Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A network administrator needs to generate a report that shows all traffic sessions that were explicitly denied by security policy rules, including the rule name that blocked the traffic. Which log type and column in the Palo Alto Networks firewall should the administrator focus on?

  1. ATraffic logs, 'Action' and 'Rule' columns
  2. BThreat logs, 'Action' column
  3. CData Filtering logs, 'File Name' column
  4. DURL Filtering logs, 'Category' column
Show answer & explanation

Correct answer: A. Traffic logs, 'Action' and 'Rule' columns

Traffic logs record all sessions processed by the firewall, including those denied by security policy. The 'Action' column will show 'deny' and the 'Rule' column will specify which security policy rule was responsible for that action.

Why the other options are wrong

  • B. Threat logs record security threats (viruses, spyware, etc.), not explicitly denied traffic by security policy rules.
  • C. Data Filtering logs record attempts to transfer sensitive data, not general denied traffic by security policies.
  • D. URL Filtering logs record web access based on URL categories, not general traffic denials by security policy rules.

Palo Alto Networks Traffic Logs

Records details of all sessions processed by the firewall, including allowed, denied, and dropped traffic, providing comprehensive visibility into network activity.

  • Contains source/destination IP, port, application, user, action, and rule name.
  • Essential for troubleshooting connectivity and policy enforcement.
  • Can be filtered and used for reporting on various traffic patterns.

Memory trick: Traffic logs show the whole journey, including the stop sign.

More Manage and Operate questions