PSE-SASE · Question #114
How can a network engineer export all flow logs and security actions to a security information and event management (SIEM) system using Prisma Access?
The correct answer is B. Configure a log forwarding profile in the Prisma Access management interface and set up syslog. Option B is correct because Prisma Access provides a built-in log forwarding mechanism - you configure a log forwarding profile in the management interface (Panorama or the Strata Cloud Manager) and specify syslog as the transport, which is the industry-standard protocol SIEM…
Question
How can a network engineer export all flow logs and security actions to a security information and event management (SIEM) system using Prisma Access?
Options
- AManually export logs daily and upload them to the SIEM system.
- BConfigure a log forwarding profile in the Prisma Access management interface and set up syslog
- CUse the integrated SIEM module in Prisma Access, schedule regular email reports, and forward
- DUse an external cloud service to collect and forward logs to the SIEM.
How the community answered
(44 responses)- A7% (3)
- B77% (34)
- C2% (1)
- D14% (6)
Explanation
Option B is correct because Prisma Access provides a built-in log forwarding mechanism - you configure a log forwarding profile in the management interface (Panorama or the Strata Cloud Manager) and specify syslog as the transport, which is the industry-standard protocol SIEM platforms use to receive security telemetry continuously and in real time.
Why the distractors fail:
- A is wrong because manual daily exports introduce dangerous latency for security events and are not scalable - SIEMs need continuous, automated feeds.
- C is wrong because Prisma Access does not include an "integrated SIEM module," and email reports are not a real-time ingestion method; SIEMs ingest structured log streams, not email.
- D is wrong because routing logs through an external cloud service adds unnecessary complexity and a potential data loss point - the native syslog forwarding in Prisma Access handles this directly without a middleware hop.
Memory tip: Think "B for Built-in + Broadcast" - the Built-in log forwarding profile Broadcasts via syslog. If you remember that syslog is the universal SIEM language and Prisma Access speaks it natively, you can eliminate every other option.
Topics
Community Discussion
No community discussion yet for this question.