Courseiva
Securing Traffic →hardMultiple Choice

PCNSA Securing Traffic Practice Question

A multinational corporation uses a Palo Alto Networks firewall to secure traffic between its internal zones. The security team wants to ensure that all traffic from the Users zone to the Servers zone is inspected for threats, but they also need to allow specific applications that use non-standard ports. They create a Security policy rule with 'application: any' and 'service: any', and attach a Vulnerability Protection profile. However, they notice that some traffic is not being inspected because it is being allowed by a more specific rule higher in the rulebase that allows only web-browsing and ssl. What should the administrator do to ensure all traffic is inspected?

⚠ Common exam trap

The trap here is assuming that attaching a Security profile to a rule guarantees inspection for all matching traffic, ignoring that rule order determines which rule is applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Move the rule with 'application: any' and 'service: any' above the more specific rule in the rulebase.

Security policy rules are processed in order, and the first matching rule determines the action and profiles applied. The more specific rule allowing web-browsing and ssl is matched before the broader rule with 'any' application and the Vulnerability Protection profile. To ensure all traffic is inspected, the administrator must move the broader rule with the inspection profile above the specific rule. This way, all traffic from Users to Servers is matched by the inspection rule first, and threat inspection is applied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new rule at the top of the rulebase that denies all traffic from Users to Servers, forcing traffic to be inspected by the next rule.

    Why it's wrong here

    A deny rule would block all traffic, not allow and inspect it. The goal is to inspect, not block. This would disrupt business operations. The correct approach is to allow and inspect, not deny. This option misunderstands the requirement to allow traffic while inspecting it.

  • ✗

    Enable 'Log at Session Start' on the more specific rule to ensure inspection occurs.

    Why it's wrong here

    Logging at session start only affects logging behavior, not inspection. Inspection is determined by Security profiles attached to the allowing rule. The specific rule likely does not have the Vulnerability Protection profile, so traffic is not inspected. Enabling logging does not add inspection. This option confuses logging with security inspection.

  • ✓

    Move the rule with 'application: any' and 'service: any' above the more specific rule in the rulebase.

    Why this is correct

    Security policy rules are evaluated top-down, and the first match is applied. The more specific rule allowing only web-browsing and ssl is matched first for that traffic, so it bypasses the broader rule with threat inspection. Moving the broader rule above ensures that all traffic from Users to Servers is matched by the rule with the Vulnerability Protection profile, thus inspected. This is the correct approach to enforce inspection for all traffic.

  • ✗

    Modify the more specific rule to include 'application: any' and attach the same Vulnerability Protection profile.

    Why it's wrong here

    Modifying the specific rule to 'any' would effectively make it a broad allow rule, but it would also allow all applications, which might violate the principle of least privilege. Additionally, if there are other rules, the issue might persist. The better solution is to reorder rules to ensure the inspection rule is hit first, rather than altering the specific rule's intent. This option does not address rule order.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.