exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 222 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 222
Topic #: 1
[All PCNSA Questions]

An administrator is troubleshooting traffic that should match the interzone-default rule. However, the administrator doesn't see this traffic in the traffic logs on the firewall. The interzone-default was never changed from its default configuration.
Why doesn't the administrator see the traffic?

  • A. The interzone-default policy is disabled by default.
  • B. Traffic is being denied on the interzone-default policy.
  • C. Logging on the interzone-default policy is disabled.
  • D. The Log Forwarding profile is not configured on the policy.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jallic
2 months ago
Selected Answer: C
This question is tricky because it states the interzone rule was never changed from the default configuration, which means it would deny traffic and also not log. Still going with C, but wish this was a two answer question.
upvoted 1 times
...
DatITGuyTho1337
1 year, 9 months ago
C is the correct answer, logging on both default rules are disabled until you override them to enable logging.
upvoted 4 times
...
Miho_GG
2 years ago
A seems more right. Logging is disabled by default.
upvoted 1 times
sguerouate
2 years ago
"The interzone-default policy is disabled by default." It's never disable by default, le log is. The response said, the rule is disable wich is not the case by default so C is the correct answer
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago