Courseiva

PCNSA Device Management and Services Practice Question

A security administrator at a branch office needs to allow a remote vendor to access the firewall's web management interface only from IP address 203.0.113.50. The firewall's management interface is in the Management zone. Which Palo Alto Networks feature should the administrator use to restrict access?

⚠ Common exam trap

The trap here is assuming that Security policy rules control access to the firewall's management interface, when actually management access is governed by Interface Management Profiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an Interface Management Profile with HTTPS allowed and permitted IP addresses set to 203.0.113.50, then apply it to the management interface.

The Interface Management Profile is the correct tool because it explicitly enables management services on an interface and can restrict them to specific source IP addresses. Applying it to the management interface with HTTPS enabled and the vendor's IP permitted ensures only that address can reach the web UI. Other options either do not affect management plane access or address routing/authentication rather than IP-based restriction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an Interface Management Profile with HTTPS allowed and permitted IP addresses set to 203.0.113.50, then apply it to the management interface.

    Why this is correct

    An Interface Management Profile controls which management services (HTTP, HTTPS, SSH, etc.) are enabled on an interface and restricts access to specified IP addresses. Applying it to the management interface with HTTPS allowed and permitted IP 203.0.113.50 ensures only that source can reach the web UI, directly meeting the requirement.

  • ✗

    Create a Security policy rule allowing traffic from 203.0.113.50 to the Management zone on port 443.

    Why it's wrong here

    Security policy rules do not apply to traffic destined for the firewall's management interface. Management plane access is controlled separately via Interface Management Profiles and administrative accounts. Even if a Security rule is created, it will not permit or deny access to the web UI, so the vendor still cannot connect.

  • ✗

    Configure an authentication profile that requires the vendor to authenticate with a certificate before accessing the web UI.

    Why it's wrong here

    An authentication profile adds an authentication step for administrative users but does not restrict access based on source IP address. The requirement is to limit access to a specific IP. Certificate authentication alone would still allow the vendor to attempt access from any IP, failing the restriction objective.

  • ✗

    Add a static route for 203.0.113.50 pointing to the management interface.

    Why it's wrong here

    Static routes direct traffic through the firewall's data plane and do not restrict administrative access. Adding a route does not limit which IPs can reach the management interface; it merely tells the firewall where to send packets. The vendor's access would still be governed by other settings, not by this route.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.