Courseiva

PCNSE Manage, Monitor and Operate Practice Question

Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)

⚠ Common exam trap

Candidates often assume Log Forwarding is limited to a single destination or requires a syslog server, but Panorama actually supports multiple destinations and various log types without mandating syslog or TLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log forwarding supports sending logs to multiple destinations

Option C is correct because Panorama log forwarding profiles allow you to define multiple server entries (up to four syslog servers, plus SNMP, email, or HTTP destinations) within a single log forwarding profile, so logs can be sent to several destinations simultaneously. Option D is correct because log forwarding profiles are attached directly to security policy rules (via the Actions tab's Log Forwarding setting), enabling per-rule control over where that rule's traffic and threat logs are sent. Option A is incorrect because TLS encryption is not mandatory for log forwarding; syslog forwarding can use UDP or plain TCP, and TLS is only one optional transport choice. Option B is incorrect because an external syslog server is not required — logs can be forwarded to Panorama itself, to another managed firewall, or to email/SNMP/HTTP destinations. Option E is incorrect because log forwarding is not limited to a single Panorama collector; multiple destinations, including multiple Panorama or syslog targets, can be configured in one profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Log forwarding must use TLS encryption

    Why it's wrong here

    Log forwarding to Panorama does not mandate TLS; transport can be plain TCP or UDP depending on configuration, and encryption is optional. It is tempting because secure transport is desirable, and TLS would be the right consideration when forwarding logs to an external syslog server that requires encrypted delivery.

  • ✗

    Log forwarding requires an external syslog server

    Why it's wrong here

    Panorama can receive forwarded logs directly from managed firewalls without any external syslog server, so this is not a requirement. It is tempting because syslog forwarding is common, and an external syslog server would be the correct target when logs must be sent outside the Panorama deployment.

  • ✓

    Log forwarding supports sending logs to multiple destinations

    Why this is correct

    Panorama log forwarding profiles let you define multiple server entries within a single profile, so each log type can be dispatched to several collectors or syslog receivers simultaneously. This satisfies the requirement for redundancy or parallel retention without duplicating profiles.

  • ✓

    Log forwarding can be configured per security policy rule

    Why this is correct

    Log forwarding can be bound directly within a security policy rule's action settings, so matching traffic generates logs sent to the specified profile. This per-rule granularity satisfies the need to route logs from distinct rules to different destinations.

  • ✗

    Log forwarding can only send logs to a single Panorama collector

    Why it's wrong here

    Panorama can receive forwarded logs from many managed firewalls and multiple log collectors, so a single-collector limit is false. Log forwarding is designed to aggregate logs from numerous devices. It would be the right approach when centralising logs from many firewalls into one or more collectors.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.