Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.
Start practicing
Policy Evaluation and Management — choose a session length
Free · No account required
Domain overview
This domain covers how PAN-OS evaluates security policy: rule order, zone and address matching, application identification, and implicit rules. Questions present traffic scenarios—often with exhibits—and ask why traffic is allowed or denied, which rule is hit, or what the firewall does next.
Exam objectives
Interpreting security rule match criteria: source/destination zone, address, user, application, and service.
Using the Traffic log and session details to identify the rule that allowed or denied a session.
Applying App-ID and Service/Application Override behavior to determine whether a rule matches.
Understanding implicit intrazone and interzone default rules and rule-order evaluation.
Assuming a rule with application web-browsing matches all web traffic; App-ID may identify a different application and skip the rule.
Forgetting that a new subnet must be added to both the security rule and any NAT or routing configuration to work.
Overlooking the implicit deny or default intrazone allow rules when no explicit rule matches traffic.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?
2A network engineer needs to ensure that all traffic from the 'Guest' zone to the 'Internet' zone is inspected for malware, but also wants to allow high-bandwidth video conferencing traffic to bypass threat inspection for performance reasons. Which approach best achieves this?
3A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?
4A firewall administrator is tasked with implementing a policy that allows SSH access from the 'Admin' zone to the 'Core' zone only for specific administrators, and all other SSH attempts should be logged and dropped. The company has a large number of administrators. Which method is most efficient and scalable?
5Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)
6A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?
7A firewall administrator is troubleshooting a situation where traffic from the 'Engineering' zone (source zone) to the 'Servers' zone (destination zone) is being allowed, but the desired behavior is to block it. The administrator runs 'show running security-policy' and sees the following rules in order: Rule1: from Engineering to Servers allow; Rule2: from Engineering to Servers deny; Rule3: from any to Servers allow. Which TWO statements are true regarding policy evaluation?
8Drag and drop the steps to configure Active/Passive High Availability on a Palo Alto Networks firewall into the correct order.
9A network administrator notices that traffic from a specific subnet is being denied even though there is a permit rule that matches the source and destination. The rulebase has over 500 rules. What is the most likely cause?
10After a policy change, a security administrator commits the candidate configuration, but the changes do not take effect immediately for all users. Some users report connectivity issues while others do not. What should the administrator check first?
11A company wants to block file-sharing applications like BitTorrent, but allow HTTP and HTTPS. Which type of policy is most appropriate to achieve this granular control?
12An administrator is troubleshooting why a rule is not being hit. The rule has source zone Trust, destination zone Untrust, source address 10.0.0.0/8, destination address any, application web-browsing, action allow, and log at session end. The traffic is coming from 10.1.1.1 to 1.2.3.4 on port 80, zone Trust to Untrust. The rule count shows zero hits. What could be the issue?
13What does a 'shadowed' rule mean in the context of policy evaluation?
14How can an administrator quickly identify which security rules are not being used in order to clean up the rulebase?
15Refer to the exhibit. An administrator is analyzing the rulebase. Traffic from source 10.1.1.5 to destination 8.8.8.8 using web-browsing application (HTTP TCP/80). Which rule will match?
16Refer to the exhibit. The administrator sees that traffic from 10.10.1.12 is being denied by rule2. Which action should the administrator take to allow this traffic while maintaining security?
17A company is migrating from a legacy firewall to a Palo Alto Networks firewall. The legacy policy has many rules with overlapping source and destination objects. Which feature should the administrator use to simplify the policy before migration?
18An administrator configures a security policy with three rules in order: Rule1 allows any to any with log at session start, Rule2 allows HTTP from trust to untrust, Rule3 denies any. Traffic from an internal user to an external web server is logged as allowed. Which rule processed the traffic?
19An administrator wants to ensure that all traffic from the engineering zone to the server zone is logged, but only when a session is established. Which log setting should be configured in the security rule?
20A security administrator is troubleshooting a rule that appears to be matching correctly but is not allowing traffic. The rule uses source zone 'Trust' and destination zone 'Untrust', and the action is 'allow'. The traffic source is in the 'DMZ' zone. What is the most likely reason the traffic is denied?
21An administrator needs to implement a policy where traffic from the 'Sales' zone to the 'Finance' zone is allowed only for the 'ms-office365' application, but traffic from 'Sales' to 'Finance' using any other application must be denied. Which rule design meets this requirement efficiently?
22An administrator is reviewing the rulebase and finds a rule with a hit count of 0 over the past 30 days. What action should the administrator consider?
23A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?
24Which TWO are best practices for managing security policies in a Palo Alto Networks firewall?
25A network administrator adds a new security rule allowing HTTP from the Trust zone to the Untrust zone. After committing, traffic from the Trust zone to the Untrust zone is still blocked. What is the most likely cause?
26A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?
27Which THREE actions can be taken based on hit counts in security rules? (Select three.)
28Which TWO methods can be used to help prevent rule shadowing? (Select two.)
29A company has a Palo Alto Networks firewall with multiple virtual routers. The security policy has a rule that allows SSH from the 'Internal' zone to the 'DMZ' zone. Recently, a new subnet 10.10.20.0/24 was added to the Internal zone. Users in that subnet report they cannot SSH to a server at 192.168.1.10 in the DMZ, while users from other subnets in Internal can. The rule has source address object '10.0.0.0/8' which includes the new subnet. The rule's source zone is Internal, destination zone is DMZ, and application is SSH. The administrator confirms the new subnet's IPs are within 10.0.0.0/8. What is the most likely cause of the problem?
30A small business has a Palo Alto Networks firewall with a single security policy rule that allows all traffic from the 'Trust' zone to the 'Untrust' zone. The business recently experienced a malware infection originating from an internal host that communicated with known malicious IP addresses. The administrator wants to implement a security policy to block traffic to these malicious IP destinations. The administrator has a list of 500 malicious IP addresses that may change frequently. What is the most efficient way to create a policy to block traffic to these IPs?
31An administrator needs to allow a specific set of external IP addresses to access an internal web server on port 443, but all other traffic to that server must be blocked. The administrator creates a security policy rule that allows the specific IP addresses and places it at the bottom of the rulebase. What will be the result?
32An administrator is creating a new security rule at the top of the rulebase to allow specific web traffic. After committing, users report that all web traffic is now blocked, including traffic that was previously allowed by a lower rule. The new rule's action is set to 'Deny' and its source and destination are set to 'any'. What is the most likely cause?
33An administrator wants to ensure that a security policy rule is only active during business hours (9 AM to 5 PM) on weekdays. Which configuration element should be used?
34An administrator has configured a security rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for specific applications. The rule is placed at position 5 in the rulebase. A user reports that traffic matching this rule is being denied. Upon inspection, the administrator finds that a rule at position 3 denies all traffic from 'Trust' to 'Untrust' for any application. What is the most likely cause of the denial?
35A security administrator is configuring a rule to allow access to a web application hosted on multiple servers with changing IP addresses. The administrator wants to ensure the rule automatically updates as the IP addresses change, without manual intervention. Which feature should be used?
36An administrator is reviewing the security policy on a Palo Alto Networks firewall and notices that a rule allowing web browsing from the Trust zone to the Untrust zone has no application specified. The administrator wants the firewall to permit only web-browsing and ssl while blocking all other applications on ports 80 and 443. What should the administrator do to meet this requirement?
37An administrator is configuring a security policy to allow access to a critical application. The application uses multiple protocols and dynamic ports. The administrator wants to ensure that the policy is as secure as possible while allowing legitimate traffic. Which two actions should the administrator take? (Choose two.)
38A network security administrator is reviewing the security policy on a Palo Alto Networks firewall. The administrator wants to ensure that traffic from the Trust zone to the Untrust zone is inspected by a specific security profile group. Which policy component should the administrator configure to attach the security profile group?
39A network security administrator at a university wants to allow students in the 'Student' zone to access the internet, but only during exam periods should they be blocked from social media. The administrator creates a security rule at the top of the rulebase that denies social media applications from the Student zone to the Internet zone and schedules it to be active only during exam weeks using a schedule object. Which statement correctly describes the evaluation of this rule?
40An administrator is reviewing the security policy and notices a rule that allows all traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only web browsing (HTTP and HTTPS) is allowed, while all other traffic is blocked. What should the administrator do?
41A security administrator is configuring a policy to allow access from the Guest zone to the Internet zone. The administrator wants to ensure that only HTTP and HTTPS traffic is allowed, and all other traffic is blocked. The administrator creates a rule with source zone Guest, destination zone Internet, application web-browsing and ssl, and action Allow. However, users report that they cannot access websites. What is the most likely cause?
42An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?
43A security administrator is configuring a security policy rule to allow access to a web server from the internet. The rule is set to allow HTTP and HTTPS traffic to the server's public IP address. However, after committing the change, users report that they cannot access the web server from the internet. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit rule. What is the most likely cause of the issue?
44An administrator is designing a security policy for a Palo Alto Networks firewall. The administrator wants to ensure that the policy is efficient and follows best practices for rule evaluation. Which two actions should the administrator take? (Choose two.)
45An administrator has created a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web browsing. Users in the Guest zone report that they can access some websites but not others. The administrator checks the traffic logs and sees that some sessions are being denied by the implicit deny rule. What is the most likely reason?
46An administrator is configuring a security rule that allows access from the Trust zone to the DMZ zone for a specific application. The administrator wants to ensure that the rule only allows the application on its default port and blocks the application if it attempts to use a non-standard port. Which setting should be used in the Service column of the security rule?
47An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)
48A security administrator is configuring a rule to allow access to a web server. The rule uses a URL category as the destination. The administrator notices that the rule is not matching traffic to the web server's IP address when users connect directly via IP. What is the most likely reason?
