ExamGecko
Home / Palo Alto Networks / PCCSE / Practice Test 2
Ask Question

Palo Alto Networks PCCSE Practice Test 2

00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

The Unusual protocol activity (Internal) network anomaly is generating too many alerts. An administrator has been asked to tune it to the option that will generate the least number of events without disabling it entirely.

Which strategy should the administrator use to achieve this goal?

Disable the policy
Disable the policy
Set the Alert Disposition to Conservative
Set the Alert Disposition to Conservative
Change the Training Threshold to Low
Change the Training Threshold to Low
Set Alert Disposition to Aggressive
Set Alert Disposition to Aggressive
Comment (0)
Suggested answer: B
Explanation:

To reduce the number of alerts generated by the 'Unusual protocol activity (Internal)' network anomaly without entirely disabling the policy, setting the Alert Disposition to Conservative (option B) is the most effective strategy. This configuration adjusts the sensitivity of the anomaly detection, reducing the likelihood of false positives and minimizing alert fatigue without compromising the ability to detect genuine security threats. By adopting a more conservative approach to anomaly detection, the administrator can ensure that only the most significant and potentially harmful activities trigger alerts, thus maintaining a balance between security vigilance and operational efficiency.

asked 23/09/2024
Med Amine Aloui
31 questions