5V0-43.21 · Question #89
Where are logging messages related to the inspection of application traffic found when enabling the Web Application Firewall (WAF) on a Virtual Service?
The correct answer is C. Analytics tab of Virtual Service detail screen. When WAF is enabled on a Virtual Service, traffic inspection logs appear in the Analytics tab because this is where all detailed per-request data - including security inspection events, policy matches, and application-layer analysis - is surfaced for that Virtual Service. WAF…
Question
Where are logging messages related to the inspection of application traffic found when enabling the Web Application Firewall (WAF) on a Virtual Service?
Options
- ALogs tab of Virtual Service detail screen
- BSecurity tab of the Virtual Service detail screen
- CAnalytics tab of Virtual Service detail screen
- DAlerts tab of the Operations screen
How the community answered
(32 responses)- A3% (1)
- B6% (2)
- C81% (26)
- D9% (3)
Explanation
When WAF is enabled on a Virtual Service, traffic inspection logs appear in the Analytics tab because this is where all detailed per-request data - including security inspection events, policy matches, and application-layer analysis - is surfaced for that Virtual Service. WAF logging is treated as observability data, not a configuration item or alert condition, so it lives alongside other traffic analytics.
Why the distractors are wrong:
- A (Logs tab): The Logs tab shows general system/event logs for the Virtual Service, not granular WAF inspection details tied to individual requests.
- B (Security tab): The Security tab is where you configure WAF policies and settings - it's a control plane view, not a data/logging view.
- D (Alerts tab on Operations screen): Alerts are threshold-based notifications for operational events (e.g., pool down, high error rate), not WAF inspection records.
Memory tip: Think of Analytics as the "show my work" tab - it reveals what the Virtual Service actually did to each request, which is exactly where WAF inspection results (what it found, what it blocked) would appear. Config → Security tab; Results → Analytics tab.
Topics
Community Discussion
No community discussion yet for this question.