Courseiva

PCNSE Core Concepts and Architecture Practice Question

Which TWO of the following are valid methods to collect logs from a Palo Alto Networks firewall for reporting and forensics?

⚠ Common exam trap

Many exam-takers confuse 'log collection' with 'alerting mechanisms' (SNMP traps and email alerts), assuming they can replace full log export, but Palo Alto firewalls require dedicated log forwarding methods (syslog, Panorama, or local export) for complete reporting and forensics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Local storage on the firewall's management disk (MP) and export via the web interface.

Option B is correct because the firewall's management plane (MP) can retain logs locally on its management disk, and administrators can retrieve them through the web interface (or CLI) for reporting and forensic review. Option E is correct because the firewall natively supports forwarding logs via syslog to external log collectors (e.g., a syslog server or Panorama in log-collector mode), which is a standard method for centralized reporting and forensics. Option A is not valid because Azure Sentinel does not ingest Palo Alto logs directly without an intermediate, such as a syslog forwarder, Log Analytics agent, or CEF connector. Option C is incorrect because SNMPv3 traps are used for monitoring/alerting on MIB objects, not for transporting full log records of all log types. Option D is incorrect because email alerts are notification-only and do not provide a complete, structured log collection mechanism for reporting and forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Export to Microsoft Azure Sentinel directly without any intermediate.

    Why it's wrong here

    The firewall cannot send logs straight to Microsoft Sentinel; it forwards to a log receiver such as syslog or Cortex Data Lake, which then feeds Sentinel. It tempts because Sentinel is a valid destination once an intermediary ingests the logs.

  • ✓

    Local storage on the firewall's management disk (MP) and export via the web interface.

    Why this is correct

    The management plane disk stores logs locally, and the web interface exports them for reporting and forensics. This satisfies the log collection requirement without external infrastructure, though retention is bounded by the firewall's on-box storage capacity.

  • ✗

    SNMPv3 traps for all log types.

    Why it's wrong here

    SNMPv3 traps carry only MIB-defined counters and status, not full log records with session detail, so they cannot supply reporting or forensic data. They tempt because SNMP traps genuinely serve device health monitoring and alerting, not log collection.

  • ✗

    Email alerts for all threat logs.

    Why it's wrong here

    Email alerts deliver only the threat logs matching a configured profile, giving no complete, queryable log store for forensics. They tempt because email alerting is a legitimate notification mechanism for high-severity threats, not a log-collection transport.

  • ✓

    Syslog to an external log collector.

    Why this is correct

    Forwarding logs via syslog to an external collector satisfies the collection requirement by streaming traffic, threat, and system logs off-box, enabling long-term retention and correlation for reporting and forensics beyond the firewall's local storage limits.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.