The traffic log shows a threat severity 'medium' and the threat log shows action 'allow' for the same session. What is the most likely reason that the threat was allowed?
Exhibit
Refer to the exhibit. Traffic Log: Time: 2024-07-15 10:00:00 Source: 10.1.1.10 Destination: 198.51.100.20 Application: web-browsing Action: allow Threat: High Severity: medium Threat Log: Time: 2024-07-15 10:00:00 Source: 10.1.1.10 Destination: 198.51.100.20 Threat ID: 12345 Action: allow
Trap 1: The action 'allow' in the threat log is misleading; the traffic was…
The log explicitly says action: allow.
Trap 2: The threat was not detected by the firewall.
It was detected as shown in the threat log.
Trap 3: The threat log does not record blocked threats.
Threat logs record both allowed and blocked threats.
- A
The security policy rule that matched this traffic is configured to allow the threat.
The profile for that rule likely has an 'allow' action for this threat.
- B
The action 'allow' in the threat log is misleading; the traffic was actually blocked.
Why wrong: The log explicitly says action: allow.
- C
The threat was not detected by the firewall.
Why wrong: It was detected as shown in the threat log.
- D
The threat log does not record blocked threats.
Why wrong: Threat logs record both allowed and blocked threats.