問題文
An analyst sees that a Log Forwarding profile contains an action that adds a tag to the source address of a matching log entry. What is that arrangement for?
選択肢
- It lets policy react to observed behavior, because a dynamic address group that selects the tag will then include the host without any configuration change.
- It forwards the entry a second time to a different destination, which is how the same log can be delivered both to the central store and to an external collector without duplicating the match list entry.
- It renames the log entry so that it can be found more easily in the log viewer, and the tag is removed when the entry ages out of the store, leaving the viewer tidy.
- It changes the severity of the threat entry so that the same behavior is escalated the next time it is seen.