49A security administrator is reviewing the rulebase and notices that a rule allowing traffic from the 'Trust' zone to the 'Untrust' zone has the action set to 'Allow' but is not being hit. The administrator confirms that there is traffic matching the source and destination zones, addresses, and applications. What is the most likely reason the rule is not being hit?
50An administrator has configured a security policy with a rule that allows traffic from the 'Guest' zone to the 'Internet' zone. The rule uses the application 'web-browsing' and 'ssl' with service 'application-default'. Users in the Guest zone report that they cannot access a specific website that uses a non-standard port for HTTPS (port 8443). What is the most likely cause of the issue?
51A firewall administrator is reviewing the security policy and notices that a rule allowing DNS from the Trust zone to the Untrust zone has a hit count of zero. The administrator confirms that DNS traffic is being generated and that the rule is enabled. Which action should the administrator take to troubleshoot why the rule is not being hit?
52A network security administrator needs to create a rule that allows DNS traffic from the Trust zone to the Untrust zone. Which application should be selected in the security rule to allow DNS?
53An administrator is troubleshooting why a security rule that allows traffic from the Trust zone to the DMZ zone is not being hit. The administrator confirms that the source IP, destination IP, and application are correct. Which factor should the administrator check next to determine why the rule is being bypassed?
54An administrator has configured a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web-browsing and ssl applications. The rule is placed at the top of the rulebase. Users in the Guest zone report that they can access websites but cannot use other applications like SSH or FTP. Which statement explains this behavior?
55An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?
56An administrator is auditing the security policy on a PA-3220 firewall. The administrator notices that a rule allowing RDP from the 'Trust' zone to the 'DMZ' zone has a source user of 'domain\jdoe' and is positioned below a broader rule that allows any application from Trust to DMZ for any user. The administrator wants the user-specific rule to be evaluated first. What is the most efficient way to achieve this?
57An administrator is configuring a security policy on a Palo Alto Networks firewall. The administrator wants to allow only HTTP and HTTPS traffic from the Trust zone to the Untrust zone, and block all other applications. The administrator creates a rule with source zone Trust, destination zone Untrust, application 'web-browsing' and 'ssl', action allow. However, after committing, users can still access other applications like SSH. What is the most likely explanation?
58A firewall administrator is reviewing the security policy and notices that a rule allowing traffic from the Trust zone to the DMZ zone is not being hit. The rule is placed after a rule that denies all traffic from Trust to DMZ. What is the most likely explanation?
59A network security administrator is configuring a security policy on a PA-5220 firewall. The administrator wants to allow HTTP and HTTPS traffic from the 'Guest' zone to the 'Internet' zone, but only for specific users in the 'guest-users' group. The administrator creates a rule with source zone 'Guest', destination zone 'Internet', source user 'guest-users', and application 'web-browsing' and 'ssl'. However, when testing, all Guest users can access the Internet, not just those in the group. What is the most likely cause?
60A security administrator is configuring a Palo Alto Networks firewall with a security policy that allows traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only specific users can access certain applications. The administrator creates a rule with source zone Trust, destination zone Untrust, source user 'domain\jdoe', application 'web-browsing', action allow. However, after committing, the user jdoe reports that they cannot access the web. The administrator checks the traffic logs and sees that the traffic is being denied by the implicit rule. What is the most likely cause?
61An administrator is designing a security policy for a new branch office. The policy must allow outbound web traffic from the Trust zone to the Untrust zone, but only for specific users in the 'Marketing' group. The firewall is integrated with Active Directory. Which TWO configurations are required to enforce this policy? (Choose two.)
62A security administrator is troubleshooting why a security rule that allows traffic from the 'Trust' zone to the 'DMZ' zone is not being matched. The administrator confirms that the source IP, destination IP, and application are correct. The rule is placed at the top of the rulebase. What is the most likely reason the rule is not being hit?
63A security administrator is reviewing the security policy on a PA-220 firewall. The administrator notices that a rule allowing DNS from the 'Trust' zone to the 'Untrust' zone is being shadowed by a rule above it that denies all traffic from 'Trust' to 'Untrust'. What is the term for this situation?
64An administrator is configuring a security policy on a PA-3260 firewall. The administrator wants to ensure that a rule allowing SSH from the 'Management' zone to the 'Internal' zone is only active during business hours (9 AM to 5 PM) on weekdays. The administrator creates a schedule object named 'BusinessHours' and attaches it to the rule. However, after applying the policy, SSH access is allowed at all times. What is the most likely reason?
65An administrator is troubleshooting why a security rule is not being hit. The rule is for traffic from the 'Trust' zone to the 'Untrust' zone, source address 10.1.1.0/24, destination address any, application 'web-browsing', service 'application-default', action allow. The traffic in question is from 10.1.1.5 to 8.8.8.8 on port 80. The administrator checks the traffic logs and sees that the session is being denied by the interzone default rule. What is the most likely cause?
Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.
The Courseiva PCNSA question bank contains 65 questions in the Policy Evaluation and Management domain, covering the 28% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Policy Evaluation and Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included