nerdexam
Palo_Alto_Networks

PCNSA · Question #154

An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs. What is the correct process to enable this logging?

The correct answer is A. Select the interzone-default rule and click Override; on the Actions tab, select Log at Session End. Option A is correct because the interzone-default rule is a predefined/default system rule, which cannot be edited like a regular rule - it must first be Overridden to create a modifiable instance. After clicking Override, you navigate to the Actions tab and enable Log at…

Submitted by alyssa_d· Apr 18, 2026Policy Evaluation and Management

Question

An administrator would like to see the traffic that matches the interzone-default rule in the traffic logs. What is the correct process to enable this logging?

Options

  • ASelect the interzone-default rule and click Override; on the Actions tab, select Log at Session End
  • BSelect the interzone-default rule and edit the rule; on the Actions tab, select Log at Session End
  • CSelect the interzone-default rule and edit the rule; on the Actions tab, select Log at Session Start
  • DThis rule has traffic logging enabled by default; no further action is required.

How the community answered

(36 responses)
  • A
    69% (25)
  • B
    6% (2)
  • C
    19% (7)
  • D
    6% (2)

Explanation

Option A is correct because the interzone-default rule is a predefined/default system rule, which cannot be edited like a regular rule - it must first be Overridden to create a modifiable instance. After clicking Override, you navigate to the Actions tab and enable Log at Session End, which captures completed session data for the traffic log.

Option B is wrong because the interzone-default rule does not present a standard "Edit" workflow; the correct action on a default rule is "Override," not "Edit" - this distinction is tested precisely because the two look similar in the UI.

Option C fails on two levels: it uses "Edit" (wrong process) and selects "Log at Session Start," which logs only the beginning of a session and lacks the full session details typically needed for traffic log analysis.

Option D is a common misconception - default rules like interzone-default have logging disabled by default, so no action would result in silent traffic with no log entries.

Memory tip: "Default rules need an Override, not an Edit" - if you see a default rule in PAN-OS (interzone, intrazone), your first click is always Override, never Edit. Pair that with "End > Start" for logging since Session End gives you the complete picture.

Topics

#Traffic Logging#Security Policy#Rule Management#Default Rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice