Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy
A security analyst is reviewing traffic logs on a Palo Alto Networks firewall and observes a high volume of 'incomplete' and 'aged-out' sessions. These sessions are consuming resources but never reaching a 'close' state. Which logging concept describes the comprehensive record of network connections and their states that the firewall maintains?
- ASystem Logs
- BConfiguration Logs
- CThreat Logs
- DTraffic Logs
Show answer & explanationAnswer & explanation
Correct answer: D. Traffic Logs
Traffic logs (also known as session logs) provide a detailed record of all network connections processed by the firewall, including their source, destination, application, service, and most importantly, their session state (e.g., 'active', 'incomplete', 'aged-out', 'close'). This is precisely what the security analyst is observing to understand session behavior.
Why the other options are wrong
- A. System logs record events related to the firewall's operating system and hardware, not network connections.
- B. Configuration logs track changes made to the firewall's configuration, not network traffic.
- C. Threat logs record security events where a threat profile (e.g., antivirus, vulnerability protection) has detected malicious activity, not general connection states.
Palo Alto Networks Traffic Logs
Traffic logs (or session logs) on a Palo Alto Networks firewall record detailed information about all network connections, including source/destination, application, service, and the session's lifecycle state.
- Records all network connections.
- Includes session state (e.g., incomplete, aged-out, close).
- Crucial for network monitoring and troubleshooting.
Memory trick: Traffic is the stream of connections; other logs are specific events.