Courseiva

PCNSE Practice Question: Managing Troubleshooting and High Availability

An engineer is deploying a new Palo Alto Networks firewall running PAN-OS 10.1 as a standalone device. The security team requires that the firewall forward syslog messages to an external server. After configuring the Syslog server profile and applying it to a Log Forwarding profile, the engineer notices that no logs are being received on the syslog server. The firewall's management interface can reach the syslog server on UDP port 514. Which action should the engineer take to resolve this issue?

⚠ Common exam trap

The trap here is assuming that configuring the Syslog server profile and Log Forwarding profile alone is sufficient, while overlooking that the security policy rules must have logging enabled to generate the logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable logging on the security policy rules that should generate the logs.

Log forwarding requires that the relevant security policy rules have logging enabled. Without logging, no traffic logs are generated, so nothing is sent to the syslog server even if the Syslog server profile and Log Forwarding profile are properly configured. Enabling logging on the security rules that handle the traffic of interest ensures that logs are created and then forwarded according to the Log Forwarding profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the syslog server's IP address to the firewall's management interface permitted IP list.

    Why it's wrong here

    The management interface permitted IP list restricts which IP addresses can access the firewall's management services (like SSH, HTTPS, SNMP). It does not control outbound syslog traffic. Since the firewall initiates the connection to the syslog server, the permitted IP list is irrelevant. The firewall can send syslog messages regardless of this list, provided that other configurations are correct.

  • ✓

    Enable logging on the security policy rules that should generate the logs.

    Why this is correct

    For logs to be forwarded, the originating security policy rules must have logging enabled at session end or at session start. Without logging enabled, no traffic logs are generated, so nothing is sent to the syslog server. Even if the Syslog server profile and Log Forwarding profile are correctly configured, the absence of logs means no forwarding occurs. Enabling logging on the relevant security rules is the necessary step.

  • ✗

    Configure a security policy rule that allows the management interface to send traffic to the syslog server.

    Why it's wrong here

    Security policy rules apply to traffic traversing the dataplane, not to traffic originating from the management plane. Management plane traffic is controlled by management interface settings, not security policies. Therefore, adding a security rule would not affect syslog forwarding from the firewall itself, and would not resolve the issue of logs not being sent.

  • ✗

    Configure a NAT policy to translate the firewall's management IP to an external IP address.

    Why it's wrong here

    NAT policies apply to traffic traversing the firewall's dataplane, not to management plane traffic. Syslog messages originate from the management interface and are sent directly using the management IP. NAT is not required for outbound management traffic, and adding a NAT rule would not affect syslog forwarding. The issue is unrelated to address translation.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.