nerdexam
Palo_Alto_Networks

PSE-SASE · Question #114

How can a network engineer export all flow logs and security actions to a security information and event management (SIEM) system using Prisma Access?

The correct answer is B. Configure a log forwarding profile in the Prisma Access management interface and set up syslog. Option B is correct because Prisma Access provides a built-in log forwarding mechanism - you configure a log forwarding profile in the management interface (Panorama or the Strata Cloud Manager) and specify syslog as the transport, which is the industry-standard protocol SIEM…

SASE Operations, Monitoring, and Troubleshooting

Question

How can a network engineer export all flow logs and security actions to a security information and event management (SIEM) system using Prisma Access?

Options

  • AManually export logs daily and upload them to the SIEM system.
  • BConfigure a log forwarding profile in the Prisma Access management interface and set up syslog
  • CUse the integrated SIEM module in Prisma Access, schedule regular email reports, and forward
  • DUse an external cloud service to collect and forward logs to the SIEM.

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    77% (34)
  • C
    2% (1)
  • D
    14% (6)

Explanation

Option B is correct because Prisma Access provides a built-in log forwarding mechanism - you configure a log forwarding profile in the management interface (Panorama or the Strata Cloud Manager) and specify syslog as the transport, which is the industry-standard protocol SIEM platforms use to receive security telemetry continuously and in real time.

Why the distractors fail:

  • A is wrong because manual daily exports introduce dangerous latency for security events and are not scalable - SIEMs need continuous, automated feeds.
  • C is wrong because Prisma Access does not include an "integrated SIEM module," and email reports are not a real-time ingestion method; SIEMs ingest structured log streams, not email.
  • D is wrong because routing logs through an external cloud service adds unnecessary complexity and a potential data loss point - the native syslog forwarding in Prisma Access handles this directly without a middleware hop.

Memory tip: Think "B for Built-in + Broadcast" - the Built-in log forwarding profile Broadcasts via syslog. If you remember that syslog is the universal SIEM language and Prisma Access speaks it natively, you can eliminate every other option.

Topics

#log forwarding#SIEM integration#syslog#flow logs

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice