PCNSA Policy Evaluation and Management Practice Question
A firewall administrator is reviewing the security policy and notices that a rule allowing traffic from the Trust zone to the DMZ zone is not being hit. The rule is placed after a rule that denies all traffic from Trust to DMZ. What is the most likely explanation?
⚠ Common exam trap
The trap here is thinking that rule specificity or action determines priority, when in fact only the order of rules matters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The allow rule is shadowed by the deny rule above it.
Security rules in PAN-OS are evaluated in top-down order. If a deny rule is placed above an allow rule and both match the same traffic, the deny rule will be hit first, preventing the allow rule from ever being evaluated. This is called shadowing, and the allow rule is effectively disabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The deny rule is more specific and therefore takes precedence.
Why it's wrong here
In PAN-OS, security rules are evaluated in top-down order; specificity does not affect precedence. The first rule that matches the traffic is applied. If a deny rule is above an allow rule, the deny rule will be hit first if it matches, regardless of specificity. Therefore, the deny rule does not take precedence due to specificity; it takes precedence because it is evaluated first.
- ✗
The allow rule requires a URL filtering profile to be hit.
Why it's wrong here
URL filtering profiles are used for web traffic inspection and do not affect whether a rule is hit. A rule is hit based on zone, address, application, and service matching, not on security profiles. The absence of a URL filtering profile would not prevent the rule from being matched; it would only affect the action taken on allowed web traffic.
- ✓
The allow rule is shadowed by the deny rule above it.
Why this is correct
In PAN-OS, security rules are evaluated from top to bottom. If a deny rule is placed above an allow rule and matches the same traffic, the deny rule will be hit first, and the allow rule will never be evaluated. This is known as shadowing. The allow rule is effectively useless because the deny rule above it blocks all matching traffic before it can be reached.
- ✗
The deny rule has a higher priority due to its action.
Why it's wrong here
Rule priority in PAN-OS is determined solely by the order in the rulebase, not by the action (allow or deny). A deny rule does not have inherent higher priority. The rule that appears first in the list is evaluated first. If a deny rule is above an allow rule, it will be evaluated first and can block traffic before the allow rule is considered.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.