PCNSA Decryption and Monitoring Practice Question
A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?
⚠ Common exam trap
The trap here is assuming that a dedicated decryption log exists, when in fact decryption details are integrated into the traffic log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic log
The traffic log is the central log for all sessions and includes application identification, even for decrypted traffic. After SSL decryption, the firewall can identify the application and log it in the traffic log. Other logs like threat or URL filtering are specialized and do not provide a complete view of application usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat log
Why it's wrong here
The threat log records security events such as viruses, spyware, and vulnerability exploits. While decrypted traffic can generate threat logs if malicious content is detected, it does not provide a comprehensive view of all applications in use. The traffic log is the correct place to see application details for all sessions, decrypted or not.
- ✓
Traffic log
Why this is correct
The traffic log records all sessions, including those that are decrypted. After decryption, the firewall can identify the application (e.g., Facebook, Gmail) and log it in the traffic log. The traffic log also shows the decryption status (e.g., decrypted, no-decrypt) and any associated threats if further inspection is done. This is the primary log for monitoring application usage.
- ✗
URL filtering log
Why it's wrong here
The URL filtering log records URL categories and actions taken by URL filtering profiles. It does not show application details for decrypted traffic. While it can indicate which websites were visited, it does not provide the granular application identification that the traffic log offers.
- ✗
Decryption log
Why it's wrong here
There is no separate 'decryption log' in Palo Alto Networks firewalls. Decryption events are logged within the traffic log, which includes fields for decryption status and error messages. The administrator should use the traffic log to monitor decrypted sessions and application details.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.