Courseiva

PCNSA Policy Evaluation and Management Practice Question

A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?

⚠ Common exam trap

The trap here is the common misconception that rule order does not matter or that a deny rule can be placed before an allow rule without blocking the intended traffic; candidates forget that firewalls evaluate top-down and stop at the first match.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an allow rule for internal source addresses, then a deny rule for any source.

The correct structure is to create an allow rule for internal source addresses first, then a deny rule for any source. Firewalls evaluate rules top-down and stop at the first match, so placing the specific allow rule before the broad deny ensures internal users are permitted while all other traffic, including external IPs, is denied by the subsequent catch-all deny. This implements a whitelist model with an explicit deny-all fallback, which is the recommended security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a deny rule for external IP addresses, then an allow rule for internal.

    Why it's wrong here

    If the deny rule matches external IPs first, it is fine; but if the external IP range is broad, it might also match internal if not careful. More importantly, the allow rule for internal must be before the deny to ensure internal traffic is not denied.

  • ✗

    Place the allow rule after the deny rule.

    Why it's wrong here

    If the deny rule is first, it would block all traffic, including internal, before reaching the allow rule.

  • ✓

    Create an allow rule for internal source addresses, then a deny rule for any source.

    Why this is correct

    Security rules evaluate top-down, so placing the internal allow rule first permits trusted users, then the trailing deny rule blocks all remaining external sources. This satisfies the stem's split requirement for internal access and external restriction.

  • ✗

    Create a single rule with a 'Deny' action and apply a user-ID condition.

    Why it's wrong here

    A user-ID condition cannot match external source IP addresses, so the deny rule would never trigger for anonymous internet traffic; user-ID requires the firewall to map an IP to an authenticated directory user, which external attackers lack. It is tempting because user-ID rules are the right tool when access must follow named internal users rather than network location.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.