Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationEasy
A security engineer is configuring a security policy rule to allow outbound HTTP/HTTPS traffic from the internal network to the internet. The company requires that all traffic matching this rule be logged at the start and end of each session for auditing purposes. Which logging option should be selected in the security policy rule configuration?
- ALog at Session End
- BNo logging
- CLog at Session Start and End
- DLog at Session Start
Show answer & explanationAnswer & explanation
Correct answer: C. Log at Session Start and End
To meet the requirement of logging at both the start and end of each session for auditing, the 'Log at Session Start and End' option is the most direct and complete choice.
Why the other options are wrong
- A. Only logs at the end, missing the start event.
- B. This would disable all logging for the rule, directly contradicting the requirement.
- D. Only logs at the start, missing the end event.
Security Policy Logging Options
Palo Alto Networks security policies offer various logging options to record session events for monitoring, auditing, and troubleshooting.
- Log at Session Start: Records when a session begins.
- Log at Session End: Records when a session terminates.
- Log at Session Start and End: Records both start and end events.
- No logging: Disables logging for the rule.
Memory trick: Logging is like a timecard: you can punch in, punch out, or both, to track your work session.