Courseiva

NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture

An organization's security architecture requires that any file downloaded over web browsing or email must be blocked if its WildFire verdict is malicious, but files with unknown verdicts should be allowed to download while analysis occurs in the cloud. Which WildFire architectural profile setting achieves this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the WildFire Analysis profile forwarding rule with 'forward' for unknown files and a Security Rule action of 'allow', while enabling Threat Prevention to block known malicious hashes.

WildFire inline analysis and forward profiles support 'download-after-verdict' or allowing unknown files while holding execution on endpoints, or allowing the download while the cloud analyzes the file in real time depending on the exact forwarding rule configuration. For inline blocking of unknowns, 'block session' can be selected; to allow unknown files while analyzing, the action is set to allow with forwarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable WildFire forwarding and configure a static EDL blocking all file extensions (.exe, .pdf, .zip).

    Why it's wrong here

    Blocking all file extensions completely disrupts normal business operations.

  • Set the WildFire analysis profile action to 'Reset-Both' for all unknown file types, effectively blocking all file downloads.

    Why it's wrong here

    Setting action to block all unknowns violates the requirement to allow unknown files during analysis.

  • Configure a Decryption Profile to drop all sessions containing binary file headers.

    Why it's wrong here

    Dropping all binary headers breaks standard software updates and web browsing.

  • Configure the WildFire Analysis profile forwarding rule with 'forward' for unknown files and a Security Rule action of 'allow', while enabling Threat Prevention to block known malicious hashes.

    Why this is correct

    Forwarding unknowns for analysis while allowing the stream (or using inline ML to block) fulfills the requirement to permit unknowns while blocking malicious.

About these practice questions

Courseiva writes every NetSec-Architect question from scratch — 228 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.