Courseiva
mediumMultiple Choice

PCNSA Practice Question: A network administrator notices that traffic from…

A network administrator notices that traffic from the internal zone to the external zone is being denied, even though a security policy allowing all outbound traffic exists. The internal zone is configured with a zone protection profile that has Flood Protection enabled. What is the most likely cause of the denial?

⚠ Common exam trap

The trap here is assuming that a security policy allow rule guarantees traffic will pass — candidates forget that zone protection and other ingress protections operate before policy lookup and can silently drop traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The zone protection profile has Flood Protection thresholds set too low, causing legitimate traffic to be dropped.

Zone protection profiles with Flood Protection enabled apply rate-based thresholds (SYN, UDP, ICMP, etc.) at the ingress of a zone. If thresholds are set too low, legitimate traffic that exceeds those rates is dropped before security policy evaluation, which explains why an allow-all outbound policy still results in denied traffic. This is the most likely cause given the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security policy is set to deny due to an implicit deny rule.

    Why it's wrong here

    Flood protection profiles drop traffic only when configured thresholds are exceeded, and the stem gives no evidence of a flood; the implicit deny rule sits at the end of the rulebase and is not triggered while a matching allow rule exists. Flood protection would be the cause if SYN or ICMP rates breached the profile's limits.

  • ✓

    The zone protection profile has Flood Protection thresholds set too low, causing legitimate traffic to be dropped.

    Why this is correct

    Flood Protection drops packets once configured thresholds are exceeded, regardless of any security policy permitting the traffic. If SYN, UDP or ICMP flood rates are set too low for normal outbound volumes, legitimate sessions from the internal zone are discarded before policy evaluation, producing the denial despite the allow-all rule.

  • ✗

    The security policy has a logging profile attached that is blocking traffic.

    Why it's wrong here

    Logging profiles only record session details; they never block traffic. They are tempting because profiles are configured alongside security policies, but the stem states Flood Protection is enabled on the internal zone, so threshold-based flood drops, not logging, explain the denial.

  • ✗

    The security policy has a schedule configured that is currently outside the allowed time.

    Why it's wrong here

    A schedule only permits or denies traffic at defined times; flood protection drops sessions exceeding zone thresholds, which matches the symptom. Schedules are tempting because they also deny otherwise-permitted traffic, but the stem specifies Flood Protection is enabled, making threshold-based drops the cause.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.