PCNSA Policy Evaluation and Management Practice Question
A security administrator is configuring a Palo Alto Networks firewall with a security policy that allows traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only specific users can access certain applications. The administrator creates a rule with source zone Trust, destination zone Untrust, source user 'domain\jdoe', application 'web-browsing', action allow. However, after committing, the user jdoe reports that they cannot access the web. The administrator checks the traffic logs and sees that the traffic is being denied by the implicit rule. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that simply referencing a username in a rule is enough, but User-ID must be enabled on the source zone to map IP addresses to users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User-ID is not enabled on the Trust zone, so the firewall cannot map the source IP to the user.
The most likely cause is that User-ID is not enabled on the Trust zone. For a security rule with a source user criterion to match, the firewall must map the source IP to a username. If User-ID is not enabled on the zone, the mapping does not occur, and the rule is skipped. The traffic then hits the implicit deny. The administrator should enable User-ID on the Trust zone and ensure the user mapping is working.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user 'domain\jdoe' is not in the local user database of the firewall.
Why it's wrong here
The firewall can use User-ID to map IP addresses to users from various sources, including Active Directory, LDAP, or local databases. If the user is not in the local database but is in Active Directory, and User-ID is configured to connect to AD, the mapping could still work. The scenario does not specify the source of user information. The issue is more likely that User-ID is not enabled or the mapping is not present, but not specifically that the user is not in the local database.
- ✗
The security rule is placed below a rule that denies all traffic from Trust to Untrust.
Why it's wrong here
If there is a deny rule above the allow rule, the deny rule would match first and block the traffic. However, the scenario states that the traffic is being denied by the implicit rule, not an explicit deny rule. The implicit rule is at the bottom, so the allow rule must have been evaluated and not matched. Therefore, this is not the cause.
- ✗
The application 'web-browsing' is not allowed for the user 'domain\jdoe' because of an application override.
Why it's wrong here
Application override is used to customize how applications are identified, but it does not restrict applications based on users. The rule explicitly allows web-browsing for the user. If an application override were misconfigured, it might affect identification, but the scenario does not indicate that. The most likely cause is that User-ID is not enabled, preventing the rule from matching.
- ✓
User-ID is not enabled on the Trust zone, so the firewall cannot map the source IP to the user.
Why this is correct
For a security rule that includes a source user, the firewall must be able to map the source IP address to a username using User-ID. If User-ID is not enabled on the zone where the user's traffic originates (Trust zone), the firewall cannot identify the user, and the rule will not match. This causes the traffic to fall through to the implicit deny. Enabling User-ID on the Trust zone is required for user-based rules to work.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.