Courseiva
Troubleshoot →easyMultiple Choice

PCNSE Troubleshoot Practice Question

A network engineer needs to verify that a specific security rule is being hit by traffic. Which firewall log should be examined?

⚠ Common exam trap

Many candidates confuse the Traffic log with the Threat log, thinking that only malicious traffic generates logs, but the Traffic log records all allowed and denied sessions regardless of threat status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic log

The Traffic log records every session that matches a security rule, including the rule ID, source/destination IPs, ports, and action (allow/deny). To verify that a specific security rule is being hit, you must examine the Traffic log, as it shows which rule processed each session. Configuration, Threat, and System logs do not contain per-session rule match data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configuration log

    Why it's wrong here

    Configuration logs capture administrative changes to the firewall's rulebase and objects, not packets evaluated against those rules, so they cannot show a rule being hit. They are examined during change auditing or rollback investigations, where the requirement is tracking who altered policy.

  • ✓

    Traffic log

    Why this is correct

    The traffic log records every session matched against security policy, including the rule name that permitted or denied it. Examining it confirms whether the specific security rule is being hit, directly satisfying the requirement to verify rule utilisation. Other logs, such as threat or URL filtering, only capture events after a rule already matched.

  • ✗

    Threat log

    Why it's wrong here

    Threat logs record traffic matching security profiles such as antivirus, anti-spyware and vulnerability signatures, so a rule permitting benign traffic produces no entry there. They are the right source when investigating exploit attempts or malware downloads rather than confirming rule matches.

  • ✗

    System log

    Why it's wrong here

    System logs record control-plane and daemon events, not per-session traffic matched against security policy, so they cannot confirm a rule hit. They are consulted for administrative troubleshooting such as commit failures or process restarts, where no traffic-matching evidence is required.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.