Courseiva
Securing TraffichardMultiple ChoiceObjective-mapped

PCNSA Securing Traffic Practice Question

A firewall is configured with multiple virtual systems (vsys). An administrator wants to allow traffic from vsys1 to vsys2 while keeping other inter-vsys traffic blocked. How should this be accomplished?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a security policy rule with source zone from vsys1 and destination zone from vsys2, action allow.

In Palo Alto firewalls, inter-vsys traffic is controlled by creating a security policy rule that specifies the source zone from vsys1 and the destination zone from vsys2 with action allow. This selectively permits traffic between specific virtual systems. Option A is incorrect because intra-vsys refers to traffic within the same vsys, not between different vsys. Option B is incorrect because there is no global 'inter-vsys' enable setting; inter-vsys traffic is governed by security policies. Option C is incorrect because inter-vsys traffic is not automatically allowed; it must be explicitly permitted via policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure intra-vsys security policy for each vsys and allow the traffic.

    Why it's wrong here

    Intra-vsys is within same vsys, not between.

  • Enable inter-vsys traffic globally in the firewall settings.

    Why it's wrong here

    There is no global enable; it's done via policies.

  • Traffic between vsys is automatically allowed.

    Why it's wrong here

    It is not automatically allowed; it's blocked by default.

  • Create a security policy rule with source zone from vsys1 and destination zone from vsys2, action allow.

    Why this is correct

    Inter-vsys traffic is controlled by security policies using zones from different vsys.

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.