Palo Alto Networks Certified Network Security Engineer (PCNSE) — Question 588
Cortex XDR notifies an administrator about grayware on the endpoints. There are no entries about grayware in any of the logs of the corresponding firewall. Which setting can the administrator configure on the firewall to log grayware verdicts?
Answer options
- A. in Threat General Settings, select "Report Grayware Files"
- B. within the log settings option in the Device tab
- C. in WildFire General Settings, select "Report Grayware Files"
- D. within the log forwarding profile attached to the Security policy rule
Correct answer: C
Explanation
The correct answer is C, as enabling 'Report Grayware Files' in WildFire General Settings allows the firewall to log grayware verdicts. Options A and B do not pertain to the WildFire settings, and D relates to log forwarding profiles, which do not specifically address grayware logging.