PCNSA Device Management and Services Practice Question
An administrator is configuring a Palo Alto Networks firewall to send logs to an external syslog server. The firewall has two virtual routers: VR1 for the internal network and VR2 for the internet. The syslog server is reachable only through VR1. Which configuration setting must be applied to ensure syslog messages are sent via VR1?
⚠ Common exam trap
The trap here is assuming that the log forwarding profile can select a virtual router, when in fact the source address in the syslog server profile determines the egress virtual router.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the syslog server profile, specify the source address as an interface in VR1, and ensure a route exists in VR1 for the syslog server.
To force syslog traffic through a specific virtual router, you must specify a source address in the syslog server profile that belongs to that virtual router. The firewall then uses that source address for outgoing syslog packets, and the virtual router associated with that interface will handle routing. This ensures the syslog server is reached via the intended path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Under Device > Server Profiles > Syslog, set the virtual router to VR1 for the syslog server profile.
Why it's wrong here
The syslog server profile configuration does not include a setting to specify a virtual router. It only defines the server address, port, format, and facility. The virtual router selection is handled elsewhere in the log forwarding configuration, not in the server profile itself. Therefore, this option is incorrect.
- ✗
In the log forwarding profile, configure the syslog server to use VR1 as the source interface.
Why it's wrong here
Log forwarding profiles do not have a setting to choose a virtual router or source interface directly. They only reference server profiles and define match criteria. The source interface for outgoing syslog is determined by the route lookup in the virtual router, not by the log forwarding profile. Thus, this option is not correct.
- ✗
Create a static route in VR1 for the syslog server IP address and ensure the firewall uses the management interface for logging.
Why it's wrong here
The management interface is typically used for management traffic and may not have access to VR1. Creating a static route in VR1 is necessary, but directing logs to the management interface would bypass VR1 and likely fail because the management interface is in the management virtual router. This option is incorrect because it misdirects the traffic.
- ✓
In the syslog server profile, specify the source address as an interface in VR1, and ensure a route exists in VR1 for the syslog server.
Why this is correct
The syslog server profile allows you to specify a source address (an interface or IP) that the firewall uses when sending syslog messages. By selecting an interface that belongs to VR1, the outgoing packets will be routed via VR1. Additionally, a route must exist in VR1 for the syslog server. This option correctly addresses the requirement.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.