NETSEC-ANALYST · Question #434
An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?
The correct answer is B. Type. The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value mean
Question
An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?
Options
- AReceive Time
- BType
- CDestination
- DSource
How the community answered
(52 responses)- A6% (3)
- B75% (39)
- C15% (8)
- D4% (2)
Explanation
The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value means that the log entry is for the end of the session. The other values indicate that the session was terminated by the firewall for various reasons.
Topics
Community Discussion
No community discussion yet for this question.