Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security auditor requires detailed logging of all denied traffic, specifically for rules that block access to known malicious IPs and URLs. The auditor wants to see the source IP, destination IP, application, and the specific security profile that caused the denial. How should the logging options for these security policy rules be configured to meet this requirement?

  1. ADisable both 'Log at Session Start' and 'Log at Session End' and rely on Threat Logs.
  2. BEnable both 'Log at Session Start' and 'Log at Session End'.
  3. CSet 'Log at Session Start' and disable 'Log at Session End'.
  4. DSet 'Log at Session End' and disable 'Log at Session Start'.
Show answer & explanation

Correct answer: D. Set 'Log at Session End' and disable 'Log at Session Start'.

For 'deny' rules, 'Log at Session End' is typically sufficient and often preferred. When a session is denied, it's usually denied at the start. Logging at session end ensures that all relevant session details, including application and security profile information (which might be determined mid-session for allowed traffic), are captured. For denied traffic, the session ends almost immediately, so logging at the end captures the denial event and associated details.

Why the other options are wrong

  • A. Disabling both would prevent any policy-based logs for denied traffic, which fails to meet the auditor's requirement for detailed logging of denied access. Threat logs capture specific threat events, but policy logs provide context of the rule itself.
  • B. Enabling both is redundant for a denied session, as the session is terminated almost immediately. It generates two logs for a single denial event and is generally used for allowed sessions to track activity throughout their lifetime.
  • C. Logging at session start for a deny rule will capture the initial packet information, but 'Log at Session End' is more comprehensive for capturing the final state and reasons for denial, including security profile actions.

Security Policy Logging Options

Palo Alto Networks security policy rules offer logging options ('Log at Session Start', 'Log at Session End') to control when session information is recorded. 'Log at Session End' is generally recommended for deny rules to capture the complete denial event.

  • Log at Session Start: Records when session begins.
  • Log at Session End: Records when session terminates, often more comprehensive.
  • For deny rules, Session End logging captures the denial event and details.

Memory trick: Deny's End, Details Attend.

More Security Policy Configuration questions