Courseiva
Securing TrafficmediumMultiple ChoiceObjective-mapped

PCNSA Securing Traffic Practice Question

A company configures GlobalProtect for remote access. Remote users can successfully connect to the firewall and obtain an IP address, but they cannot access internal resources (e.g., file servers) located in the internal network. The firewall has a security rule that allows traffic from the GlobalProtect zone to the internal zone with appropriate applications. Logs show that traffic from remote users is being matched to a different rule that denies inter-zone traffic from the GlobalProtect zone to the internal zone. The administrator checks the GlobalProtect gateway configuration and sees that the gateway assigns IP addresses from a pool, but no internal routes are defined. What is the most likely issue? The GlobalProtect gateway configuration is missing internal resource routes or split-tunneling settings. The User-ID agent is not mapping remote usernames correctly. The source zone in the security rule is set to 'Trust' instead of 'GlobalProtect'. The internal resources require a specific security profile that is not applied to the rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The source zone in the security rule is set to 'Trust' instead of 'GlobalProtect'.

The logs show traffic from remote users is being matched to a rule that denies inter-zone traffic from GlobalProtect to internal, meaning the intended allow rule is not matching. If the security rule's source zone is set to 'Trust' instead of 'GlobalProtect', traffic sourced from the GlobalProtect zone will not match that rule and will instead hit the default inter-zone deny rule. Option A is about security profiles, which would not cause a rule mismatch. Option B (User-ID) affects user mapping but not zone-based rule matching. Option C (routes/split-tunneling) affects routing but not policy matching; the users can connect and get IPs, so routing is working, but the traffic is being denied by policy, not routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The internal resources require a specific security profile that is not applied to the rule.

    Why it's wrong here

    Missing security profiles would affect threat detection, not basic access; logs would show allow action.

  • The User-ID agent is not mapping remote usernames correctly.

    Why it's wrong here

    User-ID issues would not cause traffic to match a deny rule; they affect policies based on user identification.

  • The GlobalProtect gateway configuration is missing internal resource routes or split-tunneling settings.

    Why it's wrong here

    Missing routes would cause no connectivity, but the logs show a rule match (deny), indicating policy issue.

  • The source zone in the security rule is set to 'Trust' instead of 'GlobalProtect'.

    Why this is correct

    If the rule expects source zone 'Trust', traffic from GlobalProtect zone won't match, and a subsequent deny rule blocks it.

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.