A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?
Trap 1: System logs
System logs cover firewall system events, not decryption-specific details.
Trap 2: Traffic logs
Traffic logs show decryption action (decrypt, no-decrypt) but lack detailed reasons like certificate validation errors.
Trap 3: Threat logs
Threat logs capture threats and vulnerabilities, not decryption statistics.
- A
System logs
Why wrong: System logs cover firewall system events, not decryption-specific details.
- B
Decryption logs
Decryption logs provide comprehensive data including decryption reason, certificate info, and cipher details.
- C
Traffic logs
Why wrong: Traffic logs show decryption action (decrypt, no-decrypt) but lack detailed reasons like certificate validation errors.
- D
Threat logs
Why wrong: Threat logs capture threats and vulnerabilities, not decryption statistics.