Courseiva
mediumMultiple ChoiceObjective-mapped

PCNSA Practice Question: A security administrator notices that traffic…

A security administrator notices that traffic from a specific subnet is not being logged in the Traffic logs, although the traffic is allowed by a security policy rule. Which configuration setting should be verified?

⚠ Common exam trap

Many candidates confuse Log Forwarding profiles with the actual logging toggle on the rule, assuming that applying a forwarding profile is required for logging to occur, when in fact the rule's own 'Log at Session End' setting is the primary control for local Traffic log generation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The rule has 'Log at Session End' disabled

The 'Log at Session End' setting on a security policy rule controls whether traffic matching that rule generates a Traffic log entry when the session closes. If this setting is disabled, the firewall will allow the traffic per the rule but will not record it in the Traffic logs, which matches the scenario where traffic is permitted but not logged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Zone Protection profile is set to 'Log at Session Start'

    Why it's wrong here

    Zone Protection profiles handle flood protection and other zone-based settings, not rule logging.

  • The Log Forwarding profile is not applied

    Why it's wrong here

    Log Forwarding profiles send logs to external destinations but the rule must first have logging enabled.

  • The rule has 'Log at Session End' disabled

    Why this is correct

    If 'Log at Session End' is not checked, traffic matching the rule will not be logged.

  • Disable Server Response Inspection on the rule

    Why it's wrong here

    Disabling server response inspection does not affect traffic logging.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.