nerdexam
Palo_Alto_Networks

PCNSE · Question #400

A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is bei

The correct answer is B. Data Filtering log. File Blocking profile events-regardless of the action (alert, block, continue)-are recorded in the Data Filtering log (Monitor > Logs > Data Filtering), not the Threat log. The Threat log captures vulnerability exploits, spyware, and antivirus events. The WildFire Submissions log

Submitted by jakub_pl· Apr 18, 2026Configuration Troubleshooting

Question

A network security engineer has applied a File Blocking profile to a rule with the action of Block. The user of a Linux CLI operating system has opened a ticket. The ticket states that the user is being blocked by the firewall when trying to download a TAR file. The user is getting no error response on the system. Where is the best place to validate if the firewall is blocking the user's TAR file?

Options

  • AThreat log
  • BData Filtering log
  • CWildFire Submissions log
  • DURL Filtering log

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    91% (31)
  • C
    3% (1)

Explanation

File Blocking profile events-regardless of the action (alert, block, continue)-are recorded in the Data Filtering log (Monitor > Logs > Data Filtering), not the Threat log. The Threat log captures vulnerability exploits, spyware, and antivirus events. The WildFire Submissions log tracks files sent to WildFire for analysis. The URL Filtering log captures web category events. Because the engineer applied a File Blocking profile with a 'Block' action, the TAR file download attempt will appear in the Data Filtering log, making it the correct place to validate and confirm the block.

Topics

#File Blocking#Logging#Security Profiles#Log Analysis

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice