Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A company has recently deployed a new internal application server. Due to compliance requirements, all traffic to and from this server must be logged extensively, including URL information and threat details, even if the traffic is allowed. Which security policy rule setting should be configured to ensure comprehensive logging for this specific server's traffic?

  1. ASet 'Log at Session Start' and 'Log at Session End' to Yes for the relevant security rule.
  2. BEnable 'Log Forwarding' for the security rule and configure a Syslog server.
  3. CApply a Data Filtering Profile to the security rule and enable logging within the profile.
  4. DEnable 'Security Profiles' for the rule and ensure logging is enabled within each attached profile (e.g., URL Filtering, Threat Prevention).
Show answer & explanation

Correct answer: D. Enable 'Security Profiles' for the rule and ensure logging is enabled within each attached profile (e.g., URL Filtering, Threat Prevention).

To log URL information and threat details, the relevant Security Profiles (URL Filtering, Threat Prevention, Antivirus, etc.) must be applied to the security rule. These profiles contain their own logging settings, which, when enabled, will generate detailed logs specific to their functions. Simply setting 'Log at Session Start/End' only logs basic session information, not the detailed threat or URL data.

Why the other options are wrong

  • A. This only logs basic session start/end events, not the granular URL or threat information required.
  • B. Log Forwarding sends logs to external systems, but it doesn't *generate* the detailed URL or threat logs itself if the underlying profiles aren't configured to do so.
  • C. Data Filtering Profile logs sensitive data patterns, not general URL information or threat details.

Security Profile Logging

Palo Alto Networks Security Profiles (Threat Prevention, URL Filtering, etc.) have their own logging settings that must be enabled to generate detailed logs related to their specific inspection functions.

  • Basic session logging is controlled by 'Log at Session Start/End' on the security rule.
  • Detailed threat logs are generated by the Threat Prevention profile.
  • Detailed URL logs are generated by the URL Filtering profile.
  • These profiles must be attached to the security rule, and their internal logging enabled, for comprehensive data.

Memory trick: Logging: Rule for session, profiles for detail, forward for storage, visibility's the prize.

More Security Policy Configuration questions