A firewall administrator wants to avoid overflowing the company syslog server with traffic logs. What should the administrator do to prevent the forwarding of DNS traffic logs to syslog?
A.
Disable logging on security rules allowing DNS.
B.
Go to the Log Forwarding profile used to forward traffic logs to syslog. Then, under traffic logs match list, create a new filter with application not equal to DNS.
C.
Go to the Log Forwarding profile used to forward traffic logs to syslog. Then, under traffic logs match list, create a new filter with application equal to DNS.
D.
Create a security rule to deny DNS traffic with the syslog server in the destination.
B is correct, as I have tested it in my Lab, when I was using the eq to DNS filter I could still see that DNS traffic logs were forwarded but when using not equal to DNS the DNS-related traffic was non existed to be forwarded
Im ok with B, but why not A?
If i have a policy rule for DNS traffic, I just have to put log forwarding option as "none" to avoid sending that logs right?
Option B
Create a new log forwarding profile which forwards logs only to Syslog device. Create a specific security policy for DNS traffic
https://live.paloaltonetworks.com/t5/general-topics/how-to-stop-dns-traffic-logs-going-to-log-collector/td-p/290425
This section is not available anymore. Please use the main Exam Page.PCNSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
millosz222
Highly Voted 2 years, 1 month agoJRKhan
Most Recent 9 months, 3 weeks agoMetgatz
10 months, 2 weeks agoplaythegamewithme
1 year, 4 months ago[Removed]
1 year, 6 months agosujss
1 year, 6 months agoawtsuritacuna
1 year, 11 months agoconfusion
1 year, 11 months agoguilhermeandrade
2 years ago