Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy

A security auditor requests a weekly report detailing all successful and failed authentication attempts for all users. Which type of log should be primarily used to generate this custom report?

  1. ASystem Logs
  2. BTraffic Logs
  3. CAuthentication Logs
  4. DURL Filtering Logs
Show answer & explanation

Correct answer: C. Authentication Logs

Authentication logs specifically record events related to user authentication, including successful and failed attempts, which directly addresses the auditor's request.

Why the other options are wrong

  • A. System logs record firewall operational events, not user authentication attempts.
  • B. Traffic logs record network sessions, not the authentication process itself.
  • D. URL filtering logs track web access based on categories, unrelated to user authentication.

Authentication Logs

Authentication logs on a Palo Alto Networks firewall record events related to user authentication, such as successful logins, failed attempts, and logout events, providing an audit trail for user access.

  • Crucial for auditing user access and identifying potential brute-force attacks.
  • Records username, source IP, authentication method, and result.
  • Found under Monitor > Logs > Authentication.

Memory trick: Each log type tells a different story about your network's life.

More Monitoring and Reporting questions