PCNSE Manage, Monitor and Operate Practice Question
A company wants to forward logs from a firewall to a SIEM system with high reliability. Which log forwarding method ensures that logs are not lost if the SIEM is temporarily unreachable?
⚠ Common exam trap
Candidates often assume Syslog over TCP alone guarantees delivery, but without buffering enabled in the log forwarding profile, the firewall will drop logs if the TCP connection fails, making buffering the key differentiator for reliability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Syslog over TCP with buffering enabled in the log forwarding profile.
Syslog over TCP with buffering enabled in the log forwarding profile ensures reliable delivery because TCP provides acknowledgment and retransmission of lost segments, while the buffering mechanism stores logs locally on the firewall when the SIEM is unreachable and retransmits them once connectivity is restored. This combination prevents log loss during temporary network or SIEM outages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email (SMTP) for each log.
Why it's wrong here
SMTP per log generates one message per event, which the firewall cannot queue reliably or replay after an outage, and it floods the mail server. It is tempting because email alerting suits low-volume notification of critical events, not continuous high-volume log transport.
- ✓
Syslog over TCP with buffering enabled in the log forwarding profile.
Why this is correct
TCP provides session-oriented delivery with acknowledgements and retransmission, so the firewall detects an unreachable SIEM and holds logs in its buffer rather than dropping them. This directly satisfies the reliability constraint, unlike UDP-based syslog, which is fire-and-forget with no delivery guarantee.
- ✗
Syslog over UDP with a log forwarding profile.
Why it's wrong here
UDP syslog has no acknowledgement or retransmission, so datagrams sent while the SIEM is unreachable are silently discarded. It is tempting because UDP syslog is the default, low-overhead forwarding method, and would suffice where the SIEM is continuously reachable and occasional loss is tolerable.
- ✗
Syslog over SSL without optional buffering.
Why it's wrong here
TLS encrypts the transport but provides no on-device queueing, so logs generated during an outage are dropped rather than replayed. It is tempting because syslog over SSL secures log contents in transit, which would be the right choice when confidentiality, not delivery guarantee, is the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.