verdict (malicious, benign, grayware), the submitting user, and the source/destination. This log type is precisely designed for investigating malware outbreaks related to WildFire.
Why the other options are wrong
- B. Data Filtering logs are for sensitive data patterns, not file analysis by WildFire.
- C. URL Filtering logs pertain to web access, not file submissions for malware analysis.
- D. Threat logs show detected threats on the firewall, but WildFire Submissions logs provide the specific context for files sent to WildFire.
WildFire Submissions Logs
WildFire Submissions logs provide detailed records of files submitted to the WildFire cloud for advanced threat analysis, including the analysis verdict, source, destination, and user information.
- Shows the WildFire verdict (malicious, benign, grayware).
- Includes sender/receiver and user details for submitted files.
- Crucial for investigating patient zero and spread of new malware.
Memory trick: For 'WildFire' verdicts, check the 'WildFire Submissions' logs directly!