A team needs to validate who changed an entitlement and whether the change succeeded, and then correlate the activity with broader events.
Which audit source best supports this review before adding SIEM context?
A.
DLP event dashboards, because data-movement visualizations can uncover configuration edits through exposure trend shifts
B.
Firewall Insights, because network-layer telemetry can expose configuration changes through connection-state deviations
C.
Web Insights, because application traffic views can infer administrative behavior through session lineage and path analysis
D.
ZIdentity or Administrator Management audit logs, because they record administrator actions with the actor, timestamp, target, and outcome for direct attribution
Option D provides direct administrative evidence rather than an inference from user traffic. Zscaler’s ZPA Audit Logs documentation states that audit logs display administrator sign-in and sign-out attempts, actions, request IDs, and completed configuration changes. Those records establish who performed an entitlement-related action, when it occurred, and what operation was attempted or completed. The relevant audit entry should be validated first and then correlated with identity, endpoint, and security events in the SIEM using its timestamp and request or transaction identifiers. DLP dashboards describe sensitive-data events; Firewall Insights describes network sessions and policy activity; and Web Insights describes web transactions. None is authoritative for attributing an administrator’s configuration change. Audit logs therefore supply the defensible source record before broader SIEM correlation.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit