nerdexam
Palo_Alto_Networks

PCNSA · Question #152

An administrator wishes to follow best practices for logging traffic that traverses the firewall. Which log setting is correct?

The correct answer is D. Enable Log at Session End. Palo Alto Networks best practice is to log at Session End because the end-of-session log entry contains the complete picture: total bytes transferred, packets, elapsed time, application identified, threat details, and final policy action. Logging at Session Start generates a log

Submitted by weili_xi· Apr 18, 2026Configure

Question

An administrator wishes to follow best practices for logging traffic that traverses the firewall. Which log setting is correct?

Options

  • AEnable Log at Session Start
  • BDisable all logging
  • CEnable Log at both Session Start and End
  • DEnable Log at Session End

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    4% (1)
  • D
    86% (24)

Explanation

Palo Alto Networks best practice is to log at Session End because the end-of-session log entry contains the complete picture: total bytes transferred, packets, elapsed time, application identified, threat details, and final policy action. Logging at Session Start generates a log entry before the session is fully inspected, capturing incomplete data and doubling log volume with little added value. Disabling logging defeats visibility. Logging at both Start and End is redundant and significantly increases storage and processing overhead without meaningful benefit.

Topics

#Logging Best Practices#Session Monitoring#Policy Configuration#Traffic Visibility

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice