Courseiva
Manage, Monitor and OperateeasyMultiple ChoiceObjective-mapped

PCNSE Manage, Monitor and Operate Practice Question

A network administrator notices that traffic from a specific internal subnet is not being logged to the firewall's system logs despite log forwarding being configured. The firewall is running PAN-OS 10.1. Which configuration is most likely causing the issue?

⚠ Common exam trap

It's easy for candidates to assume log forwarding configuration alone guarantees logs, overlooking the prerequisite that the security rule must have 'Log at Session End' enabled to generate the log entries that are then forwarded.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The traffic is being matched by a rule with 'Log at Session End' disabled.

In PAN-OS, a security policy rule must have 'Log at Session End' enabled to generate session-end logs. If this setting is disabled, the firewall will not log the traffic even if a log forwarding profile is applied. Since the administrator has confirmed log forwarding is configured, the most likely cause is that the specific rule matching the subnet's traffic has logging disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The subnet is not in the 'Log Destination' list.

    Why it's wrong here

    There is no such 'Log Destination' list; log forwarding profiles are applied per rule.

  • The traffic is being matched by a rule with 'Log at Session End' disabled.

    Why this is correct

    If logging is disabled on the rule, no logs are created, so forwarding has no effect.

  • Log forwarding profile is not applied to the security policy rule.

    Why it's wrong here

    Even if not applied, logs would still be generated locally; the issue is that no logs are generated at all.

  • The firewall's management plane is overloaded.

    Why it's wrong here

    This could cause log loss but not a complete absence of logs for a specific subnet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.