Courseiva
Policy Evaluation and ManagementmediumMultiple ChoiceObjective-mapped

PCNSA Policy Evaluation and Management Practice Question

A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an allow rule for DNS from Guest to Corporate, placed above a deny rule for any other traffic.

Best practice is to place the allow rule before the deny rule to ensure permitted traffic is not blocked by a broader deny rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a deny rule for any traffic from Guest to Corporate, placed above an allow rule for DNS.

    Why it's wrong here

    Incorrect. If the deny rule is above the allow rule, DNS traffic would be blocked.

  • Rely on the interzone default rule, which blocks all traffic, and add a rule to allow DNS.

    Why it's wrong here

    Incorrect. While this approach works, it is not best practice because it does not explicitly deny unwanted traffic, and the default rule may be changed.

  • Create an allow rule for DNS from Guest to Corporate, placed above a deny rule for any other traffic.

    Why this is correct

    Correct. Placing the specific allow rule above the general deny rule ensures DNS is allowed and all else is blocked.

  • Create a universal rule that applies to all zones with action 'allow' for DNS and 'deny' for everything else.

    Why it's wrong here

    Incorrect. Universal rules affect all zones, which could unintentionally allow DNS from other zones or block traffic that should be permitted.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.