Courseiva

PCNSA Device Management and Services Practice Question

A network security administrator needs to ensure that a Palo Alto Networks firewall sends SNMP traps to a monitoring server at 10.1.1.50 using the MGT interface. The administrator has already added the SNMP community string and trap destination under Device > Setup > Services > SNMP. However, no traps are being received. Which additional configuration is required to ensure traps are sent from the MGT interface?

⚠ Common exam trap

The trap here is assuming that security policy rules apply to management-plane traffic, when in fact service routes control outbound management traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a service route for SNMP under Device > Setup > Services > Service Routes.

Service routes override the default source interface for management services such as SNMP, syslog, and email. When a specific source interface is required, a service route must be configured. Without it, the firewall may use a different interface, causing the SNMP server to reject or ignore traps. Thus, creating a service route for SNMP is the correct action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a service route for SNMP under Device > Setup > Services > Service Routes.

    Why this is correct

    Service routes define the source interface and IP address for outbound management traffic. By default, SNMP traps may use the management interface, but if a specific interface is required, a service route must be configured. In this scenario, the administrator must create a service route for SNMP specifying the MGT interface to ensure traps are sent from that interface.

  • ✗

    Enable SNMP on the MGT interface under Network > Interfaces > Management.

    Why it's wrong here

    SNMP is enabled globally under Device > Setup > Services > SNMP, not per interface. The management interface is always available for management services. Enabling SNMP on the interface is not a valid configuration step and would not change the source interface for traps.

  • ✗

    Assign the SNMP server IP address to a custom zone and create a NAT policy.

    Why it's wrong here

    NAT policies are for translating addresses of traffic passing through the firewall. SNMP traps originate from the firewall itself and do not require NAT. Creating a custom zone and NAT policy would not influence which interface the traps use and is unnecessary for management-plane traffic.

  • ✗

    Configure a security policy rule allowing SNMP traffic from the MGT interface to the SNMP server.

    Why it's wrong here

    Security policy rules control traffic traversing the firewall, not management-plane traffic originating from the firewall. SNMP traps are generated by the management plane and are not subject to security policy. Therefore, this rule would not affect SNMP trap delivery and would not resolve the issue.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.