PCNSA · Question #381
Which two events can be found in data-filtering logs? (Choose two.)
The correct answer is B. Sensitive information attempting to exit the network D. A download attempt of a blocked file type. Data filtering logs record events related to Data Loss Prevention (DLP), such as attempts to transmit sensitive information outside the network and attempts to download or upload specific blocked file types.
Question
Which two events can be found in data-filtering logs? (Choose two.)
Options
- ASpecific users attempting to authenticate
- BSensitive information attempting to exit the network
- CAn unsuccessful attempt to establish a TLS session
- DA download attempt of a blocked file type
How the community answered
(28 responses)- A7% (2)
- B86% (24)
- C7% (2)
Why each option
Data filtering logs record events related to Data Loss Prevention (DLP), such as attempts to transmit sensitive information outside the network and attempts to download or upload specific blocked file types.
Events related to user authentication attempts are typically found in authentication logs or system logs, not data-filtering logs.
Data filtering policies are designed to detect and prevent the exfiltration of sensitive data, so attempts to send sensitive information out of the network would be logged.
Unsuccessful attempts to establish a TLS session are typically found in system logs, URL filtering logs (if related to a blocked site), or threat logs (if an attack is involved), not data-filtering logs.
Data filtering profiles can also be configured to block specific file types based on their actual file type (not just extension), and attempts to download or upload these blocked types would be recorded in the data filtering logs.
Concept tested: Data filtering log events (DLP)
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/data-filtering/data-filtering-overview.html
Topics
Community Discussion
No community discussion yet for this question.