Courseiva
Securing Traffic →hardMultiple Choice

PCNSA Securing Traffic Practice Question

A company uses a Palo Alto Networks firewall to secure outbound internet access. The security team wants to ensure that users cannot access malicious websites. They have configured a URL Filtering profile with the 'malware' category set to 'block' and attached it to a Security policy rule that allows web-browsing. However, users report that they can still access some known malicious sites that are categorized as 'malware'. What is the most likely reason?

⚠ Common exam trap

The trap here is assuming that attaching a URL Filtering profile to a rule is sufficient to block malicious sites, ignoring that HTTPS traffic requires decryption for URL inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'malware' category is set to 'block', but the site is using HTTPS and the firewall is not decrypting traffic, so the URL Filtering profile cannot inspect the URL.

URL Filtering can only block based on URL categories if the firewall can see the full URL. For HTTPS traffic, the URL is encrypted within the TLS session, so without SSL decryption, the firewall cannot inspect the URL and thus cannot enforce URL Filtering for those sites. The most likely reason users can access malicious HTTPS sites is that SSL decryption is not enabled. Enabling SSL Forward Proxy decryption would allow the firewall to see the URL and apply the URL Filtering profile correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The URL Filtering profile is attached to the wrong Security policy rule; there is a more specific rule above that allows the traffic without URL Filtering.

    Why it's wrong here

    If a more specific rule above allowed the traffic without URL Filtering, then all web-browsing traffic would bypass URL Filtering, not just some malicious sites. The scenario states that users can access some known malicious sites, implying that other sites are blocked. This suggests the profile is applied but not effective for HTTPS. A rule order issue would affect all sites, not just some.

  • ✗

    The URL Filtering profile is not applied because the Security policy rule does not have the correct source and destination zones.

    Why it's wrong here

    If the source and destination zones were incorrect, the rule would not match at all, and traffic would likely be denied or matched by another rule. Since users can access websites, the rule is matching and allowing traffic. The issue is specifically that some malicious sites are not blocked, so the problem is not zone matching but rather the URL Filtering configuration or action.

  • ✓

    The 'malware' category is set to 'block', but the site is using HTTPS and the firewall is not decrypting traffic, so the URL Filtering profile cannot inspect the URL.

    Why this is correct

    URL Filtering requires visibility into the HTTP request or HTTPS decryption to categorize and block based on URL. If HTTPS traffic is not decrypted, the firewall can only see the IP and port, not the full URL. Thus, sites in the 'malware' category accessed via HTTPS may not be blocked unless SSL decryption is enabled. This is a common oversight; without decryption, URL Filtering is ineffective for HTTPS.

  • ✗

    The URL Filtering profile is configured to block the 'malware' category, but the firewall's URL database is outdated and does not contain those sites.

    Why it's wrong here

    An outdated URL database could cause some sites to be miscategorized, but Palo Alto Networks updates the database frequently. Moreover, the scenario says the sites are known to be categorized as 'malware', implying the database recognizes them. The more likely issue is HTTPS decryption. While database staleness is possible, it is less common and not the primary reason in this context.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.