Courseiva

PCNSA Device Management and Services Practice Question

A network security engineer is configuring a Palo Alto Networks firewall to send SNMP traps to a management server. The engineer has already configured the SNMP community string and the trap destination IP. However, the management server is not receiving any traps. Which additional configuration is required to allow SNMP traps to be sent?

⚠ Common exam trap

The trap here is assuming that configuring the SNMP community and trap destination is sufficient, overlooking the need to enable SNMP on the management interface via an Interface Management Profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SNMP on the management interface by applying an Interface Management Profile that includes SNMP.

SNMP traps are generated by the management plane and sent out the management interface. By default, SNMP is not enabled on that interface. An Interface Management Profile with SNMP enabled must be applied to the management interface. Once that is done, the firewall can send traps to the configured destination. Other options either relate to data plane policies or routing, which are not the cause of the missing traps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an SNMPv3 user with authentication and encryption.

    Why it's wrong here

    SNMPv3 adds security but is not required for trap sending if SNMPv2c is used. The engineer already configured a community string, implying SNMPv2c. The missing step is enabling SNMP on the management interface; without that, traps are not sent regardless of SNMP version.

  • ✗

    Configure a Security policy rule allowing SNMP traffic from the firewall to the management server.

    Why it's wrong here

    Security policy rules control data plane traffic, not management plane traffic. SNMP traps originate from the management plane, so a Security policy rule is not required and will not enable trap sending. The issue is not policy but the lack of SNMP service enabled on the management interface.

  • ✓

    Enable SNMP on the management interface by applying an Interface Management Profile that includes SNMP.

    Why this is correct

    SNMP traps are sent from the management interface. By default, SNMP is not enabled on the management interface. An Interface Management Profile must be applied to the management interface with SNMP enabled for the firewall to send traps. Without this, even with community and destination configured, traps will not be transmitted.

  • ✗

    Add a static route to the management server via the management interface.

    Why it's wrong here

    A static route ensures reachability but does not enable SNMP trap sending. If the management server is on a directly connected subnet or already reachable, a route may not be needed. The absence of traps is due to SNMP not being enabled on the management interface, not a routing issue.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.