PCNSE · Question #400
A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is bei
The correct answer is B. Data Filtering log. File Blocking profile events-regardless of the action (alert, block, continue)-are recorded in the Data Filtering log (Monitor > Logs > Data Filtering), not the Threat log. The Threat log captures vulnerability exploits, spyware, and antivirus events. The WildFire Submissions log
Question
A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system. Where is the best place to validate if the firewall is blocking the user's TAR file?
Options
- AThreat log
- BData Filtering log
- CWildFire Submissions log
- DURL Filtering log
How the community answered
(34 responses)- A6% (2)
- B91% (31)
- C3% (1)
Explanation
File Blocking profile events-regardless of the action (alert, block, continue)-are recorded in the Data Filtering log (Monitor > Logs > Data Filtering), not the Threat log. The Threat log captures vulnerability exploits, spyware, and antivirus events. The WildFire Submissions log tracks files sent to WildFire for analysis. The URL Filtering log captures web category events. Because the engineer applied a File Blocking profile with a 'Block' action, the TAR file download attempt will appear in the Data Filtering log, making it the correct place to validate and confirm the block.
Topics
Community Discussion
No community discussion yet for this question.