Exit PSE-HARDWARE-FIREWAL Palo Alto Networks Systems Engineer Professional - Hardware Firewall
Question 5 of 5
0% complete
Q5 Single choice

There are no Advanced Threat Prevention log events in a company's SIEM instance. However, the systems administrator has confirmed that the Advanced Threat Prevention subscription is licensed and that threat events are visible in the threat logs on the firewall.

Which action should the systems administrator take next?

  • A

    Enable the company's Threat Prevention license.

  • B

    Check with the SIEM vendor to verify that Advanced Threat Prevention logs are reaching the
    company's SIEM instance.

  • C

    Have the SIEM vendor troubleshoot its software.

  • D

    Ensure the Security policy rules that use Advanced Threat Prevention are set for log forwarding to the correct SIEM.