Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 17 Discussion

A firewall administrator implementing Palo Alto Networks best practices on the company firewall reviews NGFW alerts in Strata Cloud Manager (SCM) and determines that one alert does not apply to this environment. If the administrator has no intention to resolve the underlying issue, what is the appropriate next step?
D) Open the NGFW alert and click ''Suppress'' under ''Actions.''
A) Click ''Copilot'' in the top right, and ask the Copilot to make an exception for the NGFW alert.
B) Assign the NGFW alert to the ''Dismiss'' user.
C) Change the NGFW alert priority to ''Not Set.''

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 17 Discussion

Actual exam question for Palo Alto Networks's NetSec-Analyst exam
Question #: 17
Topic #: 4
[All NetSec-Analyst Questions]

A firewall administrator implementing Palo Alto Networks best practices on the company firewall reviews NGFW alerts in Strata Cloud Manager (SCM) and determines that one alert does not apply to this environment. If the administrator has no intention to resolve the underlying issue, what is the appropriate next step?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:

Within the Strata Cloud Manager (SCM) interface, managing the lifecycle of incidents and alerts is a core responsibility. When an administrator encounters an NGFW alert that is deemed irrelevant or inapplicable to their specific environment, SCM provides a mechanism to silence that alert to reduce 'alert fatigue' and keep the dashboard focused on actionable items.

The appropriate action in this scenario is to Open the NGFW alert and click ''Suppress'' under ''Actions''. Suppression allows the administrator to mute specific incidents or alerts that they do not intend to remediate, effectively acknowledging the risk but choosing to ignore it in the reporting and notification workflows. This is often used for non-critical alerts or during maintenance windows. Unlike dismissing or changing priorities, Suppression is a formal administrative action within the SCM incident framework that can be granularly controlled, allowing for custom raise and clear conditions to be overridden based on the organization's unique operational needs. This ensures that the 'Health Score' or 'Security Posture' metrics are not unfairly penalized by known, accepted environmental conditions.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel