Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 13 Discussion

Which log type is the most useful for identifying if a user is repeatedly attempting to visit an "Unauthorized" website category that is being blocked by a security profile?
B) URL Filtering Log
A) Traffic Log
C) System Log
D) Authentication Log

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 13 Discussion

Actual exam question for Palo Alto Networks's NetSec-Analyst exam
Question #: 13
Topic #: 4
[All NetSec-Analyst Questions]

Which log type is the most useful for identifying if a user is repeatedly attempting to visit an "Unauthorized" website category that is being blocked by a security profile?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:

While Traffic Logs show that a connection was denied, the URL Filtering Log provides the specific context required to understand why it was denied. It explicitly lists the URL being visited, the specific URL category (e.g., adult or gambling), and the action taken by the profile.

For a Network Security Analyst, monitoring this log is a core objective for identifying potential 'insider threats' or users who require additional security training. If a host is generating hundreds of 'block' entries for high-risk categories in a short period, it could indicate that the device is infected with malware that is attempting to 'call home' to a malicious site or that a user is actively trying to bypass security controls.


Contribute your Thoughts:

0/2000 characters
Bette
14 hours ago
I feel B) is definitely more focused on unauthorized sites.
upvoted 0 times
...
Portia
6 days ago
A) Traffic Log could work too, but not as specific.
upvoted 0 times
...
Rosita
11 days ago
Agreed! It shows blocked attempts clearly.
upvoted 0 times
...
Elin
16 days ago
I think B) URL Filtering Log is the best choice.
upvoted 0 times
...
Myra
21 days ago
Really? I didn't know URL Filtering Log was that specific!
upvoted 0 times
...
Flo
26 days ago
I thought C) System Log might help, but I guess not?
upvoted 0 times
...
Lucy
1 month ago
Wait, are we sure it’s not A) Traffic Log? Seems like it could work too.
upvoted 0 times
...
Kanisha
1 month ago
I agree, URL Filtering Log is the way to go!
upvoted 0 times
...
Ashlee
1 month ago
Definitely B) URL Filtering Log. That's the one for blocked sites.
upvoted 0 times
...
Glennis
2 months ago
I’m leaning towards the URL Filtering Log too, but I wonder if the Traffic Log could provide some insights as well.
upvoted 0 times
...
Margo
2 months ago
I feel like the Authentication Log is more about user logins, so it probably wouldn’t help with this scenario.
upvoted 0 times
...
Abel
2 months ago
I remember practicing a question like this, and I think the Traffic Log could also show attempts, but it wouldn't specify if they were unauthorized.
upvoted 0 times
...
Daren
2 months ago
I think the URL Filtering Log might be the right choice since it deals with blocked websites, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel