Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy

A network administrator needs to generate a report showing the top 10 applications by session count that were blocked by the firewall in the last 7 days. Which log type should be used as the basis for this custom report?

  1. AURL Filtering logs
  2. BTraffic logs
  3. CThreat logs
  4. DAuthentication logs
Show answer & explanation

Correct answer: B. Traffic logs

Traffic logs record all sessions, including those that are blocked. To identify blocked applications by session count, Traffic logs are the appropriate source, as they contain the application name and the action taken (allow/deny/drop).

Why the other options are wrong

  • A. URL Filtering logs focus on web access categories, not all blocked applications.
  • C. Threat logs record detected threats, not general blocked application sessions.
  • D. Authentication logs track user logins, not blocked application traffic.

Traffic Logs for Blocked Sessions

Traffic logs in Palo Alto Networks firewalls record details for all network sessions, including the application identified and the action taken (allow, deny, drop, reset-client, reset-server, reset-both).

  • Contain 'action' field to determine if a session was blocked.
  • Include 'application' field for identifying the application.
  • Can be filtered and grouped to report on blocked applications by session count.

Memory trick: For 'blocked apps', check the 'traffic' flow to see what was 'denied'.

More Monitoring and Reporting questions