Courseiva

PCNSA Decryption and Monitoring Practice Question

A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?

⚠ Common exam trap

Candidates often confuse Traffic logs (which show a decryption flag) with Decryption logs (which provide the detailed reason), leading them to choose Traffic logs as the most detailed source when Decryption logs are the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Decryption logs

Decryption logs are specifically designed to record detailed information about SSL decryption actions, including whether traffic was decrypted, not decrypted, or bypassed, along with the exact reason (e.g., unsupported cipher, certificate mismatch, excluded category). This granularity is essential for monitoring decryption efficiency and troubleshooting decryption policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    System logs

    Why it's wrong here

    System logs record firewall management and daemon events such as commits and HA state, not per-session decryption verdicts. Decryption actions and no-decrypt reasons appear in the decryption log, which would be the correct choice when auditing which sessions were decrypted or bypassed.

  • ✓

    Decryption logs

    Why this is correct

    Decryption logs record each session's decryption outcome, including the specific reason a flow was not decrypted, such as unsupported cipher or exempted category. They provide the granular per-session detail needed to measure SSL decryption efficiency, unlike traffic or threat logs.

  • ✗

    Traffic logs

    Why it's wrong here

    Traffic logs capture session allow/deny decisions and application identification, but omit the specific decryption action and no-decrypt reason fields. Those details live in the decryption log, which would be the correct choice when measuring SSL decryption coverage and bypass causes.

  • ✗

    Threat logs

    Why it's wrong here

    Threat logs record sessions matching security profiles, such as antivirus or vulnerability signatures, after inspection. They do not enumerate decryption outcomes or the reason a flow was not decrypted; the decryption log is the correct source for that per-session detail.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.