Generate Tech Support File for TAC Analysis
A firewall is experiencing performance issues. The administrator wants to collect diagnostic data for TAC analysis. Which command generates a comprehensive support file?
Quick Answer
The correct answer is 'generate tech-support file' because it is purpose-built to produce exactly what a TAC engineer needs to diagnose a performance issue: a single consolidated archive pulling together system logs, the running configuration, resource utilization statistics, and other diagnostic data from across the firewall. Performance problems in particular can stem from many different subsystems, so instead of manually gathering CPU, memory, session, and log data through several separate commands, this single command bundles everything into one file that can be handed off for offline analysis. That comprehensiveness is what sets it apart from commands that only capture a narrow slice of data, such as real-time resource monitoring or a single log stream, which might show a symptom but wouldn't give TAC the broader system context needed to correlate cause and effect. It's also distinct from configuration-only exports, since a support file includes runtime and diagnostic data that a plain configuration backup would not. Whenever a scenario asks for the single best way to hand comprehensive diagnostic information to Palo Alto Networks support for a hard-to-pin-down issue like a performance problem, the tech-support file is almost always the answer, since it exists specifically to serve as the standard, complete input format TAC expects.
⚠ Common exam trap
Palo Alto Networks often tests the distinction between commands that provide real-time snapshots (like 'show system resources') versus commands that generate a comprehensive diagnostic archive (like 'generate tech-support file'), leading candidates to mistakenly choose a command that only shows current state rather than the full dataset needed for TAC analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
generate tech-support file
The 'generate tech-support file' command collects a comprehensive archive of system logs, configuration, resource utilization, and diagnostic data into a single file, which is the standard method for providing TAC with the necessary information to analyze performance issues. This command is specifically designed for troubleshooting and support scenarios, unlike other commands that only capture partial or real-time data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
debug system dump
Why it's wrong here
This is used for debugging specific issues, not for general support.
- ✗
show system resources
Why it's wrong here
This shows real-time resource usage but does not generate a file.
- ✗
show log system
Why it's wrong here
This displays system logs but does not generate a file for TAC.
- ✓
generate tech-support file
Why this is correct
This creates a support file in the opt directory.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PCNSE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator needs to generate a tech support file for TAC. Which CLI command accomplishes this?
easy- A.debug generate dump
- ✓ B.generate tech-support
- C.show tech-support
- D.request tech-support
Why B: The correct command to generate a tech support file on Palo Alto Networks firewalls is 'generate tech-support'. This command collects all relevant logs, configurations, and diagnostic data into a single archive file for TAC analysis. The 'generate' keyword is specific to Palo Alto's CLI syntax for creating output files, unlike Cisco's 'show' or 'request' commands.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.