
Palo Alto NetworksCertified Network Security Analyst
Domain 1Objective 5
1.5 Create and Apply Log Forwarding Profile NETWORK-SECURITY-ANALYST Practice Questions (Page 2)
Part of the Object Configuration Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.
19questions here
4free pages
6concepts
30%of the exam
Questions 6–10
- 6
A company has a requirement to forward all traffic logs to a SIEM for long-term storage, but only forward threat logs with 'critical' severity to a separate email distribution list for immediate alerting. The administrator has created a Log Forwarding profile. What is the MOST efficient configuration to meet this requirement?
Select an answer first - 7
A firewall administrator is troubleshooting why logs are not being forwarded to a syslog server. The Log Forwarding profile is correctly configured and applied to the security policy rule. The syslog server is reachable from the firewall's management interface. The administrator checks the syslog server profile and notices that the 'Facility' is set to 'LOG_USER' and the 'Severity' is set to 'LOG_INFO'. What is the MOST likely reason logs are not being received?
Select an answer first - 8
An administrator has configured a Log Forwarding profile to send traffic logs to a syslog server. After applying the profile to a rule and generating traffic, the syslog server receives logs, but the logs are missing the application name and user information. What is the MOST likely cause?
Select an answer first - 9
A security team needs to receive email alerts for high-severity threat logs and also forward all traffic logs to a central syslog server. They have created a Log Forwarding profile. How should they configure the profile to meet BOTH requirements?
Select an answer first - 10
A security team is verifying that a Log Forwarding profile is working correctly. They have generated test traffic that should trigger a threat log and a URL filtering log. The syslog server receives the URL filtering log but NOT the threat log. The Log Forwarding profile has both Threat and URL Filtering log types configured with the same syslog destination. What is the MOST likely cause of the missing threat log?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.