PCNSA Decryption and Monitoring Practice Question
A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?
⚠ Common exam trap
The trap here is assuming a dedicated Decryption log exists, when decryption details are actually recorded within the Traffic log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic log
The Traffic log is the primary session log on Palo Alto Networks firewalls and includes user identification, URLs, applications, and policy rule matches. For decrypted HTTPS sessions, it shows the URL and the decryption policy rule, enabling administrators to review user access to decrypted sites. Other log types serve different purposes and do not provide this combined session view.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decryption log
Why it's wrong here
Palo Alto Networks firewalls do not have a separate Decryption log type. Decryption-related information, such as the decryption policy rule and certificate details, is included in the Traffic log. Looking for a standalone Decryption log would send the administrator to a nonexistent log, delaying the investigation.
- ✗
Configuration log
Why it's wrong here
The Configuration log records changes made to the firewall's configuration by administrators, such as policy edits or commits. It does not contain session-level data about user web browsing or decrypted traffic. Consulting it would not reveal which users accessed which HTTPS sites or which decryption rules applied.
- ✗
Threat log
Why it's wrong here
The Threat log records security events such as viruses, spyware, vulnerabilities, and URL filtering actions that match a security profile. It does not provide a comprehensive session-level view of which users accessed which decrypted sites. While it may show a URL filtering block, it lacks the full session context needed for this review.
- ✓
Traffic log
Why this is correct
The Traffic log records sessions passing through the firewall, including source user, source and destination IP addresses, destination URL when available, application, and the security policy rule that allowed or denied the session. For decrypted HTTPS traffic, the URL and decryption policy information are visible in the Traffic log, making it the appropriate place to review user access to decrypted sites.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.