PCNSE Manage, Monitor and Operate Practice Question
An administrator needs every administrator login, configuration commit, and firewall restart to be recorded in a central location for an upcoming audit. The auditor requires that the records be queryable by username and timestamp, and that they be retained independently of the firewall's own log storage. Which action should the administrator take to meet these requirements?
⚠ Common exam trap
The trap here is assuming that any syslog forwarding configuration captures administrator activity, when only the audit log records management-plane actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Audit Log on the management plane and forward it to an external syslog server.
Administrative activity such as administrator logins, configuration commits, and reboots is recorded in the management-plane audit log, which includes the username and timestamp for each entry. To retain those records independently of the firewall's local storage, the audit log must be forwarded to an external syslog server, satisfying both the query and retention requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Audit Log on the management plane and forward it to an external syslog server.
Why this is correct
The audit log records administrative actions, including administrator logins, configuration commits, and system restarts, and each entry includes the username and a timestamp. Forwarding it to an external syslog server keeps the records independent of the firewall's local log storage, so the audit trail survives log rotation or device replacement and remains queryable for the auditor.
- ✗
Configure a Log Forwarding profile on the management interface to send system logs to an external server.
Why it's wrong here
Log Forwarding profiles are applied to Security, NAT, and other policy rules to forward session-related logs; they are not applied to the management interface and do not capture administrator activity. Even if system logs were forwarded, they would not include the commit and login records the audit requires, so this approach does not produce the needed audit trail.
- ✗
Configure a Syslog server profile under Device > Server Profiles > Syslog and attach it to the Management interface's log settings.
Why it's wrong here
Syslog server profiles forward traffic, threat, and system logs generated by dataplane events, but they are not the mechanism that records administrative actions such as logins, commits, and reboots. Attaching a Syslog profile to the management interface does not create an audit trail of configuration changes or administrator activity, so the auditor's requirement for queryable administrative records would not be satisfied.
- ✗
Create a custom report under Monitor > Manage Custom Reports that includes the configuration log and schedule it to be emailed daily.
Why it's wrong here
Custom reports draw from the traffic, threat, and other dataplane logs and are generated on a schedule; they do not capture management-plane administrative actions such as commits or reboots. Emailing a daily report also does not provide independent retention or the ability to query by username and timestamp on demand, so it fails the auditor's requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.