Courseiva
Network SecurityhardMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Network Security Practice Question

An administrator notices that an internal client is infected with malware that is attempting to exfiltrate data over HTTPS using a custom encrypted protocol that evades standard signatures. The administrator wants to configure WildFire inline machine learning to block this zero-day threat in real-time. Which feature must be enabled and configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Inline Machine Learning in the WildFire Analysis Profile attached to the Security policy rule.

WildFire inline machine learning provides real-time detection of zero-day threats during the initial session handshake. This requires a WildFire Analysis Profile with inline ML enabled, attached to the Security policy rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable SSL Decryption with a custom Decryption Forward Trust certificate.

    Why it's wrong here

    While decryption helps visibility, decryption alone does not provide zero-day inline machine learning detection without WildFire.

  • Set the Anti-Spyware profile action to 'Reset Both' for all severity levels.

    Why it's wrong here

    Anti-Spyware protects against known signatures, not inline zero-day machine learning analysis.

  • Enable Inline Machine Learning in the WildFire Analysis Profile attached to the Security policy rule.

    Why this is correct

    Inline machine learning evaluates files and sessions in real-time before the complete payload is downloaded or exfiltrated.

  • Configure a custom Application Override rule for the encrypted stream.

    Why it's wrong here

    Application override bypasses threat inspection and WildFire analysis entirely.

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.