nerdexam
Palo_Alto_Networks

PCNSE · Question #730

An administrator troubleshoots an issue that causes packet drops. Which log type will help the engineer verify whether packet buffer protection was activated?

The correct answer is D. Threat. Packet Buffer Protection (PBP) is a PAN-OS DoS defense mechanism that monitors the firewall's packet buffer utilization. When the buffer usage exceeds defined thresholds, PBP activates and can drop, block, or randomly discard packets to protect the dataplane. Activation events fo

Submitted by minji_kr· Apr 18, 2026Operate

Question

An administrator troubleshoots an issue that causes packet drops. Which log type will help the engineer verify whether packet buffer protection was activated?

Options

  • AConfiguration
  • BData Filtering
  • CTraffic
  • DThreat

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    14% (2)
  • D
    79% (11)

Explanation

Packet Buffer Protection (PBP) is a PAN-OS DoS defense mechanism that monitors the firewall's packet buffer utilization. When the buffer usage exceeds defined thresholds, PBP activates and can drop, block, or randomly discard packets to protect the dataplane. Activation events for Packet Buffer Protection are recorded in the Threat log, not in the Traffic, Configuration, or Data Filtering logs. In the Threat log, you will see entries with a specific threat category related to DoS/PBP activation. The Threat log is the correct place to verify whether PBP was triggered and to gather details about the event, including timestamps, source zones, and the action taken.

Topics

#Packet Buffer Protection#Log Types#Troubleshooting#DoS Protection

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice