PCNSA Device Management and Services Practice Question
A firewall administrator needs to ensure that the firewall can resolve domain names for security policy rules that use FQDN objects. The firewall is deployed in a network where DNS servers are reachable only through the dataplane interface ethernet1/2, which is in the untrust zone. The management interface cannot reach any DNS server. Which configuration should the administrator use to allow the firewall to resolve FQDNs?
⚠ Common exam trap
The trap here is assuming that DNS resolution for the firewall always uses the management interface, overlooking the service route capability that redirects DNS traffic through a dataplane interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service route for DNS that uses the dataplane interface ethernet1/2, and specify the DNS servers in Device > Setup > Services > DNS.
Service routes allow specific management-plane services (such as DNS, email, SNMP, syslog, etc.) to be sourced from a dataplane interface instead of the management interface. By configuring a service route for DNS that uses ethernet1/2, and specifying the DNS servers, the firewall can send DNS queries out the dataplane interface, which has reachability to the DNS servers. This enables FQDN resolution for security policies even when the management interface cannot reach DNS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a service route for DNS that uses the dataplane interface ethernet1/2, and specify the DNS servers in Device > Setup > Services > DNS.
Why this is correct
Service routes allow management-plane services, including DNS, to use a dataplane interface instead of the management interface. By creating a service route for DNS via ethernet1/2 and configuring the DNS servers, the firewall can resolve FQDNs through the dataplane, satisfying the requirement when the management interface lacks DNS reachability.
- ✗
Configure a DNS proxy object and assign it to the untrust zone, then set the DNS servers in Device > Setup > Services > DNS.
Why it's wrong here
A DNS proxy object is used to intercept and forward DNS requests from clients, not to provide DNS resolution for the firewall itself. Assigning it to the untrust zone would not enable the firewall to resolve FQDNs for security policies. The firewall's own DNS resolution is configured elsewhere, so this approach would fail to meet the requirement.
- ✗
Configure a static route on the management interface to the DNS servers, and set the DNS servers in Device > Setup > Services > DNS.
Why it's wrong here
Static routes on the management interface only affect management-plane traffic if the management interface has a route to the destination. Since the DNS servers are reachable only through the dataplane, a management static route would not help. The firewall would still be unable to reach the DNS servers for FQDN resolution.
- ✗
Enable DNS resolution on the untrust zone interface and set the DNS servers in Device > Setup > Services > DNS.
Why it's wrong here
There is no feature to enable DNS resolution on a zone interface for the firewall's own use. Zone interfaces are for dataplane traffic, and the firewall's DNS client settings are configured globally. Without a service route, the firewall would attempt DNS via the management interface and fail, so this option does not resolve the issue.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.