PCNSA Securing Traffic Practice Question
A network administrator is configuring a Security policy rule on a Palo Alto Networks firewall to allow HTTP traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that the rule only allows HTTP traffic on its default port. Which service setting should be used?
⚠ Common exam trap
The trap here is thinking that specifying a service object like TCP-80 is equivalent to 'application-default', but 'application-default' is dynamic and tied to the application, making it more secure and easier to manage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
application-default
The 'application-default' service setting is the correct choice because it allows traffic only on the default ports defined for the selected application. For HTTP, the default port is TCP 80. This setting ensures that the rule permits HTTP only on its standard port, aligning with least privilege. It also automatically updates if application definitions change, reducing administrative overhead. Using 'any' would be too permissive, while specific service objects like TCP-80 are static and less flexible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
application-default
Why this is correct
The 'application-default' service setting allows traffic only on the default ports defined for the selected application. For HTTP (web-browsing), the default port is TCP 80. This ensures that the rule permits HTTP only on its standard port, enhancing security by not opening additional ports. It is the recommended setting when the application is known, as it dynamically adapts to application definitions.
- ✗
service-http
Why it's wrong here
service-http is a predefined service object that represents TCP port 80. While it would allow HTTP traffic, it is not the recommended setting when the application is known. Using application-default is more precise because it ties the allowed port to the application's default. However, service-http would work if the application is set to http. But the question asks for the service setting that ensures default port for HTTP; application-default is the best practice.
- ✗
any
Why it's wrong here
'Any' service allows all ports, which is too permissive and would not restrict HTTP to its default port. This could allow HTTP on non-standard ports, which might be against the security policy. The requirement is to allow only HTTP on its default port, so 'any' is incorrect. It broadens the rule unnecessarily.
- ✗
TCP-80
Why it's wrong here
TCP-80 is a service object that allows only TCP port 80. While it would restrict to port 80, it does not automatically adapt if the application definition changes. The 'application-default' setting is preferred because it uses the application's default ports, which are maintained by Palo Alto Networks. TCP-80 is a valid choice but not the best practice when application is specified.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.