Courseiva
Decryption and Monitoring →mediumMultiple Choice

PCNSA Decryption and Monitoring Practice Question

A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?

⚠ Common exam trap

The trap here is assuming that the Traffic log alone can confirm decryption, when actual decryption status and URL-level detail are recorded in the Decryption log.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Decryption log with the 'Decryption Status' field and URL details

The Decryption log is the authoritative source for verifying SSL/TLS decryption. It records the decryption policy match, the decryption status of each session, and associated URL or host details, allowing an administrator to confirm that outbound web traffic is being decrypted and to see the specific URLs involved. Other log types either record security events, system events, or session termination reasons and do not provide per-session decryption confirmation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Traffic log with the 'Session End Reason' field filtered for 'decrypt'

    Why it's wrong here

    The Traffic log's Session End Reason indicates why a session ended, such as tcp-fin or aged-out, and does not indicate whether decryption occurred or which policy applied. Filtering on 'decrypt' in this field would not isolate decrypted sessions. The correct way to verify decryption status is the Decryption log, which records the decryption policy result, not the session end reason.

  • ✗

    Threat log filtered by 'ssl-decryption' threat ID

    Why it's wrong here

    The Threat log records security events such as vulnerabilities, spyware, and URL filtering actions, not the decryption status of benign sessions. Even when decryption is enabled, only threats detected in decrypted traffic would appear here, so the administrator could not confirm that decryption occurred for normal web traffic. This log does not provide the per-session decryption status or URL-level confirmation needed.

  • ✗

    System log filtered by subtype 'ssl-decrypt'

    Why it's wrong here

    System logs capture control-plane events such as commits, HA transitions, and daemon restarts. They do not enumerate individual decrypted sessions or report per-flow decryption status. While some decryption-related errors may appear in system logs, this log type cannot confirm that specific outbound web sessions were decrypted or identify the URLs involved, so it does not meet the requirement.

  • ✓

    Decryption log with the 'Decryption Status' field and URL details

    Why this is correct

    The Decryption log is specifically designed to record SSL/TLS decryption activity, including whether sessions were decrypted, the decryption policy that matched, and the affected URL or host. Filtering on Decryption Status lets the administrator confirm successful decryption and see which URLs were decrypted, which directly answers the requirement to verify actual decryption and identify decrypted URLs.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.