Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateEasy

A network administrator needs to generate a report detailing all successful and failed user authentications to the firewall's management interface (via SSH, HTTPS, or console) over the last 24 hours. Which log type should the administrator query to gather this specific information?

  1. ASystem logs
  2. BConfiguration logs
  3. CTraffic logs
  4. DThreat logs
Show answer & explanation

Correct answer: A. System logs

System logs record events related to the firewall's operation, including administrative logins, high availability state changes, and other system-level activities. User authentication attempts to the management interface fall under system events.

Why the other options are wrong

  • B. Configuration logs track changes made to the firewall's configuration, not authentication attempts.
  • C. Traffic logs detail network sessions passing through the firewall, not management interface access.
  • D. Threat logs record security threats detected by the firewall, such as viruses or exploits.

Palo Alto Networks Log Types

Palo Alto Networks firewalls generate various log types to record different events, each serving a specific monitoring and auditing purpose.

  • Logs are crucial for troubleshooting and security auditing.
  • Each log type captures distinct event categories.
  • System logs track firewall operational events and administrative access.

Memory trick: Logs are like specialized diaries, each for a different story.

More Manage and Operate questions