Courseiva
easyMultiple Choice

PCNSA Practice Question: A junior administrator is investigating a network…

A junior administrator is investigating a network issue where traffic to a critical server is being blocked. To see the specific security rule that matched and the action taken, which log should the administrator review?

⚠ Common exam trap

Many exam-takers confuse the Threat log with the Traffic log, assuming blocked traffic always appears in the Threat log, but the Threat log only records sessions that matched a threat signature, not all denied sessions due to security rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic log

The Traffic log records every session that traverses the firewall, including the specific security rule that matched and the action taken (allow, deny, drop, etc.). Since the administrator needs to identify which rule blocked the traffic to the critical server, the Traffic log is the correct source. System, Threat, and Config logs do not provide per-session rule matching details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    System log

    Why it's wrong here

    System logs capture device health events such as reboots, HA state changes and daemon errors, not security policy enforcement decisions. They suit troubleshooting the firewall itself. The traffic log records the specific security rule that matched and the action taken.

  • ✗

    Threat log

    Why it's wrong here

    Threat logs record traffic matching security profiles, such as antivirus, anti-spyware and vulnerability signatures, not ordinary policy rule matches. They suit investigating detected exploits. The traffic log shows which security rule matched and the resulting action.

  • ✗

    Config log

    Why it's wrong here

    Config logs record administrative changes to the firewall's configuration, such as commits and policy edits, not per-session traffic decisions. Reviewing them suits auditing who altered a rule. The traffic log records the matched security rule and its action for each session.

  • ✓

    Traffic log

    Why this is correct

    The traffic log records each session's matched security rule and the resulting action, such as allow or deny, giving the administrator the exact rule blocking traffic to the critical server. This directly satisfies the stem's need to identify the matching rule and action taken.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.