Courseiva
Securing Traffic →hardMultiple Choice

PCNSA Securing Traffic Practice Question

A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal users and the internet. The security team wants to enforce different security profiles based on the destination country of outbound traffic. They have created a Security policy rule that allows web-browsing and ssl from the trust zone to the untrust zone. They now need to apply a URL Filtering profile that blocks malicious sites only when the destination IP is geolocated in a specific high-risk country. What should the administrator configure to achieve this?

⚠ Common exam trap

It's easy for candidates to confuse source and destination regions, or placing the new rule in the wrong order so it never matches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new Security policy rule above the existing rule that matches destination region for the high-risk country, allows the applications, and attaches the URL Filtering profile.

The correct configuration creates a new Security policy rule with a destination region match for the high-risk country, placed above the existing rule. This ensures that traffic to that country is evaluated first and receives the URL Filtering profile, while other traffic continues to be handled by the original rule. This leverages geolocation objects and rule ordering to apply security profiles conditionally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the existing Security policy rule to include a destination region object for the high-risk country and attach the URL Filtering profile.

    Why it's wrong here

    Modifying the existing rule would apply the URL Filtering profile to all traffic allowed by that rule, regardless of destination country. The requirement is to enforce the profile only for a specific high-risk country, not for all outbound web traffic. This would over-apply the profile and potentially impact performance or block legitimate sites for other destinations.

  • ✗

    Create a new Security policy rule below the existing rule that matches destination region for the high-risk country, allows the applications, and attaches the URL Filtering profile.

    Why it's wrong here

    Placing the new rule below the existing rule means the existing rule will match first and allow the traffic without the URL Filtering profile. Security policy rules are evaluated top-down, and the first match is applied. Therefore, the new rule would never be hit for the intended traffic, and the URL Filtering profile would not be enforced.

  • ✗

    In the Security policy rule, add a source region object for the high-risk country and attach the URL Filtering profile.

    Why it's wrong here

    Source region matches the geographic location of the source IP address, not the destination. Since the requirement is based on the destination country, using a source region would incorrectly match traffic originating from that country rather than traffic going to it. This would not enforce the URL Filtering profile for the intended outbound sessions.

  • ✓

    Create a new Security policy rule above the existing rule that matches destination region for the high-risk country, allows the applications, and attaches the URL Filtering profile.

    Why this is correct

    This approach correctly uses a destination region object to match traffic destined for the high-risk country. Placing the new rule above the existing rule ensures it is evaluated first for matching traffic, allowing the URL Filtering profile to be applied only to those sessions. The existing rule continues to handle other destinations without the profile, achieving granular control based on geolocation.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.