Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsEasy
A security analyst is investigating a suspected malware infection originating from an internal host. The analyst needs to quickly identify all network connections established by this host, including the applications used, destination IP addresses, and the security policies that permitted the traffic. Which type of log on the Palo Alto Networks firewall would provide this comprehensive information?
- ATraffic Logs
- BConfiguration Logs
- CThreat Logs
- DSystem Logs
Show answer & explanationAnswer & explanation
Correct answer: A. Traffic Logs
Traffic logs record details about all network sessions processed by the firewall, including source/destination IP/port, application, user, and the security policy that allowed or denied the session, making them ideal for connection analysis.
Why the other options are wrong
- B. Configuration logs record changes made to the firewall's configuration, not network connections.
- C. Threat logs record detected security threats (e.g., viruses, exploits), but not all allowed network connections.
- D. System logs record events related to the firewall's operation, such as reboots or interface status changes, not network connections.
Traffic Logs
Records of all network sessions processed by the Palo Alto Networks firewall, detailing connection information, application usage, and security policy actions.
- Detailed session information
- Includes application, user, source/destination
- Records allow/deny policy actions
Memory trick: The firewall keeps many diaries, each for a different story.