Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium
A cybersecurity incident response team needs a daily report of all files submitted to WildFire for analysis, including their verdict and the user who submitted them. Where would the custom report pull this information from?
- AData Filtering Logs
- BThreat Logs
- CWildFire Logs
- DTraffic Logs
Show answer & explanationAnswer & explanation
Correct answer: C. WildFire Logs
WildFire logs are specifically generated for files submitted to the WildFire cloud for malware analysis. They contain details about the file, its verdict (malicious, benign, grayware), and the user who generated the traffic that submitted the file.
Why the other options are wrong
- A. Data Filtering logs are for content inspection and blocking specific data or file types based on policy, not for WildFire analysis status.
- B. Threat logs record detected threats, but WildFire logs provide the specific details of files submitted for analysis, including the 'pending' state and final verdict.
- D. Traffic logs record session information but not specific file submission details or WildFire verdicts.
WildFire Logs
WildFire logs on a Palo Alto Networks firewall record information about files submitted to the WildFire cloud for advanced malware analysis. They detail the file hash, verdict (malicious, benign, grayware), and associated session information.
- Crucial for identifying and understanding zero-day threats.
- Generated when a WildFire Analysis profile is applied to a security rule.
- Provides a comprehensive audit trail of advanced threat detection.
Memory trick: Each log type tells a different story about your network's life.