PCNSE · Question #781
What happens when the log forwarding built-in action with tagging is used?
The correct answer is C. Destination IP addresses of selected unwanted traffic are blocked. When the Log Forwarding built-in action with tagging fires, it registers a tag against the destination IP address of the matching traffic. This tag is consumed by a Dynamic Address Group (DAG) referenced in a Security policy rule configured to deny/block traffic. The net effect…
Question
What happens when the log forwarding built-in action with tagging is used?
Options
- ASelected logs are forwarded to the Azure Security Center.
- BDestination zones of selected unwanted traffic are blocked.
- CDestination IP addresses of selected unwanted traffic are blocked.
- DSelected unwanted traffic source zones are blocked.
How the community answered
(42 responses)- A5% (2)
- C93% (39)
- D2% (1)
Explanation
When the Log Forwarding built-in action with tagging fires, it registers a tag against the destination IP address of the matching traffic. This tag is consumed by a Dynamic Address Group (DAG) referenced in a Security policy rule configured to deny/block traffic. The net effect is that the destination IP addresses of the unwanted traffic are dynamically blocked. This is an automated enforcement mechanism that reacts to log events. Options A (Azure forwarding), B (zone blocking), and D (source zone blocking) are not functions of the tagging built-in action - tagging operates on IP addresses, not zones, and log forwarding to external SIEMs uses separate profile types.
Topics
Community Discussion
No community discussion yet for this question.