nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #434

An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?

The correct answer is B. Type. The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value mean

Logging and Monitoring

Question

An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?

Options

  • AReceive Time
  • BType
  • CDestination
  • DSource

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    75% (39)
  • C
    15% (8)
  • D
    4% (2)

Explanation

The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value means that the log entry is for the end of the session. The other values indicate that the session was terminated by the firewall for various reasons.

Topics

#traffic logs#session type attribute#log filtering#NGFW monitoring

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice