nerdexam
Palo_Alto_Networks

PCNSE · Question #283

Which logs enable a firewall administrator to determine whether a session was decrypted?

The correct answer is C. Decryption. Decryption logs (introduced in PAN-OS 8.1+) are specifically designed to record details about SSL/TLS inspection decisions. Each log entry shows whether a session was decrypted or not, the policy rule that applied, the reason for decryption or exemption, certificate details…

Submitted by haru.x· Apr 18, 2026Operate

Question

Which logs enable a firewall administrator to determine whether a session was decrypted?

Exhibit

PCNSE question #283 exhibit

Options

  • ATraffic
  • BSecurity Policy
  • CDecryption
  • DCorrelated Event

How the community answered

(40 responses)
  • A
    3% (1)
  • C
    93% (37)
  • D
    5% (2)

Explanation

Decryption logs (introduced in PAN-OS 8.1+) are specifically designed to record details about SSL/TLS inspection decisions. Each log entry shows whether a session was decrypted or not, the policy rule that applied, the reason for decryption or exemption, certificate details, and the TLS version/cipher used. Traffic logs record session flow information (source, destination, bytes, application) but do not provide granular decryption status details. Security Policy logs show policy matches. Correlated Event logs are threat intelligence correlation events, unrelated to decryption status.

Topics

#Decryption#Logging#SSL/TLS Inspection#Firewall Administration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice