PCNSE Manage, Monitor and Operate Practice Question
An administrator receives an alert that a firewall's disk usage is at 85%. The administrator wants to reduce disk usage by automatically deleting older log files. Which action should be taken?
⚠ Common exam trap
A common mix-up: candidates confuse 'adding external storage' (Option A) as a solution for disk usage, but the question specifically asks for automatic deletion of older logs, not just expanding capacity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure log export and auto-deletion in Log Settings
The firewall's log settings allow administrators to configure automatic log export and auto-deletion policies. By enabling log export to an external server (e.g., syslog) and setting a retention period or disk usage threshold, the firewall will automatically purge older log files when disk usage reaches a specified limit, such as 85%. This directly addresses the need to reduce disk usage without manual intervention or disabling logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an external disk to the firewall
Why it's wrong here
Adding an external disk expands storage capacity but does not automatically delete older log files, so the 85% threshold would still be reached. It is tempting because it addresses disk pressure, and it would be correct when the requirement is to retain more logs rather than purge them.
- ✓
Configure log export and auto-deletion in Log Settings
Why this is correct
Log Settings controls log storage behaviour, including export to external servers and automatic deletion of older logs once thresholds are reached. Enabling auto-deletion directly reduces disk consumption, satisfying the requirement to reclaim space without manual intervention.
- ✗
Disable logging for non-critical traffic
Why it's wrong here
Disabling logging for non-critical traffic reduces the volume of new logs written, but it does not delete existing older log files, so the current 85% usage is not lowered automatically. It would be appropriate when the goal is to cut log generation at source, not to age out stored logs.
- ✗
Manually delete logs from the CLI
Why it's wrong here
Manually deleting logs from the CLI frees space once, but it is not automatic and does not recur as logs age, so the requirement for automatic deletion of older files is unmet. It would be the correct approach for a one-off emergency cleanup rather than ongoing retention management.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.