Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium

A security analyst is investigating a potential data exfiltration attempt. They need to identify all sessions where a significant amount of data (over 1 GB) was uploaded to external destinations from internal hosts within the last 24 hours. Which log type and filter combination would be most effective for this investigation?

  1. AURL Filtering logs, (category eq 'file-sharing') and (bytes-received gt 1073741824)
  2. BTraffic logs, (bytes-sent gt 1073741824) and (direction eq 'outbound')
  3. CThreat logs, (action eq 'upload') and (bytes-sent gt 1073741824)
  4. DData Filtering logs, (file-type eq 'executable') and (bytes-sent gt 1073741824)
Show answer & explanation

Correct answer: B. Traffic logs, (bytes-sent gt 1073741824) and (direction eq 'outbound')

Traffic logs record all network sessions, including data transfer volumes. Filtering for 'bytes-sent' greater than 1 GB (1,073,741,824 bytes) and 'direction' as 'outbound' will effectively identify large data uploads to external destinations.

Why the other options are wrong

  • A. URL Filtering logs are for web access categories, not data transfer volume. 'bytes-received' would track downloads, not uploads.
  • C. Threat logs focus on security threats, not general data transfer volume. 'action eq 'upload'' is not a standard filter for threat logs related to data volume.
  • D. Data Filtering logs focus on specific data patterns or file types, not overall session data volume. 'file-type eq 'executable'' is too specific and irrelevant for general data exfiltration.

Traffic Logs for Data Volume Analysis

Traffic logs in Palo Alto Networks firewalls record details about network sessions, including the amount of data transferred (bytes-sent and bytes-received).

  • Crucial for bandwidth usage analysis and identifying large data transfers.
  • Includes fields like 'bytes-sent', 'bytes-received', 'duration', 'source', 'destination'.
  • Can be filtered to investigate potential data exfiltration or unusual data patterns.

Memory trick: Traffic Logs Track Transferred Terabytes.

More Monitoring and Reporting questions