Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium
A security analyst is investigating a potential data exfiltration incident. They need to review all outbound traffic from a specific internal subnet (10.1.1.0/24) that used the 'ftp' application over the last 24 hours and was allowed by the firewall. Which log type and filter combination would be most effective for this purpose?
- ATraffic logs, (source eq 10.1.1.0/24) and (application eq ftp) and (action eq allow)
- BURL Filtering logs, (source eq 10.1.1.0/24) and (application eq ftp) and (action eq alert)
- CData Filtering logs, (source eq 10.1.1.0/24) and (application eq ftp) and (action eq block)
- DThreat logs, (source eq 10.1.1.0/24) and (application eq ftp) and (action eq drop)
Show answer & explanationAnswer & explanation
Correct answer: A. Traffic logs, (source eq 10.1.1.0/24) and (application eq ftp) and (action eq allow)
To investigate allowed outbound traffic for data exfiltration, Traffic logs are the primary source. The filters 'source eq 10.1.1.0/24' and 'application eq ftp' correctly identify the origin and method, and 'action eq allow' ensures only permitted sessions are shown, which is crucial for exfiltration investigation.
Why the other options are wrong
- B. URL Filtering logs are for web access, not FTP, and 'action eq alert' is not a standard action for general traffic logs.
- C. Data Filtering logs are for specific data patterns, not all allowed application traffic, and 'action eq block' would show denied traffic.
- D. Threat logs are for detected threats, not general traffic flow, and 'action eq drop' would show blocked traffic, not allowed.
Traffic Log Analysis
Traffic logs record details of all sessions processed by the firewall, including source, destination, application, action (allow/deny), and bytes transferred.
- Essential for understanding network flow and allowed/denied connections.
- Can be filtered by various criteria like source/destination IP, application, port, action.
- Crucial for troubleshooting connectivity and investigating security incidents.
Memory trick: To see the 'flow', use 'traffic' logs and filter what's 'allowed'!