Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingMedium

A security analyst needs to create a custom report that shows all blocked traffic from external IP addresses to internal servers over the last 30 days, grouped by destination IP. Which log type should be used as the basis for this report?

  1. AURL Filtering Logs
  2. BSystem Logs
  3. CTraffic Logs
  4. DThreat Logs
Show answer & explanation

Correct answer: C. Traffic Logs

Traffic logs record all sessions processed by the firewall, including those that are allowed or denied. To report on blocked traffic, the traffic logs are the appropriate source, filtering for 'Action: deny'.

Why the other options are wrong

  • A. URL Filtering logs record web access based on URL categories, not all blocked external-to-internal traffic.
  • B. System logs record events related to the firewall's operation (e.g., reboots, configuration changes), not network traffic.
  • D. Threat logs specifically record detected threats (viruses, spyware, vulnerabilities), not general blocked traffic.

Traffic Logs

Traffic logs on a Palo Alto Networks firewall record details about all network sessions that traverse the device, including allowed and denied connections, source/destination information, and application usage.

  • Crucial for understanding network flow and security policy enforcement.
  • Contains 'Action' field indicating allow, deny, drop, etc.
  • Used for bandwidth analysis, connectivity troubleshooting, and security audits.

Memory trick: Each log type tells a different story about your network's life.

More Monitoring and Reporting questions