PCNSE Manage, Monitor and Operate Practice Question
A user complains that they cannot access internal resources via GlobalProtect. The firewall shows the user is connected with an IP address from the tunnel pool. Which log type should the administrator check first to determine if traffic is being allowed or denied?
⚠ Common exam trap
A common mix-up: candidates think User-ID logs (Option D) are relevant because the user is connected, but User-ID logs only show authentication mappings, not traffic policy decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic logs.
The administrator should check Traffic logs first because they record every session attempt, showing whether traffic was allowed or denied based on security policies. Since the user is connected with a tunnel IP, the issue is likely policy-based, and Traffic logs provide the source, destination, and action (allow/deny) for each session, directly revealing if the traffic is being blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System logs.
Why it's wrong here
System logs capture daemon, management-plane and GlobalProtect connection events, not security policy verdicts on tunnel traffic, so they cannot show allow or deny. They are the right choice when diagnosing whether the GlobalProtect tunnel itself established or dropped.
- ✓
Traffic logs.
Why this is correct
Traffic logs record the security policy action, source, destination and application for each session, showing whether GlobalProtect tunnel traffic to internal resources was allowed or denied. This directly answers whether policy is blocking the user's access.
- ✗
Threat logs.
Why it's wrong here
Threat logs record traffic matching security profiles such as antivirus, vulnerability and spyware signatures, so permitted or denied sessions never appear there. They are the correct first check when investigating whether a session triggered a security profile action rather than a policy rule.
- ✗
User-ID logs.
Why it's wrong here
User-ID logs record user-to-IP mapping and group membership, not per-session allow or deny verdicts, so they cannot show whether the tunnel traffic was permitted. They are the right choice when verifying that a user was correctly identified and mapped to the expected IP address.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.