PCNSE Manage, Monitor and Operate Practice Question
Which TWO of the following are valid considerations when configuring Log Forwarding for Panorama? (Choose two.)
⚠ Common exam trap
Candidates often assume Log Forwarding is limited to a single destination or requires a syslog server, but Panorama actually supports multiple destinations and various log types without mandating syslog or TLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log forwarding supports sending logs to multiple destinations
Option C is correct because Panorama log forwarding profiles allow you to define multiple server entries (up to four syslog servers, plus SNMP, email, or HTTP destinations) within a single log forwarding profile, so logs can be sent to several destinations simultaneously. Option D is correct because log forwarding profiles are attached directly to security policy rules (via the Actions tab's Log Forwarding setting), enabling per-rule control over where that rule's traffic and threat logs are sent. Option A is incorrect because TLS encryption is not mandatory for log forwarding; syslog forwarding can use UDP or plain TCP, and TLS is only one optional transport choice. Option B is incorrect because an external syslog server is not required — logs can be forwarded to Panorama itself, to another managed firewall, or to email/SNMP/HTTP destinations. Option E is incorrect because log forwarding is not limited to a single Panorama collector; multiple destinations, including multiple Panorama or syslog targets, can be configured in one profile.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Log forwarding must use TLS encryption
Why it's wrong here
Log forwarding to Panorama does not mandate TLS; transport can be plain TCP or UDP depending on configuration, and encryption is optional. It is tempting because secure transport is desirable, and TLS would be the right consideration when forwarding logs to an external syslog server that requires encrypted delivery.
- ✗
Log forwarding requires an external syslog server
Why it's wrong here
Panorama can receive forwarded logs directly from managed firewalls without any external syslog server, so this is not a requirement. It is tempting because syslog forwarding is common, and an external syslog server would be the correct target when logs must be sent outside the Panorama deployment.
- ✓
Log forwarding supports sending logs to multiple destinations
Why this is correct
Panorama log forwarding profiles let you define multiple server entries within a single profile, so each log type can be dispatched to several collectors or syslog receivers simultaneously. This satisfies the requirement for redundancy or parallel retention without duplicating profiles.
- ✓
Log forwarding can be configured per security policy rule
Why this is correct
Log forwarding can be bound directly within a security policy rule's action settings, so matching traffic generates logs sent to the specified profile. This per-rule granularity satisfies the need to route logs from distinct rules to different destinations.
- ✗
Log forwarding can only send logs to a single Panorama collector
Why it's wrong here
Panorama can receive forwarded logs from many managed firewalls and multiple log collectors, so a single-collector limit is false. Log forwarding is designed to aggregate logs from numerous devices. It would be the right approach when centralising logs from many firewalls into one or more collectors.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.