Courseiva

PCNSA Device Management and Services Practice Question

An organization needs to send threat logs to two different syslog servers: one for real-time alerts and one for long-term storage. They also need to send traffic logs to the long-term storage syslog only. They have configured two syslog server profiles. What is the correct approach?

⚠ Common exam trap

Test-takers frequently assume a single log forwarding profile can be assigned to multiple log types with different server destinations, but Palo Alto requires separate profiles to achieve selective routing, as a single profile applies all its servers to all logs it covers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create two separate log forwarding profiles, one for threat logs with both syslog profiles, and one for traffic logs with only the long-term storage profile.

Palo Alto Networks firewalls use separate log forwarding profiles to control which logs are sent to which syslog servers. By creating two profiles—one for threat logs that includes both syslog server profiles (real-time and long-term storage) and one for traffic logs that includes only the long-term storage profile—the organization can selectively route logs to meet their requirements. This approach leverages the firewall's ability to assign different log forwarding profiles to different log types, ensuring granular control over log distribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create two separate log forwarding profiles, one for threat logs with both syslog profiles, and one for traffic logs with only the long-term storage profile.

    Why this is correct

    Separate log forwarding profiles let each log type target distinct syslog servers. Threat logs reference both profiles for real-time alerting and archival, while traffic logs reference only the long-term profile, satisfying the selective routing requirement without duplicating server configuration.

  • ✗

    Use the default log forwarding settings and configure the syslog servers globally.

    Why it's wrong here

    Global syslog settings send all log types to every configured server, so traffic logs would reach the real-time alert server as well as long-term storage. Log forwarding profiles exist precisely to route log types selectively per rule. Global configuration suits environments where every server receives every log type.

  • ✗

    Create a single log forwarding profile with both syslog profiles and assign it to all rules.

    Why it's wrong here

    A single log forwarding profile applies identical syslog destinations to every matched rule, so traffic logs would also reach the real-time alert server, contradicting the requirement. Separate profiles per rule type are needed. It is tempting because one profile simplifies management when all log types share the same destinations.

  • ✗

    Configure each firewall rule to specify which syslog server to send logs to.

    Why it's wrong here

    Firewall rules reference log forwarding profiles, not syslog server profiles directly, so a rule cannot select an individual syslog server. The profiles must be bound into a forwarding profile first. Direct per-rule server selection would be tempting if granularity below the profile level were required.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.