PCNSA Policy Evaluation and Management Practice Question
A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates think rule order does not matter or that a block rule can override an allow rule regardless of position, but Palo Alto Networks enforces strict top-down evaluation where the first match wins, so a lower rule cannot override a higher rule's action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule is positioned below an allow rule that matches the same traffic.
The Palo Alto Networks firewall evaluates security rules in top-down order, from the first rule in the rulebase to the last. If a rule that allows traffic is placed higher in the list, it will match and permit the traffic before the lower-placed block rule is ever evaluated. The block rule at the bottom is effectively never reached for that traffic, which is why the intended blocking action fails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The source IP is negated in the rule.
Why it's wrong here
Negating the source IP inverts the match, so the rule would target every address except the specified one, not block that address. Negation is tempting for whitelisting all-but-one hosts, which is its legitimate use, but it does not explain a higher rule permitting the traffic.
- ✗
The rule is placed at the top of the rulebase and overridden by a later rule.
Why it's wrong here
The stem already states the rule sits at the bottom of the rulebase, so a top placement contradicts the given facts. Top placement is tempting because first-match evaluation means an early rule wins, which is exactly why administrators put broad blocks there deliberately.
- ✓
The rule is positioned below an allow rule that matches the same traffic.
Why this is correct
Palo Alto Networks evaluates security rules top-down and stops at the first match, so a rule placed below an allow rule covering the same source, destination and application is never reached. The blocking rule must be moved above the matching allow rule to take effect.
- ✗
The rule is disabled in the rulebase.
Why it's wrong here
A disabled rule cannot match traffic at all, so it would not be the rule permitting the connection; the stem states traffic is being allowed by a rule higher in the list. Disabling is tempting when decommissioning a rule temporarily, but an enabled rule above is the actual cause here.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.