PCNSE Manage, Monitor and Operate Practice Question
A systems administrator needs to configure log forwarding to an external syslog server for Security policies. Which two actions are required to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is that candidates mistakenly think a syslog server profile can be applied directly to a Security policy rule, but the PCNSE exam requires understanding that a Log Forwarding profile is the mandatory intermediary object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a syslog server profile under Device > Server Profiles > Syslog.
A syslog server profile must first be created under Device > Server Profiles > Syslog to define the external syslog server's IP address, port (default 514), and transport protocol (UDP/TCP). This profile is a prerequisite for any log forwarding to an external syslog server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a syslog server profile under Device > Server Profiles > Syslog.
Why this is correct
A syslog server profile is required to define the destination syslog server.
- ✗
Create an SNMP trap profile under Device > Server Profiles > SNMP Trap.
Why it's wrong here
SNMP trap profiles are used for SNMP notifications, not syslog forwarding.
- ✗
Directly apply the syslog server profile to each Security policy rule.
Why it's wrong here
Syslog server profiles cannot be directly applied to policy rules; they must be referenced via a Log Forwarding profile.
- ✗
Enable log forwarding under the firewall's Device > Setup > Logging and Reporting settings.
Why it's wrong here
There is no global log forwarding setting; it is configured per rule via Log Forwarding profiles.
- ✓
Create a Log Forwarding profile that references the syslog server profile and apply it to Security policy rules.
Why this is correct
The Log Forwarding profile ties the syslog server profile to the policy rule for forwarding logs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.