Courseiva

PCNSA Device Management and Services Practice Question

An administrator configures SNMP monitoring on a firewall but receives no data from the SNMP manager. Which check should be performed first?

⚠ Common exam trap

Candidates often assume the problem is network connectivity (Option B) or subnet mismatch (Option C), but the PCNSA exam emphasizes that SNMP-specific configuration errors—especially the community string and allowed IP list—are the most frequent first-check items.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the SNMP community string and allowed management IPs in the SNMP server profile

The most common cause of SNMP monitoring failure after initial configuration is a mismatch in the SNMP community string (for SNMPv2c) or authentication credentials, or the SNMP manager's IP not being permitted in the SNMP server profile. The SNMP server profile on the firewall explicitly defines which community strings and manager IPs are allowed to poll the device. If these are incorrect, the firewall will silently drop SNMP requests, even if network connectivity is fine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check that the SNMP manager supports SNMPv3

    Why it's wrong here

    SNMPv3 support is not a prerequisite for receiving data; the manager can poll using SNMPv1 or v2c if the firewall is configured accordingly. It is tempting because version mismatches do cause failures, but the first check should confirm the firewall's SNMP configuration and reachability rather than the manager's version capability.

  • ✗

    Verify that the firewall's management IP is reachable from the SNMP manager

    Why it's wrong here

    Reachability of the management IP is a valid prerequisite, but it is not the first check when SNMP polling specifically returns no data; the SNMP service and community or user configuration on the firewall must be verified. It is tempting because connectivity failures do break monitoring, but the stem implies the manager is already configured.

  • ✗

    Ensure the SNMP manager is running on the same subnet as the firewall

    Why it's wrong here

    SNMP polling works across subnets and routed networks, so co-location is not required; the manager can reside anywhere with IP reachability. It is tempting because same-subnet setups avoid routing issues, but placing the manager elsewhere is a supported and common design, making this check irrelevant here.

  • ✓

    Verify the SNMP community string and allowed management IPs in the SNMP server profile

    Why this is correct

    SNMPv3 aside, v1/v2c authentication relies solely on the community string, and the firewall only answers managers whose source IP is in the permitted list. A wrong string or missing manager address silently drops polls, producing exactly the no-data symptom, so verifying both in the server profile is the fastest first check.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.