Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A security analyst is investigating a performance degradation issue on a Palo Alto Networks firewall. The firewall is configured with SSL Forward Proxy decryption for outbound traffic. They suspect that specific applications, known to have issues with decryption, might be contributing to the problem. To confirm this, which log type should the analyst primarily review to identify sessions that are failing or bypassing decryption?
- AThreat logs
- BTraffic logs
- CURL Filtering logs
- DDecryption logs
Show answer & explanationAnswer & explanation
Correct answer: D. Decryption logs
Decryption logs specifically record information about SSL/TLS decryption events, including sessions that successfully decrypted, failed decryption, or were excluded/bypassed from decryption. This log type is essential for troubleshooting and monitoring the decryption process and identifying applications that are causing issues.
Why the other options are wrong
- A. Threat logs focus on detected threats, not decryption status.
- B. Traffic logs show session details but don't specifically detail decryption status or failures.
- C. URL Filtering logs show web access based on URL categories, not decryption specific failures.
Decryption Logs
Decryption logs in Palo Alto Networks firewalls provide detailed information about SSL/TLS decryption events, including successful decryption, decryption failures, and bypassed sessions.
- Crucial for monitoring the health and effectiveness of decryption policies.
- Helps identify applications or websites that cause decryption errors.
- Records reasons for decryption failures (e.g., unsupported cipher, certificate issues).
- Shows sessions explicitly excluded from decryption.
Memory trick: For decryption issues, the decryption log is your best clue.