Exam PCNSA All QuestionsBrowse all questions from this exam
Question 166

Given the screenshot, what are two correct statements about the logged traffic? (Choose two.)

    Correct Answer: B, D

    The logged traffic indicates that the web session was allowed but ended due to a threat, as seen in the 'SESSION END REASON' column. This suggests that the traffic was denied by a security profile, addressing potential threats detected during the session. Additionally, the 'APPLICATION' column indicates web browsing over port 443, which infers that the web session involved HTTPS traffic, likely decrypted for inspection. This aligns with the provided setup where the 'FROM ZONE' is 'LAN' and the 'TO ZONE' is 'Internet', indicating typical web traffic inspection and filtering.

Discussion
Jackie26Options: BD

Entries for traffic that matches the URL Filtering profile attached to a security policy rule- will show as url Entries generated when traffic matches one of the Security Profiles attached to a security rule on the firewall- it will show as threat

TheMaster01Options: BD

The session was decrypted because you can see web-browsing over port 443 The traffic was denied by a security profile https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQlCAO

Aiazd

How to read that it was decrypted? There are some 443 traffic not decrypted..

TheMaster01Options: BD

B and D are correct

Mouna_certOptions: BD

for URL Filtering, the type of logs is not traffic i believe

MazalazaOptions: BD

BD seem better answer

SillyGoose123

How can I read that the traffic was denied?

SillyGoose123

Nevermind, it's "Session end reason"

OteslarOptions: BD

B and D are correct.