nerdexam
Palo_Alto_Networks

PCNSA · Question #434

An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?

The correct answer is B. Type. The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value…

Submitted by eva_at· Apr 18, 2026Operate

Question

An administrator should filter NGFW traffic logs by which attribute column to determine if the entry is for the start or end of the session?

Options

  • AReceive Time
  • BType
  • CDestination
  • DSource

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    88% (45)
  • C
    2% (1)
  • D
    8% (4)

Explanation

The Type attribute column in the NGFW traffic logs indicates whether the log entry is for the start or end of the session. The possible values are START, END, DROP, DENY, and INVALID. The START value means that the log entry is for the start of the session, and the END value means that the log entry is for the end of the session. The other values indicate that the session was terminated by the firewall for various reasons.

Topics

#NGFW logs#Log analysis#Session monitoring#Traffic logs

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice