PCNSE Manage, Monitor and Operate Practice Question
A security administrator needs to ensure that the firewall sends an email notification to the security team whenever a critical threat is detected. The email server is reachable at 10.10.10.5, and the firewall's management interface is in the 10.10.10.0/24 subnet. Which configuration step is required to enable email notifications for critical threats?
⚠ Common exam trap
The trap here is assuming that Log Forwarding profiles can directly send email without an Email server profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an Email server profile under Device > Server Profiles > Email and then attach it to a Log Forwarding profile used in the security policy.
The correct approach is to create an Email server profile that defines the SMTP server, and then reference that profile within a Log Forwarding profile. The Log Forwarding profile is then attached to the security policy that logs the critical threats. This ensures that when a threat is detected, an email is sent. Other options involve different server types that do not provide email functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Syslog server profile under Device > Server Profiles > Syslog and set the severity level to critical.
Why it's wrong here
Syslog is used to send logs to a syslog server, not to send email. Even if you set the severity to critical, it would not generate an email. This option does not meet the requirement of email notification.
- ✓
Configure an Email server profile under Device > Server Profiles > Email and then attach it to a Log Forwarding profile used in the security policy.
Why this is correct
To send email notifications for threats, you must create an Email server profile with the SMTP server details and then reference it in a Log Forwarding profile. The Log Forwarding profile is then applied to the security policy that matches the traffic. This is the standard method for email alerting on critical threats.
- ✗
Configure a Log Forwarding profile under Objects > Log Forwarding and enable email notifications directly in the profile.
Why it's wrong here
While Log Forwarding profiles are used to forward logs, they do not directly contain email settings. You must first create an Email server profile and then reference it in the Log Forwarding profile. This option omits the necessary Email server profile creation.
- ✗
Configure an SNMP trap destination under Device > Server Profiles > SNMP and enable traps for critical threats.
Why it's wrong here
SNMP traps are used for network management notifications, not for sending email. While SNMP can alert on system events, it cannot send email notifications. This option does not fulfill the requirement of email notification for critical threats.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.