Courseiva
Device Management and ServiceshardMultiple ChoiceObjective-mapped

PCNSA Device Management and Services Practice Question

A security analyst uses Panorama to generate a custom report on all traffic using the application 'facebook-base' across the enterprise. The analyst creates a new report template in Panorama with the filter '(app eq facebook-base)' and runs the report for the past 30 days. The report returns zero results. However, when the analyst logs into a specific firewall and queries the traffic logs using the same filter, results appear. The analyst confirms that the firewall is configured to forward logs to Panorama and that Panorama receives logs from all firewalls. What is the most likely reason the Panorama report fails to return data?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The application filter must specify the parent application 'facebook' because 'facebook-base' is a sub-application.

In Panorama, application filters require the parent application name when filtering by sub-application. 'facebook-base' is a sub-application of 'facebook', so the correct filter should be '(app eq facebook) (subapp eq facebook-base)'. Option A correctly identifies that the filter must specify the parent application. Option B is incorrect because Panorama supports both scheduled and ad-hoc queries. Option C is incorrect because the report template does not need to be committed to a device group; reports are run independently. Option D is incorrect because log forwarding to Panorama is configured in the log forwarding profile, but the port is not the issue; the logs are already forwarded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The application filter must specify the parent application 'facebook' because 'facebook-base' is a sub-application.

    Why this is correct

    Panorama requires the parent application for sub-application filters.

  • Panorama only supports scheduled reports, not ad-hoc queries.

    Why it's wrong here

    Panorama supports both ad-hoc and scheduled reports.

  • The report template is not committed to the device group.

    Why it's wrong here

    Report templates are committed to Panorama, not device groups.

  • The firewall's log forwarding profile must be set to send logs to Panorama on a separate port.

    Why it's wrong here

    No separate port is required.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.