nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #155

The firewall includes predefined reports, custom reports can be built for specific data and actionable tasks, or predefined and custom reports can be combined to compile information needed to…

The correct answer is C. Netflow Reports D. Botnet Reports E. User or Group Activity Reports. Netflow Reports, Botnet Reports, and User or Group Activity Reports represent three core report categories that firewalls provide to deliver actionable network security intelligence -- Netflow Reports capture traffic flow data for network analysis, Botnet Reports identify hosts…

Logging and Monitoring

Question

The firewall includes predefined reports, custom reports can be built for specific data and actionable tasks, or predefined and custom reports can be combined to compile information needed to monitor network security. The firewall provides which three types of reports? (Choose three.)

Options

  • ASNMP Reports
  • BPDF Summary Reports
  • CNetflow Reports
  • DBotnet Reports
  • EUser or Group Activity Reports

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    6% (3)
  • C
    84% (43)

Explanation

Netflow Reports, Botnet Reports, and User or Group Activity Reports represent three core report categories that firewalls provide to deliver actionable network security intelligence -- Netflow Reports capture traffic flow data for network analysis, Botnet Reports identify hosts potentially compromised by malware or command-and-control activity, and User or Group Activity Reports tie network behavior to specific identities for accountability and policy enforcement.

SNMP (option A) is a network management protocol used for device monitoring and alerting, not a firewall report type, so it does not belong in this category. PDF Summary Reports (option B) describes an output format or delivery method for packaging reports, not a distinct report category in its own right, which is why it is a distractor.

Memory tip: Focus on the three types of data a firewall uniquely surfaces -- flow data (Netflow), threat data (Botnet), and identity data (User/Group Activity). These map to the three pillars of network visibility: what traffic is moving, what threats are present, and who is responsible.

Topics

#Firewall Reporting#Network Monitoring#Threat Intelligence#Security Analytics

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice