PCNSA · Question #248
Which log type would be used to find commit entries for a firewall?
The correct answer is A. Config. To find commit entries and other administrative configuration changes on a Palo Alto Networks firewall, the administrator should consult the Config log type. This log specifically records configuration changes, including when commits occur and by whom.
Question
Which log type would be used to find commit entries for a firewall?
Options
- AConfig
- BAlarms
- CCorrelation
- DSystem
How the community answered
(32 responses)- A94% (30)
- B3% (1)
- C3% (1)
Why each option
To find commit entries and other administrative configuration changes on a Palo Alto Networks firewall, the administrator should consult the Config log type. This log specifically records configuration changes, including when commits occur and by whom.
The Config log type records all configuration changes made on the firewall, including when an administrator commits a configuration, providing details like the timestamp and the administrator who performed the action. This log is crucial for auditing configuration modifications.
Alarms are related to specific security events or system health issues, not configuration changes or commits.
Correlation logs identify patterns of related events across different log types to detect complex threats, not individual commit actions.
System logs record events related to the firewall's operating system and hardware, such as daemon restarts or high resource utilization, but not explicitly commit entries.
Concept tested: Firewall log types for configuration auditing
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/config-log-fields
Topics
Community Discussion
No community discussion yet for this question.