Palo Alto Networks Certified Network Security Administrator (PCNSA)Monitoring and ReportingEasy
A security analyst is reviewing firewall logs and needs to quickly identify all sessions that were denied due to a security policy rule. Which log type should the analyst primarily examine?
- ASystem Logs
- BThreat Logs
- CTraffic Logs
- DURL Filtering Logs
Show answer & explanationAnswer & explanation
Correct answer: C. Traffic Logs
Traffic logs record all connection attempts and their outcomes, including sessions that were denied by security policies. This log type provides the necessary details to identify denied sessions.
Why the other options are wrong
- A. System logs record firewall operational events, not individual session outcomes.
- B. Threat logs focus on detected threats and vulnerabilities, not policy-based denials.
- D. URL Filtering logs specifically detail actions taken by the URL filtering profile, not general security policy denials.
Traffic Logs
Traffic logs record all network sessions processed by the firewall, detailing source, destination, application, action, and bytes transferred.
- Captures allowed, denied, dropped, and reset sessions.
- Essential for monitoring network activity and security policy effectiveness.
- Includes information like application, user, zone, and security rule.
Memory trick: Each log type tells a different story about firewall activity.