Courseiva

PCNSA Policy Evaluation and Management Practice Question

A network security administrator is configuring a security policy on a PA-5220 firewall. The administrator wants to allow HTTP and HTTPS traffic from the 'Guest' zone to the 'Internet' zone, but only for specific users in the 'guest-users' group. The administrator creates a rule with source zone 'Guest', destination zone 'Internet', source user 'guest-users', and application 'web-browsing' and 'ssl'. However, when testing, all Guest users can access the Internet, not just those in the group. What is the most likely cause?

⚠ Common exam trap

The trap here is focusing on User-ID or application configuration when the actual issue is rule order allowing a broader rule to take precedence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule is placed below a more general rule that allows all Guest traffic to the Internet.

In PAN-OS, security rules are evaluated from top to bottom. If a rule that allows all Guest users to the Internet exists above the user-specific rule, it will match first and permit all traffic. The user-specific rule will never be evaluated. To restrict access to only the 'guest-users' group, the specific rule must be placed above any broader rules that could match the same traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application 'ssl' is not a valid application for HTTP and HTTPS traffic.

    Why it's wrong here

    The 'ssl' application is used for HTTPS traffic, and 'web-browsing' for HTTP. They are valid applications. If they were incorrect, the rule might not match, but again, the symptom is that all users are allowed, indicating a broader rule is likely matching first. The validity of applications is not the issue here.

  • ✗

    The source user group 'guest-users' does not exist in the local user database.

    Why it's wrong here

    If the user group did not exist, the rule would not match any user, and traffic would be denied or matched by a subsequent rule. However, the symptom is that all users are allowed, which suggests a broader rule is matching. A missing group would not cause all users to be allowed; it would cause the rule to be skipped. Therefore, this is not the most likely cause.

  • ✗

    User-ID is not enabled on the firewall, so user-based rules are ignored.

    Why it's wrong here

    If User-ID were not enabled, the user-based rule would not match any user, and traffic would fall through to other rules. If a broader rule allows all users, then all users would be allowed. However, the question states that the administrator created the rule with a source user, implying User-ID is configured. The most likely cause is rule order, not User-ID being disabled.

  • ✓

    The rule is placed below a more general rule that allows all Guest traffic to the Internet.

    Why this is correct

    If a more general rule allowing all Guest traffic exists above the user-specific rule, it will match first, granting access to all users. The user-specific rule would never be evaluated. This is a common misconfiguration. The administrator must ensure the user-specific rule is above any broader rules that might match the same traffic. Rule order is critical in PAN-OS security policy.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.