Courseiva
Decryption and MonitoringeasyMultiple SelectObjective-mapped

PCNSA Decryption and Monitoring Practice Question

An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?

⚠ Common exam trap

Palo Alto Networks often tests the distinction between Traffic logs (which show the result of decryption, such as a deny action) and Decryption logs (which show the decryption process itself), leading candidates to mistakenly choose Traffic logs as the primary source for decryption errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Decryption logs

Decryption logs are specifically designed to record details about SSL/TLS decryption actions, including handshake failures, certificate validation errors, and decryption policy matches. When troubleshooting connectivity issues related to decryption, these logs provide the most direct insight into why a session might be blocked or failing due to decryption errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • System logs

    Why it's wrong here

    System logs cover firewall system events, not decryption actions.

  • URL Filtering logs

    Why it's wrong here

    URL Filtering logs show URL categories and policy actions, not decryption specifics.

  • Decryption logs

    Why this is correct

    Decryption logs offer detailed information such as decryption reason, cipher, and certificate details.

  • Threat logs

    Why it's wrong here

    Threat logs record security threats, not decryption details.

  • Traffic logs

    Why this is correct

    Traffic logs include a 'Decryption Action' field indicating if traffic was decrypted or bypassed.

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.