PCNSA · Question #152
An administrator wishes to follow best practices for logging traffic that traverses the firewall. Which log setting is correct?
The correct answer is D. Enable Log at Session End. Palo Alto Networks best practice is to log at Session End because the end-of-session log entry contains the complete picture: total bytes transferred, packets, elapsed time, application identified, threat details, and final policy action. Logging at Session Start generates a log
Question
An administrator wishes to follow best practices for logging traffic that traverses the firewall. Which log setting is correct?
Options
- AEnable Log at Session Start
- BDisable all logging
- CEnable Log at both Session Start and End
- DEnable Log at Session End
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C4% (1)
- D86% (24)
Explanation
Palo Alto Networks best practice is to log at Session End because the end-of-session log entry contains the complete picture: total bytes transferred, packets, elapsed time, application identified, threat details, and final policy action. Logging at Session Start generates a log entry before the session is fully inspected, capturing incomplete data and doubling log volume with little added value. Disabling logging defeats visibility. Logging at both Start and End is redundant and significantly increases storage and processing overhead without meaningful benefit.
Topics
Community Discussion
No community discussion yet for this question.