Read the rulebase top-down and identify which rule actually matches the session, then map the threat to the correct Security Profile. The single most important thing is rule order: the first matching rule wins, so a block rule below an allow rule never fires.
Start practicing
Securing Traffic — choose a session length
Free · No account required
Domain overview
Securing Traffic covers how the firewall classifies, decrypts, and inspects traffic after a session matches a Security policy rule. Questions use exhibits of rules and profiles, asking you to identify rule roles, pick the right Security Profile for a threat such as DNS tunneling, and explain why allowed traffic bypasses a block rule.
Exam objectives
Security policy rule roles and how rule order and match criteria determine which rule applies
Applying Security Profiles such as Anti-Spyware, Vulnerability Protection, URL Filtering, and DNS Security to traffic
SSL/TLS decryption methods including forward proxy and inbound inspection, and decryption policy exceptions
Why traffic is allowed despite a block rule, including rule order, negated match, or an earlier allow rule
Assuming a block rule takes effect when an earlier rule above it already matches and allows the session
Applying the wrong profile to DNS, such as URL Filtering instead of DNS Security, to stop DNS tunneling
Forgetting that decryption must be configured before content-based profiles can inspect encrypted sessions
Click any question to see the full explanation and answer options, or start a focused practice session above.
A network engineer is troubleshooting a drop in traffic from a critical application. The traffic is allowed by the security policy, but the firewall is dropping the packets. The engineer views the session log and sees that the session is being terminated due to 'tcp-non-syn'. What is the most likely cause?
2An organization wants to prevent data exfiltration via DNS tunneling. Which security profile should be applied to the outbound DNS traffic?
3A company has a firewall configured with multiple virtual routers. A user on a trusted network can ping the firewall's management IP but cannot reach an external server. The security policy allows the traffic. What is the most likely cause?
4An administrator needs to allow inbound SMTP traffic to a mail server located in the DMZ. The firewall has a public IP address on the external interface. Which configuration is necessary to ensure the mail server receives the traffic?
5Which TWO actions should be taken to protect against DNS tunneling? (Choose two.)
6Which TWO are valid methods to decrypt SSL/TLS traffic on a Palo Alto Networks firewall? (Choose two.)
7A security administrator notices traffic from an internal user to a known malicious IP address in the corporate network. The traffic is allowed despite a security rule that blocks traffic to that IP. The rule is in a rulebase with multiple rules, and the administrator verifies that the malicious IP is correctly listed in a custom object used by the rule. What is the most likely cause of this issue?
8Drag and drop the steps to perform a packet capture (tcpdump) on a Palo Alto Networks firewall using the CLI into the correct order.
9Match each PAN-OS component to its role.
10A network administrator wants to allow HTTP and HTTPS traffic from untrust zone to DMZ zone for a web server, but block all other traffic. What is the most efficient way to achieve this with a single rule?
11An organization has a security policy that allows all traffic from the corporate user zone to the internet, but they want to block access to social media sites only for a specific group of users in the HR department. What is the best approach?
12A company uses Palo Alto Networks firewall and wants to configure NAT to allow internal users to access the internet using a public IP address pool. Which NAT type should be used?
13A company is implementing SSL Decryption with a forward proxy for outbound traffic. They want to ensure that traffic to sensitive sites like banking is not decrypted. What is the correct configuration?
14When creating a security policy to block malware, which THREE profile types should be applied for comprehensive protection?
15Based on the exhibit, what is the role of the rule "Allow_Outbound"?
16A company wants to block all social media except LinkedIn. Which combination of URL filtering actions should be implemented?
17An organization has implemented SSL forward proxy decryption. Users on Windows workstations report that many HTTPS sites show certificate errors. The firewall's decryption policy is configured correctly. What is the most likely cause?
18A company's security policy uses application-based rules. However, some traffic from a new cloud application is being blocked even though the application is allowed in the rule. What should the administrator check first?
19An administrator wants to block traffic from a specific user using User-ID. What is required to identify users in security policies?
20Traffic between two internal zones is being dropped due to a security policy rule that blocks any traffic. However, the administrator needs to allow specific inter-zone traffic for a critical application. The allowed traffic is sourced from a special IP range. How should the administrator configure the security policy to permit only this traffic while still blocking other traffic?
21A company is using Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection) in their security policies. Malware is still getting through. What is a common misconfiguration that could cause this?
22Which TWO of the following are methods to identify users for User-ID? (Choose two.)
23Which THREE components are required to successfully decrypt outbound SSL traffic using forward proxy? (Choose three.)
24A network administrator is troubleshooting a connectivity issue. The firewall has a security rule that allows traffic from the Trust zone to the Untrust zone for the subnet 192.168.1.0/24 with application 'web-browsing'. However, users in that subnet cannot access any external websites. The administrator checks the logs and sees that the traffic is being blocked by a rule named 'Deny All' that is listed before the allow rule in the policy order. What is the most likely cause of the problem? The rule order is incorrect; the allow rule is below the 'Deny All' rule. The source address object for the allow rule is misconfigured with a wrong subnet mask. The application 'web-browsing' is not being properly identified by App-ID. The User-ID agent is overriding the allow rule and triggering a block action.
