PCNSA Policy Evaluation and Management Practice Question
A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?
⚠ Common exam trap
PCNSA often tests rule ordering — candidates who place the deny rule first or rely on implicit defaults forget that PAN-OS stops at the first match, so the exception rule must precede the catch-all deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an allow rule for DNS from Guest to Corporate, placed above a deny rule for any other traffic.
PAN-OS evaluates security policies top-down and stops at the first match, so the DNS allow rule must sit above the deny rule to permit DNS while blocking everything else. This explicit allow-then-deny ordering implements least privilege and makes the intent auditable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a deny rule for any traffic from Guest to Corporate, placed above an allow rule for DNS.
Why it's wrong here
A blanket deny above the DNS allow rule blocks the DNS traffic too, since policy is evaluated top-down and the deny matches first. It is tempting as an explicit catch-all, but the correct approach places the specific DNS allow above a broader Guest-to-Corporate deny.
- ✗
Rely on the interzone default rule, which blocks all traffic, and add a rule to allow DNS.
Why it's wrong here
The interzone default rule permits intrazone and interzone traffic by default on many platforms, so relying on it to block Guest-to-Corporate leaves traffic allowed. It is tempting as a zero-configuration baseline, but an explicit deny rule is required to enforce the restriction.
- ✓
Create an allow rule for DNS from Guest to Corporate, placed above a deny rule for any other traffic.
Why this is correct
Security policy is evaluated top-down with first-match semantics, so the specific DNS allow rule must precede the broader deny. Placing the deny first would drop DNS too, since the deny matches any application and no later rule is consulted.
- ✗
Create a universal rule that applies to all zones with action 'allow' for DNS and 'deny' for everything else.
Why it's wrong here
A universal rule spanning all zones cannot express a zone-specific exception, so it would allow DNS everywhere and deny unrelated interzone traffic. It is tempting for its single-rule simplicity, but the requirement is scoped to Guest-to-Corporate, needing zone-specific rules.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.