Courseiva
Securing Traffic →mediumMultiple Choice

PCNSA Securing Traffic Practice Question

A company is using Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection) in their security policies. Malware is still getting through. What is a common misconfiguration that could cause this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The profiles are set to 'alert' instead of 'block' for the critical threat categories.

If Security Profiles (Antivirus, Anti-Spyware, Vulnerability Protection) are set to 'alert' instead of 'block' for critical threat categories, the firewall will generate alerts but will not block the malware. This is a common misconfiguration that allows malware to pass through. Option B is incorrect because while outdated signatures can reduce effectiveness, the question specifically asks about a common misconfiguration, and alert vs. block is a more frequent oversight. Option C is incorrect because if profiles are not attached to any security rule, they would not be applied at all, but the scenario implies they are attached. Option D is incorrect because the order of profile groups within a rule does not affect blocking; all profiles are applied simultaneously.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The profiles are set to 'alert' instead of 'block' for the critical threat categories.

    Why this is correct

    Profiles configured to alert rather than block generate threat logs but permit the traffic to continue, so malware reaches endpoints despite the security policy. Changing critical threat categories to block enforces the intended prevention action.

  • ✗

    The antivirus signatures are outdated.

    Why it's wrong here

    Outdated signatures leave known threats undetected, but the stem’s profiles already cover those vectors; the actual gap is traffic bypassing inspection entirely, such as applications excluded from decryption or profiles applied only to allow rules. Signature updates are the correct fix when new malware variants evade otherwise correctly scoped, decrypted traffic.

  • ✗

    The security profiles are not attached to any security rule.

    Why it's wrong here

    Profiles only inspect traffic when referenced by a security rule; unattached profiles are never evaluated, so malware passes uninspected. It is tempting because the profiles exist and appear configured, but Palo Alto Networks applies profiles per-rule, so an unbound profile has no effect on traffic.

  • ✗

    The profile groups are applied in the wrong order.

    Why it's wrong here

    Profile groups are containers for security profiles, not ordered stages, so no sequence exists to misconfigure. The tempting association is policy rule ordering, where Palo Alto evaluates rules top-down and a permissive rule above a block rule lets traffic bypass inspection — but that concerns rules, not the profile group itself.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.