Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard

A security auditor requires that all changes made to the firewall configuration, including who made them and when, are logged and immutable. Which feature on the Palo Alto Networks firewall ensures the integrity and auditability of configuration changes?

  1. ACommit History
  2. BAudit Comment
  3. CAdmin Activity Log
  4. DConfig Log
Show answer & explanation

Correct answer: D. Config Log

The Config Log (or Configuration Log) specifically records every configuration change made to the firewall, including the administrator, timestamp, and the exact change. This log is immutable and provides a clear audit trail, directly addressing the auditor's requirement for integrity and auditability.

Why the other options are wrong

  • A. Commit History shows who committed a configuration and provides options to revert, but the Config Log provides the granular, immutable detail of *each change*.
  • B. Audit Comment is a field filled during a commit, providing context, but it's not the log itself that ensures integrity and auditability of the *changes*.
  • C. Admin Activity Log tracks administrative actions (login, logout, commit), but not the detailed 'what changed' information.

Config Log (Configuration Log)

The Config Log on a Palo Alto Networks firewall is an immutable log that records every configuration change, including the administrator who made the change, the timestamp, and the specific parameters that were modified, providing a critical audit trail.

  • Records all configuration changes.
  • Includes admin, timestamp, and exact changes.
  • Immutable and essential for auditability.

Memory trick: The 'Config Log' is the firewall's permanent diary of every change.

More Deploy and Configure questions