Courseiva

PCNSA Decryption and Monitoring Practice Question

Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)

⚠ Common exam trap

Watch out — candidates often confuse the Threat log (which shows post-decryption threats) with logs that diagnose the decryption process itself, or mistakenly think GlobalProtect logs are relevant because SSL decryption is sometimes used in VPN environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System log

The System log (B) records decryption-related events, such as certificate validation failures, handshake errors, and unsupported cipher suites, which are critical for diagnosing SSL decryption issues. The Traffic log (D) shows whether traffic was decrypted or bypassed, including the 'Decrypted' flag and details about the SSL/TLS handshake, allowing you to verify decryption policy application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GlobalProtect log

    Why it's wrong here

    GlobalProtect logs cover tunnel, HIP and user authentication events for remote access, not the SSL handshake, certificate or cipher negotiation failures that break decryption. They are tempting because GlobalProtect traffic is itself decrypted, but the decryption and system logs record those errors.

  • ✓

    System log

    Why this is correct

    The system log records decryption engine state changes, including SSL forward proxy failures, certificate validation errors, and resource exhaustion events. It satisfies the stem's troubleshooting constraint by exposing why the firewall cannot decrypt traffic, such as unsupported ciphers or untrusted issuer chains, rather than merely listing decrypted sessions.

  • ✗

    Threat log

    Why it's wrong here

    Threat logs record security verdicts on sessions after decryption succeeds, so they show nothing about why a handshake or certificate check failed. They are tempting because decryption failures can surface as threats, but the decryption and system logs carry the SSL error detail.

  • ✓

    Traffic log

    Why this is correct

    The traffic log records the session's decryption verdict, showing whether SSL Forward Proxy applied, bypassed, or blocked traffic, plus the specific reason code. This directly satisfies the stem's need to troubleshoot decryption issues by revealing policy mismatches, unsupported ciphers, or untrusted certificates for each flow.

  • ✗

    URL Filtering log

    Why it's wrong here

    The URL Filtering log records category and policy verdicts for web requests; it does not show certificate validation, cipher negotiation or decryption-bypass reasons. It would be the right log for tuning URL filtering policy, not for diagnosing why SSL decryption failed.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.