nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #4

A customer is looking for an analytics tool that uses the logs on the firewall to detect actionable events on the network. They require something to automatically process a series of related threat ev

The correct answer is A. The Automated Correlation Engine. The automated correlation engine is an analytics tool that uses the logs on the firewall to detect actionable events on your network. The engine correlates a series of related threat events that, when combined, indicate a likely compromised host on your network or some other high

Threat Prevention and WildFire

Question

A customer is looking for an analytics tool that uses the logs on the firewall to detect actionable events on the network. They require something to automatically process a series of related threat events that, when combined, indicate a likely compromised host on their network or some other higher level conclusion. They need to pinpoint the area of risk, such as compromised hosts on the network, allows you to assess the risk and take action to prevent exploitation of network resources. Which feature of PAN-OS can you talk about to address their requirement to optimize their business outcomes?

Options

  • AThe Automated Correlation Engine
  • BCortex XDR and Cortex Data Lake
  • CWildFire with API calls for automation
  • D3rd Party SIEM which can ingest NGFW logs and perform event correlation

How the community answered

(21 responses)
  • A
    71% (15)
  • B
    5% (1)
  • C
    14% (3)
  • D
    10% (2)

Explanation

The automated correlation engine is an analytics tool that uses the logs on the firewall to detect actionable events on your network. The engine correlates a series of related threat events that, when combined, indicate a likely compromised host on your network or some other higher level conclusion. It pinpoints areas of risk, such as compromised hosts on the network, allows you to assess the risk and take action to prevent exploitation of network resources. The automated correlation engine uses correlation objects to analyze the logs for patterns and when a match occurs, it generates a correlated event. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-automated- engine#:~:text=The%20automated%20correlation%20engine%20is,some%20other%20higher%2 0level%20conclusion.

Topics

#Automated Correlation Engine#threat correlation#compromised host detection#PAN-OS analytics

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice