PCNSE Practice Question: Managing Troubleshooting and High Availability
An engineer is deploying a new Palo Alto Networks firewall running PAN-OS 10.1 as a standalone device. The security team requires that the firewall forward syslog messages to an external server. After configuring the Syslog server profile and applying it to a Log Forwarding profile, the engineer notices that no logs are being received on the syslog server. The firewall's management interface can reach the syslog server on UDP port 514. Which action should the engineer take to resolve this issue?
⚠ Common exam trap
The trap here is assuming that configuring the Syslog server profile and Log Forwarding profile alone is sufficient, while overlooking that the security policy rules must have logging enabled to generate the logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable logging on the security policy rules that should generate the logs.
Log forwarding requires that the relevant security policy rules have logging enabled. Without logging, no traffic logs are generated, so nothing is sent to the syslog server even if the Syslog server profile and Log Forwarding profile are properly configured. Enabling logging on the security rules that handle the traffic of interest ensures that logs are created and then forwarded according to the Log Forwarding profile.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the syslog server's IP address to the firewall's management interface permitted IP list.
Why it's wrong here
The management interface permitted IP list restricts which IP addresses can access the firewall's management services (like SSH, HTTPS, SNMP). It does not control outbound syslog traffic. Since the firewall initiates the connection to the syslog server, the permitted IP list is irrelevant. The firewall can send syslog messages regardless of this list, provided that other configurations are correct.
- ✓
Enable logging on the security policy rules that should generate the logs.
Why this is correct
For logs to be forwarded, the originating security policy rules must have logging enabled at session end or at session start. Without logging enabled, no traffic logs are generated, so nothing is sent to the syslog server. Even if the Syslog server profile and Log Forwarding profile are correctly configured, the absence of logs means no forwarding occurs. Enabling logging on the relevant security rules is the necessary step.
- ✗
Configure a security policy rule that allows the management interface to send traffic to the syslog server.
Why it's wrong here
Security policy rules apply to traffic traversing the dataplane, not to traffic originating from the management plane. Management plane traffic is controlled by management interface settings, not security policies. Therefore, adding a security rule would not affect syslog forwarding from the firewall itself, and would not resolve the issue of logs not being sent.
- ✗
Configure a NAT policy to translate the firewall's management IP to an external IP address.
Why it's wrong here
NAT policies apply to traffic traversing the firewall's dataplane, not to management plane traffic. Syslog messages originate from the management interface and are sent directly using the management IP. NAT is not required for outbound management traffic, and adding a NAT rule would not affect syslog forwarding. The issue is unrelated to address translation.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.