Courseiva
Managing ObjectsmediumMultiple ChoiceObjective-mapped

PCNSA Managing Objects Practice Question

A company uses a Palo Alto Networks firewall to control outbound access. They have created custom application filters to block social media and streaming. However, they need to allow a specific corporate YouTube channel for training videos. The administrator creates an application group "Corporate-YouTube" containing the "youtube-base" application, and adds a security rule to allow traffic from internal users to the application group. Despite this, users still cannot access the corporate YouTube channel. What is the most likely reason?

⚠ Common exam trap

Watch out — candidates often assume application-based rules override all other checks, but Palo Alto Networks firewalls evaluate URL filtering before App-ID, so a URL filtering block will prevent the application from being identified and allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall's URL filtering profile is blocking the category before application identification can occur.

The most likely reason is that the URL filtering profile is blocking the YouTube category before the firewall can identify the application. Palo Alto Networks firewalls process URL filtering before application identification in the security policy evaluation order. Even though the application group 'Corporate-YouTube' is allowed, the URL filtering profile (which is applied to the rule or as a default) will block the request if the URL category (e.g., 'streaming-media' or 'social-networking') is denied, preventing the traffic from reaching the application identification stage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The firewall's URL filtering profile is blocking the category before application identification can occur.

    Why this is correct

    URL filtering profiles can block based on URL category before the application is identified, preventing access even if the application is allowed.

  • The application group is not correctly associated with the security policy.

    Why it's wrong here

    If the group is correctly referenced, this is not the issue; the administrator likely added it correctly.

  • The application "youtube-base" is not recognized by the firewall.

    Why it's wrong here

    youtube-base is a built-in application and should be recognized.

  • The security rule allowing the application group is placed after a deny rule that blocks the "streaming" category.

    Why it's wrong here

    Rule order can cause issues, but the most typical problem is URL filtering pre-empting application allow.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.