nerdexam
Palo_Alto_Networks

PCNSE · Question #698

Which log type will help the engineer verify whether packet buffer protection was activated?

The correct answer is C. Threat. Packet Buffer Protection is a Zone Protection and DoS Protection feature that defends against packet buffer exhaustion attacks. When it activates (either in alert or block mode), PAN-OS records the event in the Threat log, categorized under the DoS sub-type. Traffic logs record s

Submitted by rania.sa· Apr 18, 2026Operate

Question

Which log type will help the engineer verify whether packet buffer protection was activated?

Options

  • AData Filtering
  • BConfiguration
  • CThreat
  • DTraffic

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (29)

Explanation

Packet Buffer Protection is a Zone Protection and DoS Protection feature that defends against packet buffer exhaustion attacks. When it activates (either in alert or block mode), PAN-OS records the event in the Threat log, categorized under the DoS sub-type. Traffic logs record session-level forwarding decisions, Configuration logs record admin changes, and Data Filtering logs record DLP-related matches - none of these capture packet buffer protection activation events. Checking the Threat log is the correct place to confirm whether and when packet buffer protection triggered.

Topics

#Logging#Threat logs#Packet buffer protection#Security features

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice