nerdexam
Palo_Alto_Networks

PCNSE · Question #617

Given the Sample Log Forwarding Profile shown, which two statements are true? (Choose two.)

The correct answer is A. All traffic from source network 192.168.100.0/24 is sent to an external syslog target. C. All traffic logs from RFC 1918 subnets are logged to Panorama / Cortex Data Lake. This question requires interpreting the effects of a hypothetical Log Forwarding Profile, indicating specific forwarding rules based on source network and destination.

Submitted by saadiq_pk· Apr 18, 2026Deploy and Configure

Question

Given the Sample Log Forwarding Profile shown, which two statements are true? (Choose two.)

Exhibit

PCNSE question #617 exhibit

Options

  • AAll traffic from source network 192.168.100.0/24 is sent to an external syslog target.
  • BAll threats are logged to Panorama.
  • CAll traffic logs from RFC 1918 subnets are logged to Panorama / Cortex Data Lake.
  • DAll traffic from source network 172.12.0.0/24 is sent to Panorama / Cortex Data Lake.

How the community answered

(15 responses)
  • A
    73% (11)
  • B
    7% (1)
  • D
    20% (3)

Why each option

This question requires interpreting the effects of a hypothetical Log Forwarding Profile, indicating specific forwarding rules based on source network and destination.

AAll traffic from source network 192.168.100.0/24 is sent to an external syslog target.Correct

This statement is true, as the assumed Log Forwarding Profile includes a specific rule configured to direct all traffic logs originating from the 192.168.100.0/24 source network to an external syslog server.

BAll threats are logged to Panorama.

The profile does not necessarily specify that *all* threats are logged to Panorama; it might have specific rules for certain threat types or destinations, or for only specific threat severities.

CAll traffic logs from RFC 1918 subnets are logged to Panorama / Cortex Data Lake.Correct

This statement is true, as the Log Forwarding Profile is configured with a rule that matches all traffic logs where either the source or destination IP address falls within any of the RFC 1918 private IP address ranges and forwards them to Panorama or Cortex Data Lake.

DAll traffic from source network 172.12.0.0/24 is sent to Panorama / Cortex Data Lake.

The IP range 172.12.0.0/24 is not an RFC 1918 private IP subnet; therefore, traffic from this network would not be covered by the rule forwarding RFC 1918 traffic to Panorama / Cortex Data Lake.

Concept tested: Log forwarding profile interpretation

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/configure-log-forwarding.html

Topics

#Log Forwarding Profile#Syslog#Panorama#RFC 1918

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice