Question 1
A financial services firm is deploying Prisma Access managed by Strata Cloud Manager. For compliance reasons, they must log all DNS queries made by mobile users to an on-premises SIEM. The current configuration forwards all other traffic logs to the Strata Logging Service. Which configuration change is required to selectively forward only the DNS logs to the on-premises SIEM while maintaining other logging functions?
Answer and explanation
Correct answer: B
When using the Strata Logging Service, log forwarding is configured centrally within the SCM settings, not via security policy rules like in Panorama. The correct method is to navigate to the logging service configuration, create a specific rule for the desired log type (DNS), and direct it to the appropriate external destination (the SIEM). The other options describe methods used in Panorama-managed firewalls or are conceptually incorrect.