PCNSE Manage, Monitor and Operate Practice Question
An administrator needs to ensure that the firewall sends an alert to an external server whenever a critical threat is detected, and also wants to receive a daily summary of blocked traffic. Which two log forwarding destinations should be configured to satisfy both requirements?
⚠ Common exam trap
Watch out — candidates often confuse raw log streaming over syslog with an alerting mechanism, when a targeted notification requires a log forwarding profile with an email action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an email profile for the critical threat alerts and a scheduled report for the daily summary.
Critical threat alerts are event-driven and are best delivered through an email profile referenced by a log forwarding profile, which fires when a matching log is generated. A recurring summary of blocked traffic is a scheduled reporting task, produced by a report configured to run daily. Syslog streams raw events and does not produce summaries, and SNMP traps target device-level events rather than log content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an SNMP trap server profile for the daily summary and an email profile for the critical threat alerts.
Why it's wrong here
SNMP traps are designed for event notifications such as link state or resource thresholds, not for delivering formatted log summaries or threat log content. Email can deliver alerts, but pairing it with SNMP for the summary reverses the intended use and would not reliably produce a daily blocked-traffic report.
- ✗
Configure a syslog server profile for the critical threat alerts and a scheduled report for the daily summary.
Why it's wrong here
Syslog can carry threat logs to an external collector, but it delivers raw streamed events rather than a targeted alert, and the administrator specifically wants an alert when a critical threat is detected. The scheduled report portion is correct, but the alert mechanism chosen does not match the stated requirement.
- ✗
Configure a syslog server profile for the daily summary and an email profile for the critical threat alerts.
Why it's wrong here
Syslog can receive logs, but generating a consolidated daily summary requires scheduled reporting rather than raw log streaming. Email profiles send event-driven notifications and are not suited to a scheduled summary. This combination does not cleanly satisfy the daily summary requirement, which is better served by a report.
- ✓
Configure an email profile for the critical threat alerts and a scheduled report for the daily summary.
Why this is correct
Email profiles attached to a log forwarding profile can trigger notifications when matching threat logs are generated, satisfying the immediate alert requirement. Scheduled reports can be configured to run daily and include data such as blocked traffic, satisfying the summary requirement. Together they map directly to both needs.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.