nerdexam
Palo_Alto_Networks

PCNSE · Question #781

What happens when the log forwarding built-in action with tagging is used?

The correct answer is C. Destination IP addresses of selected unwanted traffic are blocked. When the Log Forwarding built-in action with tagging fires, it registers a tag against the destination IP address of the matching traffic. This tag is consumed by a Dynamic Address Group (DAG) referenced in a Security policy rule configured to deny/block traffic. The net effect…

Submitted by carter_n· Apr 18, 2026Operate

Question

What happens when the log forwarding built-in action with tagging is used?

Options

  • ASelected logs are forwarded to the Azure Security Center.
  • BDestination zones of selected unwanted traffic are blocked.
  • CDestination IP addresses of selected unwanted traffic are blocked.
  • DSelected unwanted traffic source zones are blocked.

How the community answered

(42 responses)
  • A
    5% (2)
  • C
    93% (39)
  • D
    2% (1)

Explanation

When the Log Forwarding built-in action with tagging fires, it registers a tag against the destination IP address of the matching traffic. This tag is consumed by a Dynamic Address Group (DAG) referenced in a Security policy rule configured to deny/block traffic. The net effect is that the destination IP addresses of the unwanted traffic are dynamically blocked. This is an automated enforcement mechanism that reacts to log events. Options A (Azure forwarding), B (zone blocking), and D (source zone blocking) are not functions of the tagging built-in action - tagging operates on IP addresses, not zones, and log forwarding to external SIEMs uses separate profile types.

Topics

#Log Forwarding#Tagging#Dynamic Blocking#Policy Enforcement

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice