ExamGecko
Question list
Search
Search

Question 340 - PCNSA discussion

Report
Export

What is the best-practice approach to logging traffic that traverses the firewall?

A.
Enable both log at session start and log at session end.
Answers
A.
Enable both log at session start and log at session end.
B.
Enable log at session start only.
Answers
B.
Enable log at session start only.
C.
Enable log at session end only.
Answers
C.
Enable log at session end only.
D.
Disable all logging options.
Answers
D.
Disable all logging options.
Suggested answer: C

Explanation:

The best-practice approach to logging traffic that traverses the firewall is to enable log at session end only. This option allows the firewall to generate a log entry only when a session ends, which reduces the load on the firewall and the log storage. The log entry contains information such as the source and destination IP addresses, ports, zones, application, user, bytes, packets, and duration of the session.The log at session end option also provides more accurate information about the session, such as the final application and user, the total bytes and packets, and the session end reason1. To enable log at session end only, you need to:

Create or modify a Security policy rule that matches the traffic that you want to log.

Select the Actions tab in the policy rule and check the Log at Session End option.

Commit the changes to the firewall or Panorama and the managed firewalls.

asked 23/09/2024
Calin-Alin Stoenescu
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first