25A security administrator configures log forwarding to send threat logs to a central SIEM. The administrator creates a log forwarding profile that includes 'threat' and 'traffic' log types, and applies the profile to several security rules. After verifying, the SIEM receives logs for allowed traffic, but does not receive any logs for denied traffic. The administrator confirms that the deny rules also have the same log forwarding profile applied. What is the most likely cause of the missing denied traffic logs? The log forwarding profile is not configured to forward logs for denied sessions. The SIEM is not configured to receive syslog messages for deny actions. The firewall is logging only at session end and the deny sessions are not completing. The log forwarding profile only includes 'traffic' logs and not 'threat' logs.
26An organization wants to segment internal traffic between the Engineering and Finance departments and apply threat prevention. Which TWO actions should be taken? (Choose two.)
27A company recently deployed a Palo Alto Networks PA-220 firewall to secure outbound web access. The security policies include a rule named 'Allow-Web' with the following configuration: source zone 'Inside', destination zone 'Outside', application 'web-browsing', service 'application-default', action 'allow'. All other traffic is denied by a default deny rule. Users report that they can access most public websites, but they cannot access a partner's website hosted at 203.0.113.50 on TCP port 8080. Connections to this site time out. DNS resolution for the hostname works correctly. The firewall logs show that traffic from internal users to 203.0.113.50:8080 is not matching any rule and is being denied by the default deny rule. Which action should the administrator take to resolve the issue while adhering to security best practices?
28A security administrator at a hospital needs to allow clinicians to access a cloud-based electronic health record (EHR) system at ehr.example.com. The firewall must inspect the traffic for threats, but the EHR vendor requires that the firewall not decrypt the traffic due to strict patient data privacy regulations. Which Security policy rule configuration should the administrator implement?
29A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal users and the internet. The security team wants to enforce different security profiles based on the destination country of outbound traffic. They have created a Security policy rule that allows web-browsing and ssl from the trust zone to the untrust zone. They now need to apply a URL Filtering profile that blocks malicious sites only when the destination IP is geolocated in a specific high-risk country. What should the administrator configure to achieve this?
30An administrator needs to allow DNS traffic from the Trust zone to the Untrust zone. The security policy rule uses the application 'dns' and service 'application-default'. Which port will be allowed by default?
31An administrator wants to block all peer-to-peer (P2P) file sharing applications while allowing other traffic. Which security policy action should be used to achieve this?
32A network security administrator is configuring a security policy rule to allow DNS traffic from the Trust zone to the Untrust zone. The rule uses application dns and service application-default. Users report that DNS queries to external servers are failing. The administrator notices that the firewall is allowing the DNS queries but the responses are being dropped. What is the most likely cause?
33A security administrator needs to create a policy that allows users in the 'trust' zone to access the internet, but blocks access to a specific set of known malicious URLs. The administrator has subscribed to a URL filtering service and wants to use a custom URL category to block the malicious sites. Which configuration should be used?
34A security administrator has configured a security policy rule to allow SSH from the Trust zone to the Untrust zone. The rule uses the application 'ssh' and the service 'application-default'. Users report that SSH connections to external servers on port 2222 are failing, while SSH on port 22 works. What is the most likely cause of the failure?
35An administrator has configured a security policy rule to allow traffic from the 'trust' zone to the 'untrust' zone with application 'any' and service 'any'. The administrator wants to ensure that the firewall logs all allowed traffic, but notices that not all sessions are being logged. What is the most likely reason?
36A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal zones. The security team wants to ensure that all traffic from the Users zone to the Servers zone is inspected for threats, but they also need to allow specific applications that use non-standard ports. They create a Security policy rule with 'application: any' and 'service: any', and attach a Vulnerability Protection profile. However, they notice that some traffic is not being inspected because it is being allowed by a more specific rule higher in the rulebase that allows only web-browsing and ssl. What should the administrator do to ensure all traffic is inspected?
37A network administrator is configuring a Security policy rule on a Palo Alto Networks firewall to allow HTTP traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that the rule only allows HTTP traffic on its default port. Which service setting should be used?
38A company uses a Palo Alto Networks firewall to secure outbound internet access. The security team wants to ensure that users cannot access malicious websites. They have configured a URL Filtering profile with the 'malware' category set to 'block' and attached it to a Security policy rule that allows web-browsing. However, users report that they can still access some known malicious sites that are categorized as 'malware'. What is the most likely reason?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Read the rulebase top-down and identify which rule actually matches the session, then map the threat to the correct Security Profile. The single most important thing is rule order: the first matching rule wins, so a block rule below an allow rule never fires.
The Courseiva PCNSA question bank contains 38 questions in the Securing Traffic domain, covering the 10% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Traffic domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included