PCNSE · Question #777
A root cause analysis investigation into a recent security incident reveals that several decryption rules have been disabled. The security team wants to generate email alerts when decryption rules…
The correct answer is B. With the relevant configuration log filter inside Device > Log Settings. To generate email alerts for changes to decryption rules, configure a configuration log filter with email forwarding within Device > Log Settings.
Question
A root cause analysis investigation into a recent security incident reveals that several decryption rules have been disabled. The security team wants to generate email alerts when decryption rules are changed. How should email log forwarding be configured to achieve this goal?
Options
- AWith the relevant system log filter inside Device > Log Settings
- BWith the relevant configuration log filter inside Device > Log Settings
- CWith the relevant configuration log filter inside Objects > Log Forwarding
- DWith the relevant system log filter inside Objects > Log Forwarding
How the community answered
(37 responses)- A19% (7)
- B73% (27)
- C5% (2)
- D3% (1)
Why each option
To generate email alerts for changes to decryption rules, configure a configuration log filter with email forwarding within Device > Log Settings.
System logs record operational events of the firewall, not changes to security policy configurations like decryption rules.
Changes to security policies, including decryption rules, are recorded as configuration logs, and the filters for these logs are applied in Device > Log Settings to trigger email alerts via a configured log forwarding profile.
While Objects > Log Forwarding defines the log forwarding profiles, the specific log type filters (like for configuration logs) are defined under Device > Log Settings.
System logs do not capture configuration changes, and the specific log filtering definition is done under Device > Log Settings, not directly in Objects > Log Forwarding.
Concept tested: Log forwarding configuration for alerts
Source: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/monitoring/configure-log-forwarding/configure-log-forwarding-to-an-email-server
Topics
Community Discussion
No community discussion yet for this question.