PCNSA Device Management and Services Practice Question
A syslog server is only reachable through a specific interface on the firewall. To ensure syslog logs are sent via that interface, which configuration is required?
⚠ Common exam trap
Many candidates confuse service routes with static routes or policy-based forwarding, assuming that any routing change will fix the source interface issue, but service routes are the only mechanism that controls the source interface for firewall-originated traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a service route for syslog
Service routes in Palo Alto Networks firewalls allow you to specify which source interface or IP address is used for outbound traffic from the firewall itself, such as syslog, SNMP, or authentication. By configuring a service route for syslog, you ensure that syslog messages are sourced from the specific interface that can reach the syslog server, even if the routing table would otherwise choose a different path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a static route for the syslog server IP
Why it's wrong here
A static route only directs traffic toward a destination subnet; it cannot bind syslog egress to a particular source interface. The stem requires the log traffic to leave via one named interface, which is set by the syslog server profile's source-interface setting. Static routes are for reachability, not source selection.
- ✓
Set up a service route for syslog
Why this is correct
A service route forces traffic originating from the firewall itself, such as syslog, to egress a specified interface rather than following the routing table. This satisfies the constraint that syslog must be sent via a particular interface.
- ✗
Enable NAT on the syslog traffic
Why it's wrong here
NAT rewrites addresses and ports; it does not choose which physical interface carries syslog egress. The requirement is source-interface binding in the syslog server profile, which forces traffic out the specified interface. NAT would be right when translating addresses for internet-bound or overlapping-subnet traffic, not for interface selection.
- ✗
Use policy-based forwarding for syslog traffic
Why it's wrong here
Policy-based forwarding overrides the routing table per-flow, which is unnecessary when the syslog server is reachable via a normal route through that interface. It suits steering traffic that the routing table would otherwise send elsewhere, not selecting an egress interface for a reachable destination.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.