nerdexam
Palo_Alto_Networks

PCNSE · Question #877

A firewall administrator configures the HIP profiles on the edge firewall where GlobalProtect is enabled, and adds the profiles to security rules. The administrator wants to redistribute the HIP repor

The correct answer is A. HIP profiles are configured but not added to security rules in the data center firewall. C. HIP Match log forwarding is not configured under Log Settings in the device tab.. Two conditions must both be true for HIP match logs to appear on a firewall: (1) HIP profiles must be actively referenced in security rules on that firewall-if a HIP profile exists but is not attached to any security rule, the firewall never evaluates it and therefore never gener

Submitted by carlos_mx· Apr 18, 2026Configuration Troubleshooting

Question

A firewall administrator configures the HIP profiles on the edge firewall where GlobalProtect is enabled, and adds the profiles to security rules. The administrator wants to redistribute the HIP reports to the data center firewalls to apply the same access restrictions using HIP profiles. However, the administrator can only see the HIP match logs on the edge firewall but not on the data center firewall. What are two reasons why the administrator is not seeing HIP match logs on the data center firewall? (Choose two.)

Options

  • AHIP profiles are configured but not added to security rules in the data center firewall.
  • BUser ID is not enabled in the Zone where the users are coming from in the data center firewall.
  • CHIP Match log forwarding is not configured under Log Settings in the device tab.
  • DLog Forwarding Profile is configured but not added to security rules in the data center firewall.

How the community answered

(55 responses)
  • A
    73% (40)
  • B
    18% (10)
  • D
    9% (5)

Explanation

Two conditions must both be true for HIP match logs to appear on a firewall: (1) HIP profiles must be actively referenced in security rules on that firewall-if a HIP profile exists but is not attached to any security rule, the firewall never evaluates it and therefore never generates a HIP match log entry (choice A); and (2) HIP Match log forwarding must be explicitly enabled under Device > Log Settings-even if HIP matches occur, the firewall will not record or forward those log entries unless this setting is configured (choice C). Choice B (User-ID zone enablement) affects user mapping, not HIP log visibility. Choice D (Log Forwarding Profile) controls where logs are sent externally, but the absence of HIP match logs entirely points to the profile not being applied to rules and logging not being enabled at the device level.

Topics

#GlobalProtect#HIP Profiles#Log Forwarding#Security Rules

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice