PCNSE · Question #283
Which logs enable a firewall administrator to determine whether a session was decrypted?
The correct answer is C. Decryption. Decryption logs (introduced in PAN-OS 8.1+) are specifically designed to record details about SSL/TLS inspection decisions. Each log entry shows whether a session was decrypted or not, the policy rule that applied, the reason for decryption or exemption, certificate details…
Question
Which logs enable a firewall administrator to determine whether a session was decrypted?
Exhibit
Options
- ATraffic
- BSecurity Policy
- CDecryption
- DCorrelated Event
How the community answered
(40 responses)- A3% (1)
- C93% (37)
- D5% (2)
Explanation
Decryption logs (introduced in PAN-OS 8.1+) are specifically designed to record details about SSL/TLS inspection decisions. Each log entry shows whether a session was decrypted or not, the policy rule that applied, the reason for decryption or exemption, certificate details, and the TLS version/cipher used. Traffic logs record session flow information (source, destination, bytes, application) but do not provide granular decryption status details. Security Policy logs show policy matches. Correlated Event logs are threat intelligence correlation events, unrelated to decryption status.
Topics
Community Discussion
No community discussion yet for this question.
