Palo Alto Networks (PANW) Certified Network Security Administrator (PCNSA) Practice Exam

Disable ads (and more) with a membership for a one time $4.99 payment

Prepare for the Palo Alto Networks Certified Network Security Administrator Exam with flashcards and multiple choice questions. Each question includes hints and explanations to boost your confidence and readiness!

Practice this question and more.


How can you view active sessions on the firewall that matched a specific security rule named "ftp-out" using the CLI?

  1. show sessions filter ftp-out

  2. list session ftp-out

  3. show session all filter rule ftp-out

  4. get sessions ftp-out

The correct answer is: show session all filter rule ftp-out

To view active sessions on the firewall that matched a specific security rule, the command "show session all filter rule ftp-out" is used. This command is specifically designed to provide comprehensive details about all active sessions, while filtering for those that match the specified rule, in this case, "ftp-out." Using "show session all" ensures you are getting a full view of the current sessions, including the ones filtered by the rule name. The command also indicates that you're querying for sessions based on defined security rules, which is essential when troubleshooting or monitoring traffic in relation to specific security policies. The inclusion of "filter rule ftp-out" clearly establishes what you're searching for and normalizes the output to ensure that it strictly pertains to the sessions that have matched this specific rule. This makes the query not only precise but also user-friendly, as users can clearly see the traffic that is allowed or blocked according to that rule.