Courseiva

PCNSA Policy Evaluation and Management Practice Question

A firewall administrator is reviewing the security policy and notices that a rule allowing DNS from the Trust zone to the Untrust zone has a hit count of zero. The administrator confirms that DNS traffic is being generated and that the rule is enabled. Which action should the administrator take to troubleshoot why the rule is not being hit?

⚠ Common exam trap

The trap here is assuming the rule itself is misconfigured when the issue is actually rule order, specifically a preceding rule that matches and takes action first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check if there is a rule above that matches DNS traffic and has a deny action.

Security rules are evaluated top-down. If a rule above the DNS allow rule matches DNS traffic and denies it, the DNS allow rule will never be reached, resulting in zero hits. The administrator should examine the rules above for any that might match DNS and have a deny action, or any action that would prevent the DNS rule from being evaluated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check if there is a rule above that matches DNS traffic and has a deny action.

    Why this is correct

    If a rule above the DNS allow rule matches DNS traffic and denies it, the DNS allow rule will never be evaluated, resulting in a zero hit count. This is the most likely cause when a rule is not being hit despite traffic being present. The administrator should review the rules above for any that might match DNS.

  • ✗

    Verify that the DNS application is included in the rule's Application column.

    Why it's wrong here

    If the DNS application were missing from the rule, the rule would not match DNS traffic, but the administrator would likely have noticed that when configuring. The question states the rule is for DNS, so it presumably includes the DNS application. The more likely cause is a preceding rule that matches and denies the traffic.

  • ✗

    Ensure that the source and destination zones are correctly configured as Trust and Untrust.

    Why it's wrong here

    The administrator already configured the rule for Trust to Untrust, and the question implies the rule is for DNS from Trust to Untrust. While zone misconfiguration could cause a zero hit count, it is less likely if the administrator is reviewing the rule. A preceding deny rule is a more common cause of zero hits.

  • ✗

    Check if the rule is placed after a more general allow rule that permits all traffic.

    Why it's wrong here

    If a more general allow rule above permits all traffic, the DNS rule would not be hit because the general rule would match first. However, the DNS traffic would still be allowed, so the administrator might not notice a problem. The question states the rule has zero hits, which could be due to a general allow rule, but a deny rule is more likely to cause a noticeable issue.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.