exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 109 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 109
Topic #: 1
[All PCNSE Questions]

Which log file can be used to identify SSL decryption failures?

  • A. Traffic
  • B. ACC
  • C. Configuration
  • D. Threats
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Daniel2020
Highly Voted 3 years, 9 months ago
A Always from the traffic log. Whether it is drilling down into traffic log details or enabling the decryption column. Acquaint yourself with this reference: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/verify-decryption.html
upvoted 9 times
...
Micutzu
Highly Voted 8 months, 2 weeks ago
Selected Answer: A
The question is about "log file" and SSL decrypt failures. ACC isn't a log file. SLL decrypt failures you can see on Decryption log and in Traffic log (Session End Reason column)
upvoted 6 times
...
0d2fdfa
Most Recent 2 months ago
Selected Answer: B
B is correct according to the documentation. The most common reasons for decryption failures are TLS protocol errors, cipher version errors (client and server version mismatches and client and Decryption profile version mismatches), and certificate errors. To investigate decryption errors, start with the Application Command Center (ACC) to identify failures and then go to the Decryption logs to drill down into details. Option is is Traffic and NOT "Decryption logs" https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-troubleshooting-workflow-examples/investigate-decryption-failure-reasons
upvoted 3 times
...
327c7c8
3 months, 2 weeks ago
B: Is the correct answer. ACC>SSL Activity>Decryption failure reasones Give you the information about the failure. Traffic log can you verify if the treffic is encrypted or not. There are no details about the failure.
upvoted 4 times
...
Marshpillowz
5 months, 4 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
news088
10 months, 3 weeks ago
ACC is not a log file . The question is about "Which log file", so A should be the correct one.
upvoted 2 times
...
duckduckgooo
1 year, 1 month ago
Selected Answer: B
I am going to go with B https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-troubleshooting-workflow-examples/investigate-decryption-failure-reasons WHat people are selecting is for validating if decryption was used, but not for specific failures.
upvoted 2 times
PaloSteve
1 year ago
From this article: "To investigate decryption errors, start with the Application Command Center (ACC) to identify failures and then go to the Decryption logs to drill down into details." So, the real answer might be the Decryption logs, which. of course, is not an option. LOL.
upvoted 2 times
...
...
DenskyDen
1 year, 5 months ago
Selected Answer: A
View Decrypted Traffic Sessions—Filter the Traffic Logs (MonitorLogsTraffic) using the filter ( flags has proxy ) https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/verify-decryption#id185BG0KL0W1
upvoted 1 times
PaloSteve
1 year ago
This flag is only for traffic that has been successfully decrypted. It will not help identify SSL decryption failures
upvoted 2 times
...
...
TAKUM1y
1 year, 9 months ago
Selected Answer: A
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/verify-decryption
upvoted 2 times
...
Pretorian
1 year, 11 months ago
Another tricky question, very common with PANW tests. While I agree with "A", if you go to "Monitor > Decryption" you will see an "Error" and "Error Index" column (if you don't see it, you can enable it). The Traffic log will only tell you if a session was decrypted or not, but no-decrypted traffic doesn't always mean a failure, it could often mean there's a decryption policy with action "no decrypt" or an SSL decryption exclusion or an error. Something to think about...
upvoted 1 times
...
FS68
2 years, 9 months ago
A because ACC isn't a log file
upvoted 2 times
...
kike71
3 years ago
I think that correct answer is B PANOS Guide. Investigate Decryption Failure Reasons Begin your investigation at ACC>SSL Activity and look at the Decryption Failure Reasons widget https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-troubleshooting-workflow-examples/investigate-decryption-failure-reasons.html#id1eee110d-3799-45ef-a4b0-e5e7fbd157af
upvoted 2 times
kike71
3 years ago
There is a thing that dizzies me... ACC isn't a log file
upvoted 2 times
duckduckgooo
1 year, 4 months ago
Dang it, I gotta read slower. I was looking why it wasn't that since 10.x has that great feature.
upvoted 1 times
...
...
...
thegreek1
3 years, 1 month ago
Confirmed that the answer is A Traffic. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/verify-decryption.html
upvoted 3 times
...
kraut
3 years, 3 months ago
IMHO: A - traffic log specifically check session end reason where decrypted=yes and action=allowed. you'll see errors such as decrypt-error decrypt-cert-validation
upvoted 2 times
...
lucaboban
3 years, 4 months ago
The following tools provide full visibility into the TLS handshake and help you troubleshoot and monitor your decryption deployment: ACC - SSL Activity Monitor - Logs - Decryption So as there is no Decryption listed as answer, ACC fits. Correct answer is: A
upvoted 1 times
...
CKPH
3 years, 4 months ago
PCNSE is based on PANOS10 https://live.paloaltonetworks.com/t5/certification-articles/pcnse-and-pcnsa-exam-changes-with-10-0/ta-p/344832 Could be B: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-notes/pan-os-10-0-release-information/features-introduced-in-pan-os-10-0/decryption-features.html#ida1eb9d8c-515e-4e88-b217-1ebc025a45d4 "Use the new ACC features to identify traffic for which decryption causes problems and then use the new Decryption logs to drill down into details and solve the problem."
upvoted 1 times
Prutser2
3 years ago
agree could be, again wording of question, clearly states "log file" ACC is not a log file. so brings back to A
upvoted 1 times
...
...
Daniel2020
3 years, 5 months ago
B - as from PAN-OS 10, troubleshooting SSL in done in the following process: 1. Check ACC decryption widgets to identify traffic that causes decryption issues 2. Drill down further using the Decryption Log. It is not A because that simply tells you if the traffic was or was not decrypted. It does not in any way provide you with a means for troubleshooting. The question is asking you to troubleshoot. Read "Troubleshoot and Monitor Decryption" for PAN-OS 10. It clearly lists your troubleshooting process for SSL decryption issues https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/troubleshoot-and-monitor-decryption.html
upvoted 3 times
bmarks
3 years, 5 months ago
The Question is simply asking which 'log file' lists/identifies decrypt failures, not how and where do I troubleshoot them... The Application Command Center (ACC) is an analytical tool, not a log file. The only answer that makes sense is A Traffic log.
upvoted 4 times
bmarks
3 years, 5 months ago
Also, the PCNSE 9 exam covers PANOS 9.1, not PANOS 10
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago