Courseiva
Securing Traffic →hardMultiple Choice

PCNSA Securing Traffic Practice Question

An administrator has configured a security policy rule to allow traffic from the 'trust' zone to the 'untrust' zone with application 'any' and service 'any'. The administrator wants to ensure that the firewall logs all allowed traffic, but notices that not all sessions are being logged. What is the most likely reason?

⚠ Common exam trap

The trap here is assuming that an 'any/any' allow rule with logging enabled will log all traffic, when in fact earlier rules can intercept traffic and bypass logging, leading to incomplete logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security policy rule is not matching all traffic because it is placed after a more specific rule that denies or allows traffic without logging.

The most likely reason for not all allowed sessions being logged is that another rule earlier in the rulebase is matching some traffic and either has logging disabled or is a deny rule. The 'any/any' rule only logs sessions that it processes. If a more specific rule above it handles certain traffic without logging, those sessions will not appear in the logs. Therefore, reviewing rule order and logging settings is necessary to ensure all allowed traffic is logged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security policy rule does not have 'Log at Session End' enabled.

    Why it's wrong here

    By default, 'Log at Session End' is enabled for allow rules. If it were disabled, no session end logs would be generated. However, the issue is that not all sessions are logged, not that no sessions are logged. It is unlikely that the logging option is disabled, as it is enabled by default. The more likely cause is related to session start logging or other factors.

  • ✗

    The firewall is not configured to log at session start, and some sessions are not being logged because they are not completing.

    Why it's wrong here

    If sessions do not complete, they may not generate session end logs. However, the administrator wants to log all allowed traffic, and if sessions are not completing, they might still be logged at session start if that option is enabled. But the scenario does not indicate that sessions are incomplete. The more direct reason for missing logs is often related to the default logging behavior for certain applications or traffic that is not matched by the rule.

  • ✓

    The security policy rule is not matching all traffic because it is placed after a more specific rule that denies or allows traffic without logging.

    Why this is correct

    Security rules are evaluated top-down, and if a more specific rule above the 'any/any' rule matches traffic and has logging disabled, those sessions will not be logged by the 'any/any' rule. The 'any/any' rule only logs traffic that it processes. This is a common cause of missing logs when multiple rules exist. Ensuring the rule order and logging settings are correct is essential.

  • ✗

    The firewall's log storage is full, causing new logs to be dropped.

    Why it's wrong here

    If log storage is full, the firewall may stop logging or overwrite older logs, but this would affect all logs, not just some sessions. The administrator notices that not all sessions are logged, which suggests a selective issue rather than a global storage problem. Additionally, PAN-OS typically alerts on log storage issues, and the administrator would likely be aware of such a condition.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.