Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy

A security analyst is reviewing traffic logs on a Palo Alto Networks firewall and observes a high volume of 'incomplete' and 'aged-out' sessions. These sessions are consuming resources but never reaching a 'close' state. Which logging concept describes the comprehensive record of network connections and their states that the firewall maintains?

  1. ASystem Logs
  2. BConfiguration Logs
  3. CThreat Logs
  4. DTraffic Logs
Show answer & explanation

Correct answer: D. Traffic Logs

Traffic logs (also known as session logs) provide a detailed record of all network connections processed by the firewall, including their source, destination, application, service, and most importantly, their session state (e.g., 'active', 'incomplete', 'aged-out', 'close'). This is precisely what the security analyst is observing to understand session behavior.

Why the other options are wrong

  • A. System logs record events related to the firewall's operating system and hardware, not network connections.
  • B. Configuration logs track changes made to the firewall's configuration, not network traffic.
  • C. Threat logs record security events where a threat profile (e.g., antivirus, vulnerability protection) has detected malicious activity, not general connection states.

Palo Alto Networks Traffic Logs

Traffic logs (or session logs) on a Palo Alto Networks firewall record detailed information about all network connections, including source/destination, application, service, and the session's lifecycle state.

  • Records all network connections.
  • Includes session state (e.g., incomplete, aged-out, close).
  • Crucial for network monitoring and troubleshooting.

Memory trick: Traffic is the stream of connections; other logs are specific events.

More Core Concepts questions