Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingHard
A company policy requires that any download of an executable file (.exe) from the internet must be recorded in a specific report, along with the user who initiated the download and the source URL. Which Palo Alto Networks logging feature, when properly configured with a Security Profile, enables this specific type of granular logging?
- AURL Filtering Logs with custom URL categories.
- BWildFire Logs with a malware analysis profile.
- CTraffic Logs with application filters.
- DData Filtering Logs with a File Blocking profile.
Show answer & explanationAnswer & explanation
Correct answer: D. Data Filtering Logs with a File Blocking profile.
Data Filtering logs, specifically when a File Blocking profile is configured to block or alert on executable file downloads, will record the necessary details including the user, source URL, and file type. While other logs might show some data, Data Filtering is designed for content inspection and logging specific file transfers.
Why the other options are wrong
- A. URL Filtering logs categorize websites, but don't specifically log file type downloads or user details for blocked files.
- B. WildFire logs are for malware analysis of unknown files, not for simply recording the download of known executable file types as per policy.
- C. Traffic logs show the session but not the specific file content or the user who initiated a specific file download, only the application.
Data Filtering Logs
Data Filtering logs record events related to the detection or blocking of sensitive data or specific file types as defined by Data Filtering profiles (e.g., File Blocking, Data Loss Prevention). They provide granular details about the content that triggered the policy.
- Requires a Data Filtering Security Profile to be applied to security rules.
- Captures information like file name, type, user, source/destination.
- Used for compliance, preventing data exfiltration, and controlling file transfers.
Memory trick: Content inspection needs specific logs to detail what's inside.