Courseiva
Securing TrafficeasyMultiple ChoiceObjective-mapped

PCNSA Securing Traffic Practice Question

A network administrator is troubleshooting a connectivity issue. The firewall has a security rule that allows traffic from the Trust zone to the Untrust zone for the subnet 192.168.1.0/24 with application 'web-browsing'. However, users in that subnet cannot access any external websites. The administrator checks the logs and sees that the traffic is being blocked by a rule named 'Deny All' that is listed before the allow rule in the policy order. What is the most likely cause of the problem? The rule order is incorrect; the allow rule is below the 'Deny All' rule. The source address object for the allow rule is misconfigured with a wrong subnet mask. The application 'web-browsing' is not being properly identified by App-ID. The User-ID agent is overriding the allow rule and triggering a block action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The rule order is incorrect; the allow rule is below the 'Deny All' rule.

In Palo Alto Networks firewalls, rules are evaluated in top-down order. If the 'Deny All' rule is above the allow rule, it will match first and block traffic. Options B, C, and D are plausible but less likely given the log evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The rule order is incorrect; the allow rule is below the 'Deny All' rule.

    Why this is correct

    Since the logs show the traffic matches the deny rule, the allow rule must be positioned lower in the rulebase.

  • The application 'web-browsing' is not being properly identified by App-ID.

    Why it's wrong here

    If App-ID failed, the traffic might not match the rule, but the log would show a different action or no match.

  • The source address object for the allow rule is misconfigured with a wrong subnet mask.

    Why it's wrong here

    While a misconfigured address object could cause a mismatch, the log indicates the traffic matched the deny rule, not that it failed to match the allow rule.

  • The User-ID agent is overriding the allow rule and triggering a block action.

    Why it's wrong here

    User-ID does not override rule actions; it only adds user context.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.