Courseiva
TroubleshoothardMultiple SelectObjective-mapped

PCNSE Troubleshoot Practice Question

An engineer is troubleshooting a scenario where traffic from a specific source IP is not being logged although the security policy log setting is set to 'log at session end'. Which three conditions could prevent logging for that traffic? (Choose three.)

⚠ Common exam trap

It's easy for candidates to assume 'log at session end' always generates a log, but they overlook that session termination events (like resets) or log rate capacity exhaustion can prevent the log from being written, and that deny rules with logging disabled will never produce a log regardless of the policy setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The traffic is denied by a rule that has logging disabled.

If a security policy rule denies traffic and has logging disabled, no log entry is generated even if the rule is configured to log at session end. The firewall only logs traffic that matches a rule with logging enabled; if logging is disabled for the deny rule, the session is silently dropped without any log record.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The traffic is denied by a rule that has logging disabled.

    Why this is correct

    If the denying rule has no logging configured, no log is generated.

  • The source IP is in a global log filtering exclusion.

    Why it's wrong here

    Palo Alto firewalls do not have a global IP-based log exclusion feature.

  • The session is terminated before session end (e.g., reset).

    Why this is correct

    If the session ends prematurely, the session-end log may not be written.

  • The traffic matches a rule with 'log at session start' only.

    Why it's wrong here

    Log at session start would still generate a log at start, not missing completely.

  • The firewall is exceeding its log rate capacity.

    Why this is correct

    When log rate is exceeded, logs may be dropped.

About these practice questions

One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.