Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy
A security auditor requests a weekly report detailing all successful and failed authentication attempts for all users. Which type of log should be primarily used to generate this custom report?
- ASystem Logs
- BTraffic Logs
- CAuthentication Logs
- DURL Filtering Logs
Show answer & explanationAnswer & explanation
Correct answer: C. Authentication Logs
Authentication logs specifically record events related to user authentication, including successful and failed attempts, which directly addresses the auditor's request.
Why the other options are wrong
- A. System logs record firewall operational events, not user authentication attempts.
- B. Traffic logs record network sessions, not the authentication process itself.
- D. URL filtering logs track web access based on categories, unrelated to user authentication.
Authentication Logs
Authentication logs on a Palo Alto Networks firewall record events related to user authentication, such as successful logins, failed attempts, and logout events, providing an audit trail for user access.
- Crucial for auditing user access and identifying potential brute-force attacks.
- Records username, source IP, authentication method, and result.
- Found under Monitor > Logs > Authentication.
Memory trick: Each log type tells a different story about your network's life.