Palo Alto Networks (PANW) Certified Network Security Administrator (PCNSA) Practice Exam

Disable ads (and more) with a membership for a one time $4.99 payment

Prepare for the Palo Alto Networks Certified Network Security Administrator Exam with flashcards and multiple choice questions. Each question includes hints and explanations to boost your confidence and readiness!

Practice this question and more.


What is the remaining step for the security engineer to optimize syslog message forwarding after deploying the M-100 appliances?

  1. Enable individual syslog forwarding on each firewall

  2. Configure Collector Log Forwarding

  3. Install additional M-100 appliances

  4. Revert to individual syslog configurations

The correct answer is: Configure Collector Log Forwarding

The choice to configure Collector Log Forwarding is the correct step to optimize syslog message forwarding after deploying the M-100 appliances. The M-100 is a central management appliance designed by Palo Alto Networks to streamline and enhance the management of multiple firewalls. One of its primary functions includes consolidating logs from various sources, and configuring Collector Log Forwarding allows these logs to be efficiently collected and sent to the M-100 for centralized management and analysis. By utilizing Collector Log Forwarding, the security engineer can take full advantage of the capabilities offered by the M-100 appliance, such as improved performance in log handling, enhanced analysis tools, and the ability to correlate logs from multiple firewalls. This centralizes and simplifies log management, leading to better insights and reporting. In contrast, enabling individual syslog forwarding on each firewall would create a decentralized logging environment, which is contrary to the purpose of deploying the M-100. Installing additional M-100 appliances may not be necessary for optimizing the existing setup if the current infrastructure can handle the log management effectively. Lastly, reverting to individual syslog configurations would negate the benefits of having a centralized model with the M-100 appliance and would not contribute to optimization in this context.