Courseiva

PCNSA Policy Evaluation and Management Practice Question

A security administrator is configuring a policy to allow access from the Guest zone to the Internet zone. The administrator wants to ensure that only HTTP and HTTPS traffic is allowed, and all other traffic is blocked. The administrator creates a rule with source zone Guest, destination zone Internet, application web-browsing and ssl, and action Allow. However, users report that they cannot access websites. What is the most likely cause?

⚠ Common exam trap

The trap here is focusing on the application or service settings when the real issue is rule order, which is a common oversight in policy evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule is placed below a more general deny rule that blocks all traffic from Guest to Internet.

Security rules are processed in order from top to bottom, and the first rule that matches the traffic is applied. If a deny rule for all traffic from Guest to Internet is placed above the allow rule for web-browsing and ssl, the deny rule will match first and block all traffic, preventing users from accessing websites. The allow rule must be moved above the deny rule to take effect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The rule is placed below a more general deny rule that blocks all traffic from Guest to Internet.

    Why this is correct

    Security rules are evaluated top-down, and the first match wins. If a deny rule for all traffic from Guest to Internet is above the allow rule, it will match first and block the traffic. The allow rule will never be evaluated. This is a common misconfiguration that causes users to be unable to access websites even though an allow rule exists.

  • ✗

    The rule is missing a security profile that allows web browsing.

    Why it's wrong here

    Security profiles do not allow or block traffic based on application; they apply additional inspection and can block threats. A missing security profile would not prevent the rule from allowing traffic. The rule's action is Allow, so traffic should be permitted unless another factor blocks it. Security profiles are not required for basic allow rules.

  • ✗

    The rule's service is set to application-default, but the users are using non-standard ports.

    Why it's wrong here

    If users are using non-standard ports for HTTP or HTTPS, the application-default service would not match. However, the scenario does not indicate non-standard ports; users are simply browsing websites. The more common issue is that the rule is not matching due to other factors such as security profiles or URL filtering, but the question asks for the most likely cause given the configuration.

  • ✗

    The application web-browsing does not include HTTPS traffic, so ssl must be replaced with web-browsing.

    Why it's wrong here

    The application web-browsing covers HTTP, while ssl covers HTTPS. Both are needed for full web access. Replacing ssl with web-browsing would not allow HTTPS, making the problem worse. The configuration of web-browsing and ssl is correct for allowing both HTTP and HTTPS. The issue is likely rule order.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.