PCNSA Securing Traffic Practice Question
A network administrator is troubleshooting a connectivity issue. The firewall has a security rule that allows traffic from the Trust zone to the Untrust zone for the subnet 192.168.1.0/24 with application 'web-browsing'. However, users in that subnet cannot access any external websites. The administrator checks the logs and sees that the traffic is being blocked by a rule named 'Deny All' that is listed before the allow rule in the policy order. What is the most likely cause of the problem? The rule order is incorrect; the allow rule is below the 'Deny All' rule. The source address object for the allow rule is misconfigured with a wrong subnet mask. The application 'web-browsing' is not being properly identified by App-ID. The User-ID agent is overriding the allow rule and triggering a block action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule order is incorrect; the allow rule is below the 'Deny All' rule.
In Palo Alto Networks firewalls, rules are evaluated in top-down order. If the 'Deny All' rule is above the allow rule, it will match first and block traffic. Options B, C, and D are plausible but less likely given the log evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The rule order is incorrect; the allow rule is below the 'Deny All' rule.
Why this is correct
Palo Alto firewalls evaluate security rules top-down and stop at the first match, so the 'Deny All' rule sitting above the allow rule intercepts the traffic before it is ever evaluated against the web-browsing permit. Reordering the rules so the allow rule precedes 'Deny All' resolves the connectivity failure.
- ✗
The application 'web-browsing' is not being properly identified by App-ID.
Why it's wrong here
App-ID misidentification would prevent the allow rule matching web-browsing, but the logs show the traffic hitting 'Deny All' first, so evaluation never reaches the allow rule. It is tempting because App-ID failures do cause unexpected blocks, and that would be the cause if the deny rule sat below the allow rule.
- ✗
The source address object for the allow rule is misconfigured with a wrong subnet mask.
Why it's wrong here
A wrong subnet mask would stop the allow rule matching those source addresses, but the logs show traffic reaching and being blocked by 'Deny All', which sits above the allow rule. It is tempting because address objects commonly cause silent mismatches, and that would be the cause if no rule matched the traffic at all.
- ✗
The User-ID agent is overriding the allow rule and triggering a block action.
Why it's wrong here
User-ID maps source IP addresses to users for policy enforcement; it does not reorder rules or override an earlier deny, and the logs already show the 'Deny All' rule matching first. It is tempting because User-ID failures do cause unexpected blocks, and that would be the cause if the deny rule referenced users rather than any source.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.