Courseiva

PCNSA Device Management and Services Practice Question

A security administrator at a company with a PA-5220 running PAN-OS 10.2 must ensure that configuration backups can be restored to a replacement firewall of the same model. The administrator plans to use scheduled configuration exports and also wants to retain a copy of the running configuration before a major change. Which TWO actions will satisfy these requirements? (Choose two.)

⚠ Common exam trap

The trap here is treating device state exports or log exports as configuration backups, when only a full configuration export or snapshot contains the policies and objects needed to rebuild a firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a scheduled configuration export under Device > Setup > Operations that saves a full configuration snapshot to an external SCP server on a recurring basis.

Scheduled configuration exports provide recurring off-box full configuration snapshots that can be loaded onto a replacement firewall, satisfying disaster recovery. Named configuration snapshots taken before a major change provide a local rollback point on the same device. Together they cover both off-box retention and quick local recovery, while log exports and device state exports do not contain the full configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Export only the device state under Device > Setup > Operations, since the device state contains all security policy and object definitions.

    Why it's wrong here

    The device state export contains runtime state such as HA status, session information, and some operational data, but it is not a substitute for a full configuration backup. Security policies and objects live in the configuration, not the device state. Relying on device state alone would leave the replacement firewall without the policy set it needs to function.

  • ✗

    Configure a scheduled log export to the same SCP server so that configuration and logs are stored together for restoration.

    Why it's wrong here

    Log exports contain traffic, threat, and system logs, not the configuration needed to rebuild a firewall. Restoring logs does not restore policies, objects, or network settings. While co-locating logs and configuration on one server is convenient, the log export job alone does not satisfy the requirement to restore a replacement firewall.

  • ✓

    Create a scheduled configuration export under Device > Setup > Operations that saves a full configuration snapshot to an external SCP server on a recurring basis.

    Why this is correct

    Scheduled configuration exports capture the full running configuration, including policies, objects, and network settings, and store it externally. This satisfies the need for recurring, restorable backups that survive hardware loss. Because the snapshot is complete, it can be loaded onto a replacement firewall of the same model, provided the software version is compatible.

  • ✗

    Enable configuration versioning under Device > Setup > Management so the firewall automatically pushes each commit to an external repository.

    Why it's wrong here

    PAN-OS does not automatically push committed configurations to an external repository through a configuration versioning feature. While the firewall keeps local configuration versions that can be rolled back, they remain on the device and are lost if the hardware fails. External retention requires an explicit export job or a Panorama-managed deployment.

  • ✓

    Use the 'Save named configuration snapshot' option under Device > Setup > Operations to capture the current configuration before making changes.

    Why this is correct

    Named configuration snapshots capture the current running configuration locally on the firewall and can be loaded later if a change causes problems. Taking one before a major change provides a rollback point. Combined with an external scheduled export, it covers both local quick rollback and off-box disaster recovery for the replacement firewall.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.