PCNSA Policy Evaluation and Management Practice Question
A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?
⚠ Common exam trap
The trap here is the common misconception that rule order does not matter or that a deny rule can be placed before an allow rule without blocking the intended traffic; candidates forget that firewalls evaluate top-down and stop at the first match.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an allow rule for internal source addresses, then a deny rule for any source.
The correct structure is to create an allow rule for internal source addresses first, then a deny rule for any source. Firewalls evaluate rules top-down and stop at the first match, so placing the specific allow rule before the broad deny ensures internal users are permitted while all other traffic, including external IPs, is denied by the subsequent catch-all deny. This implements a whitelist model with an explicit deny-all fallback, which is the recommended security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a deny rule for external IP addresses, then an allow rule for internal.
Why it's wrong here
If the deny rule matches external IPs first, it is fine; but if the external IP range is broad, it might also match internal if not careful. More importantly, the allow rule for internal must be before the deny to ensure internal traffic is not denied.
- ✗
Place the allow rule after the deny rule.
Why it's wrong here
If the deny rule is first, it would block all traffic, including internal, before reaching the allow rule.
- ✓
Create an allow rule for internal source addresses, then a deny rule for any source.
Why this is correct
Security rules evaluate top-down, so placing the internal allow rule first permits trusted users, then the trailing deny rule blocks all remaining external sources. This satisfies the stem's split requirement for internal access and external restriction.
- ✗
Create a single rule with a 'Deny' action and apply a user-ID condition.
Why it's wrong here
A user-ID condition cannot match external source IP addresses, so the deny rule would never trigger for anonymous internet traffic; user-ID requires the firewall to map an IP to an authenticated directory user, which external attackers lack. It is tempting because user-ID rules are the right tool when access must follow named internal users rather than network location.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.