InterviewSolution
| 1. |
What exactly is a wildfire? Could you give a basic description of how wildfire works? |
|
Answer» Finding solutions and analysing malware to protect a network from potential attacks is a time-consuming procedure. Wildfire is a cloud-based malware DETECTION service that aids in the detection of unknown files or threats created by attackers. Wildfire provides enterprises with immediate protection and danger intelligence. The WildFire Analysis Environment detects and blocks previously unknown malware by creating signatures that Palo Alto Networks firewalls can employ to detect and stop it. When a Palo Alto Networks firewall identifies an unknown sample (a file or a link included in an email), it can send the sample to WildFire for analysis. WildFire classifies a sample as benign, grayware, phishing, or malicious based on the traits, behaviours, and activities it exhibits when examined and PERFORMED in the WildFire sandbox. WildFire then creates signatures to RECOGNISE the freshly identified malware and makes the most recent signatures available globally in real-time for retrieval. The malware originally detected by a single Palo Alto Networks firewall can subsequently be automatically blocked by all Palo Alto Networks firewalls by comparing incoming samples against these signatures. From the time where a USER downloads a file containing an advanced VM-aware payload until the point where WildFire develops a signature package utilised by Palo Alto Networks firewalls to protect against future malware exposure, the FOLLOWING sequence explains the WildFire process lifecycle. |
|