Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy

A security team needs to monitor attempts to access known malicious websites categorized as 'phishing' or 'malware' by the firewall's URL filtering. They want to see the source IP, destination URL, and the user involved. Which log type should they analyze?

  1. AThreat Logs
  2. BTraffic Logs
  3. CAuthentication Logs
  4. DURL Filtering Logs
Show answer & explanation

Correct answer: D. URL Filtering Logs

URL Filtering logs specifically record web access attempts, the URL category matched, and actions taken (allow/block) based on URL filtering profiles. This is the precise log type for monitoring access to categorized websites.

Why the other options are wrong

  • A. Threat logs record detected malware or exploits, not general access to categorized URLs.
  • B. Traffic logs show session data but don't specifically highlight URL categories or actions from URL filtering profiles as the primary focus.
  • C. Authentication logs track user login/logout events, unrelated to web content access.

URL Filtering Logs

URL Filtering logs on a Palo Alto Networks firewall record attempts to access web pages, showing the URL, its category, the user, source/destination IPs, and the action taken (allow, block, alert) by the URL Filtering profile.

  • Generated when a URL Filtering profile is applied to a security rule.
  • Essential for monitoring web usage and enforcing web access policies.
  • Provides granular visibility into web traffic based on categories.

Memory trick: Each log type tells a different story about your network's life.

More Monitoring and Reporting questions