Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy

A company policy dictates that all attempts to access gambling websites must be blocked and logged. A security analyst needs to verify that the URL Filtering profile is correctly blocking these sites and that the corresponding log entries are being generated. Which log type would the analyst review to confirm this policy enforcement?

  1. ATraffic logs
  2. BAuthentication logs
  3. CSystem logs
  4. DURL Filtering logs
Show answer & explanation

Correct answer: D. URL Filtering logs

URL Filtering logs specifically record web access attempts, the URL category matched, and the action taken by the URL Filtering profile. This log type is the direct source for verifying the enforcement of URL filtering policies against categories like 'gambling'.

Why the other options are wrong

  • A. Traffic logs show general session information but not the specific URL category match or URL filtering action.
  • B. Authentication logs relate to user login events, not web browsing.
  • C. System logs record firewall operational events, not web access attempts.

URL Filtering Logs

URL Filtering logs record details about web access attempts, including the URL, its category, the URL Filtering profile action (block, allow, alert, continue), and the source user/IP.

  • Directly shows enforcement of URL filtering policies.
  • Includes the specific URL category that was matched.
  • Essential for auditing web usage and policy effectiveness.

Memory trick: To see 'URL' blocks, check the 'URL Filtering logs' directly!

More Monitoring and Reporting questions