PCNSA Policy Evaluation and Management Practice Question
A network security administrator is reviewing the security policy on a Palo Alto Networks firewall. The administrator wants to ensure that traffic from the Trust zone to the Untrust zone is inspected by a specific security profile group. Which policy component should the administrator configure to attach the security profile group?
⚠ Common exam trap
The trap here is thinking that security profiles can be attached to NAT or decryption rules, when they are configured on security rules only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security rule that permits the traffic
Security profile groups are attached directly to security rules. When traffic matches a security rule, the firewall applies the attached profile group to inspect the traffic for threats, malware, and other risks. NAT, decryption, and application override rules serve different purposes and do not provide the field to attach security profile groups. The administrator must edit the security rule that permits the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The decryption policy rule that matches the traffic
Why it's wrong here
Decryption policy rules determine whether traffic is decrypted and can reference decryption profiles, but they do not apply security profile groups for threat inspection. Security profiles are applied at the security rule level after decryption. Therefore, attaching a profile group to a decryption rule would not achieve the goal of inspecting the Trust-to-Untrust traffic.
- ✓
The security rule that permits the traffic
Why this is correct
Security profiles are attached to security rules, and they are applied only to traffic that matches the rule. To inspect Trust-to-Untrust traffic with a specific profile group, the administrator must attach that profile group to the rule that allows the traffic. Other policy types, such as NAT or decryption, may influence traffic but do not directly apply security profiles for inspection.
- ✗
The application override policy rule
Why it's wrong here
Application override rules are used to force traffic to be identified as a specific application, bypassing App-ID. They do not provide a mechanism to attach security profile groups. While they can affect which security rule matches, they are not the correct place to configure threat inspection profiles. The administrator should use the security rule for that purpose.
- ✗
The NAT rule that translates the source address
Why it's wrong here
NAT rules perform address translation and do not have a field for attaching security profile groups. While NAT can affect which security rule matches by changing the source or destination zone, it does not apply security profiles. The administrator must configure the profile group on the security rule that ultimately permits the traffic, not on the NAT rule.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.