nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #190

A customer requires an analytics tool with the following attributes: - Uses the logs on the firewall to detect actionable events on the network - Automatically processes a series of related threat eve

The correct answer is C. Automated correlation engine (ACE). The automated correlation engine is an analytics tool that uses the logs on the firewall to detect actionable events on your network. The engine correlates a series of related threat events that, when combined, indicate a likely compromised host on your network or some other high

Threat Prevention

Question

A customer requires an analytics tool with the following attributes:

  • Uses the logs on the firewall to detect actionable events on the network
  • Automatically processes a series of related threat events that, when combines, indicate a likely

comprised host on the network

  • Pinpoints the area of risk and allows for assessment of the risk to action can be taken to prevent

exploitation of network resources Which feature of PAN-OS will address these requirements?

Options

  • AWildFire with application program interface (API) calls for automation
  • BThird-party security information and event management (SIEM) which can ingest next-generation
  • CAutomated correlation engine (ACE)
  • DCortex XDR and Cortex Data Lake

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    80% (37)
  • D
    11% (5)

Explanation

The automated correlation engine is an analytics tool that uses the logs on the firewall to detect actionable events on your network. The engine correlates a series of related threat events that, when combined, indicate a likely compromised host on your network or some other higher level conclusion. It pinpoints areas of risk, such as compromised hosts on the network, allows you to assess the risk and take action to prevent exploitation of network resources. The automated correlation engine uses correlation objects to analyze the logs for patterns and when a match occurs, it generates a correlated event. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated- engine#:~:text=The%20automated%20correlation%20engine%20is,some%20other%20higher%2 0level%20conclusion.

Topics

#Automated Correlation Engine#compromised host detection#threat analytics#log analysis

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice