nerdexam
Palo_Alto_Networks

PCNSE · Question #252

If a DNS sinkhole is configured, any sinkhole actions indicating a potentially infected host are recorded in which log type?

The correct answer is C. Threat. When a DNS sinkhole is configured, the firewall redirects DNS responses for malicious domains to a sinkhole IP address. When an infected host subsequently attempts to connect to that sinkhole IP, the firewall identifies the suspicious behavior and records the event in the Threat

Submitted by khalil_dz· Apr 18, 2026Operate

Question

If a DNS sinkhole is configured, any sinkhole actions indicating a potentially infected host are recorded in which log type?

Exhibit

PCNSE question #252 exhibit

Options

  • AData Filtering
  • BWildFire Submissions
  • CThreat
  • DTraffic

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    88% (36)
  • D
    7% (3)

Explanation

When a DNS sinkhole is configured, the firewall redirects DNS responses for malicious domains to a sinkhole IP address. When an infected host subsequently attempts to connect to that sinkhole IP, the firewall identifies the suspicious behavior and records the event in the Threat log - specifically as a DNS sinkhole action. This allows administrators to identify potentially compromised hosts by reviewing Threat log entries. Traffic logs record general connection data but do not classify DNS sinkhole events as threats; WildFire Submission and Data Filtering logs serve entirely different purposes.

Topics

#DNS Sinkhole#Logging#Threat Prevention#Log Types

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice