nerdexam
Palo_Alto_Networks

PCNSA · Question #355

An administrator is troubleshooting an issue with Office365 and expects that this traffic traverses the firewall. When reviewing Traffic Log entries, there are no logs matching traffic from the test…

The correct answer is C. Traffic matches the interzone-default rule, which does not log traffic by default. The absence of Office365 traffic in the Traffic Log suggests the traffic might be implicitly denied by the interzone-default rule, which does not generate logs by default.

Submitted by weili_xi· Apr 18, 2026Policy Evaluation and Management

Question

An administrator is troubleshooting an issue with Office365 and expects that this traffic traverses the firewall. When reviewing Traffic Log entries, there are no logs matching traffic from the test workstation. What might cause this issue?

Options

  • AOffice365 traffic is logged in the System Log.
  • BOffice365 traffic is logged in the Authentication Log.
  • CTraffic matches the interzone-default rule, which does not log traffic by default.
  • DThe firewall is blocking the traffic, and all blocked traffic is in the Threat Log.

How the community answered

(32 responses)
  • B
    6% (2)
  • C
    91% (29)
  • D
    3% (1)

Why each option

The absence of Office365 traffic in the Traffic Log suggests the traffic might be implicitly denied by the interzone-default rule, which does not generate logs by default.

AOffice365 traffic is logged in the System Log.

Office365 traffic, if it traverses the firewall, would be logged in the Traffic Log, not the System Log, which records firewall operational events.

BOffice365 traffic is logged in the Authentication Log.

Authentication Log records user authentication events, not general application traffic like Office365.

CTraffic matches the interzone-default rule, which does not log traffic by default.Correct

The interzone-default rule applies to traffic flowing between different security zones and has a default action of Deny. Critically, this default rule does not have logging enabled by default, meaning any traffic matching it will be silently dropped without an entry in the Traffic Log.

DThe firewall is blocking the traffic, and all blocked traffic is in the Threat Log.

While blocked traffic can be in the Threat Log if a threat is detected, traffic blocked by a security policy rule (like the interzone-default rule) that doesn't have logging enabled would not appear in the Threat Log, which is specifically for detected threats.

Concept tested: Default interzone rule behavior and logging

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rules.html

Topics

#Troubleshooting#Traffic Logging#Security Policy#Default Rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice