Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 17 Discussion

A firewall administrator implementing Palo Alto Networks best practices on the company firewall reviews NGFW alerts in Strata Cloud Manager (SCM) and determines that one alert does not apply to this environment. If the administrator has no intention to resolve the underlying issue, what is the appropriate next step?
D) Open the NGFW alert and click ''Suppress'' under ''Actions.''
A) Click ''Copilot'' in the top right, and ask the Copilot to make an exception for the NGFW alert.
B) Assign the NGFW alert to the ''Dismiss'' user.
C) Change the NGFW alert priority to ''Not Set.''

Palo Alto Networks NetSec-Analyst Exam - Topic 4 Question 17 Discussion

Actual exam question for Palo Alto Networks's NetSec-Analyst exam
Question #: 17
Topic #: 4
[All NetSec-Analyst Questions]

A firewall administrator implementing Palo Alto Networks best practices on the company firewall reviews NGFW alerts in Strata Cloud Manager (SCM) and determines that one alert does not apply to this environment. If the administrator has no intention to resolve the underlying issue, what is the appropriate next step?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:

Within the Strata Cloud Manager (SCM) interface, managing the lifecycle of incidents and alerts is a core responsibility. When an administrator encounters an NGFW alert that is deemed irrelevant or inapplicable to their specific environment, SCM provides a mechanism to silence that alert to reduce 'alert fatigue' and keep the dashboard focused on actionable items.

The appropriate action in this scenario is to Open the NGFW alert and click ''Suppress'' under ''Actions''. Suppression allows the administrator to mute specific incidents or alerts that they do not intend to remediate, effectively acknowledging the risk but choosing to ignore it in the reporting and notification workflows. This is often used for non-critical alerts or during maintenance windows. Unlike dismissing or changing priorities, Suppression is a formal administrative action within the SCM incident framework that can be granularly controlled, allowing for custom raise and clear conditions to be overridden based on the organization's unique operational needs. This ensures that the 'Health Score' or 'Security Posture' metrics are not unfairly penalized by known, accepted environmental conditions.


Contribute your Thoughts:

0/2000 characters
Lauran
3 days ago
Dismiss sounds like a lazy move, though.
upvoted 0 times
...
Phyliss
8 days ago
I agree with D, it's a clean way to handle it.
upvoted 0 times
...
Leandro
13 days ago
Wait, can you really just suppress alerts like that?
upvoted 0 times
...
Eileen
19 days ago
Definitely not A, that seems risky!
upvoted 0 times
...
Kate
24 days ago
I think option D is the best choice here.
upvoted 0 times
...
Ma
29 days ago
I vaguely recall that dismissing alerts could lead to missing important issues later. Maybe we shouldn't do that?
upvoted 0 times
...
Kindra
1 month ago
I feel like changing the priority isn't really the best option. Suppressing seems more appropriate.
upvoted 0 times
...
Candra
1 month ago
I think we practiced a similar question where we had to suppress alerts. That might be the right answer.
upvoted 0 times
...
Patria
1 month ago
I remember something about dismissing alerts, but I'm not sure if that's the right approach here.
upvoted 0 times
...

Save Cancel