NEW QUESTION NO: 1
Which three file types will be uploaded automatically to WildFire for examination? (Choose three.)
A. Application data files that trigger preventions
B. Executables allowed to run by local analysis
C. Executables with a verdict overridden by the administrator
D. Executables with no previous verdict in the ESM deployment
E. Application data files opened by the end user
F. Executables allowed to run because their publisher is trusted
Answer: A,B,E
NEW QUESTION NO: 2
Which two statements about advanced cyberthreats are true? (Choose two.)
A. It is very common for attacks to use previously unknown malware.
B. A zero-day vulnerability is defined as a security flaw of which the vulnerable product's vendor has no prior awareness.
C. It is impractical to protect against zero-day attacks.
D. A zero-day vulnerability is defined as a security flaw of which the vulnerable product's customers have no prior awareness.
Answer: B,D
NEW QUESTION NO: 3
In which two ways does Traps complement Palo Alto Networks perimeter protection?
(Choose two.)
A. Information about threats from both Palo Alto Networks firewalls and Traps endpoints flows into a shared threat intelligence cloud.
B. ESM servers send information about threats directly to Palo Alto Networks firewalls.
C. Endpoints are sometimes operated by their users outside the corporate network perimeter.
D. Traps endpoints send information about threats directly to Palo Alto Networks firewalls.
Answer: B,D
NEW QUESTION NO: 4
The Traps product and documentation use the terms "malware" and "exploit" in a very specific way. Which two statements are true? (Choose two.)
A. The primary vector for exploits is .exe files.
B. Malware consists of application data files containing malicious code.
C. Malware consists of malicious executable files that do not rely on exploit techniques.
D. Exploits attempt to take advantage of a vulnerability in code.
Answer: B,D
NEW QUESTION NO: 5
Which two statements about Local Analysis are true? (Choose two.)
A. Local analysis is called whenever an executable file would otherwise get an Unknown or No Connection verdict.
B. Palo Alto Networks uses machine-learning techniques in its labs to build the local analysis model.
C. Traps endpoint agents build a local analysis model based on the executables they detect.
D. Local analysis is called to validate all verdicts on executable files before the files are allowed to run.
Answer: A,B
NEW QUESTION NO: 6
Which two statements about file hashes are true? (Choose two.)
A. The Traps agent caches the hashes of executable files for which it has verdicts.
B. WildFire populates ESM Server's cache with hashes of files known from other customers to be malicious.
C. ESM Servers send hashes of application data files to WildFire.
D. ESM Servers send hashes of executable files to WildFire.
Answer: B,C
NEW QUESTION NO: 7
How does an administrator make a Tech Support File?
A. Use cytool on the endpoint
B. Click the "Generate" button on the Settings page in ESM Console
C. Use dbconfig on ESM Server
D. Click the "Create ZIP" button on the Logs page in ESM Console
Answer: B
NEW QUESTION NO: 8
What is the maximum supported number of endpoints per ESM Server in a Traps 3.4 deployment?
A. 350
B. 10,000
C. 16,000
D. 80,000
Answer: D
NEW QUESTION NO: 9
Which three statements about the trusted publisher mechanism are true? (Choose three.)
A. The trusted-publisher mechanism is called whenever an executable file would otherwise get an Unknown or No Connection verdict.
B. The trusted-publisher mechanism allows trusted signed executables to run without seeking a WildFire verdict.
C. The trusted-publisher mechanism blocks executables from running unless they are signed by a trusted publisher.
D. The list of trusted publishers is maintained through content updates.
E. The trusted-publisher mechanism takes precedence over verdict overrides by administrators.
F. No executable will be affected by the trusted-publisher mechanism unless it is signed by a publisher on a list maintained by Palo Alto Networks.
Answer: A,D,E
NEW QUESTION NO: 10
A user receives an email with an attached data file containing an exploit. What is it's likely effect? (Choose two.)
A. The exploit can work only if a corresponding application is installed on the user's system.
B. The exploit can do damage only if it downloads a piece of malware.
C. The exploit can work only if it begins with a buffer overflow.
D. The exploit might be launched merely by previewing the attachment.
Answer: A,B