PCNSA Securing Traffic Practice Question
A firewall is configured with multiple virtual systems (vsys). An administrator wants to allow traffic from vsys1 to vsys2 while keeping other inter-vsys traffic blocked. How should this be accomplished?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security policy rule with source zone from vsys1 and destination zone from vsys2, action allow.
In Palo Alto firewalls, inter-vsys traffic is controlled by creating a security policy rule that specifies the source zone from vsys1 and the destination zone from vsys2 with action allow. This selectively permits traffic between specific virtual systems. Option A is incorrect because intra-vsys refers to traffic within the same vsys, not between different vsys. Option B is incorrect because there is no global 'inter-vsys' enable setting; inter-vsys traffic is governed by security policies. Option C is incorrect because inter-vsys traffic is not automatically allowed; it must be explicitly permitted via policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure intra-vsys security policy for each vsys and allow the traffic.
Why it's wrong here
Intra-vsys is within same vsys, not between.
- ✗
Enable inter-vsys traffic globally in the firewall settings.
Why it's wrong here
There is no global enable; it's done via policies.
- ✗
Traffic between vsys is automatically allowed.
Why it's wrong here
It is not automatically allowed; it's blocked by default.
- ✓
Create a security policy rule with source zone from vsys1 and destination zone from vsys2, action allow.
Why this is correct
Inter-vsys traffic is controlled by security policies using zones from different vsys.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.