PCNSA Decryption and Monitoring Practice Question
Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)
⚠ Common exam trap
Watch out — candidates often confuse the Threat log (which shows post-decryption threats) with logs that diagnose the decryption process itself, or mistakenly think GlobalProtect logs are relevant because SSL decryption is sometimes used in VPN environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System log
The System log (B) records decryption-related events, such as certificate validation failures, handshake errors, and unsupported cipher suites, which are critical for diagnosing SSL decryption issues. The Traffic log (D) shows whether traffic was decrypted or bypassed, including the 'Decrypted' flag and details about the SSL/TLS handshake, allowing you to verify decryption policy application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GlobalProtect log
Why it's wrong here
GlobalProtect logs cover tunnel, HIP and user authentication events for remote access, not the SSL handshake, certificate or cipher negotiation failures that break decryption. They are tempting because GlobalProtect traffic is itself decrypted, but the decryption and system logs record those errors.
- ✓
System log
Why this is correct
The system log records decryption engine state changes, including SSL forward proxy failures, certificate validation errors, and resource exhaustion events. It satisfies the stem's troubleshooting constraint by exposing why the firewall cannot decrypt traffic, such as unsupported ciphers or untrusted issuer chains, rather than merely listing decrypted sessions.
- ✗
Threat log
Why it's wrong here
Threat logs record security verdicts on sessions after decryption succeeds, so they show nothing about why a handshake or certificate check failed. They are tempting because decryption failures can surface as threats, but the decryption and system logs carry the SSL error detail.
- ✓
Traffic log
Why this is correct
The traffic log records the session's decryption verdict, showing whether SSL Forward Proxy applied, bypassed, or blocked traffic, plus the specific reason code. This directly satisfies the stem's need to troubleshoot decryption issues by revealing policy mismatches, unsupported ciphers, or untrusted certificates for each flow.
- ✗
URL Filtering log
Why it's wrong here
The URL Filtering log records category and policy verdicts for web requests; it does not show certificate validation, cipher negotiation or decryption-bypass reasons. It would be the right log for tuning URL filtering policy, not for diagnosing why SSL decryption failed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.