PCNSA Policy Evaluation and Management Practice Question
A security administrator is configuring a rule to allow access to a web server. The rule uses a URL category as the destination. The administrator notices that the rule is not matching traffic to the web server's IP address when users connect directly via IP. What is the most likely reason?
⚠ Common exam trap
The trap here is assuming that a URL category will match any traffic to a server's IP, when URL categories are based on the requested URL or SNI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
URL categories are only evaluated for HTTP and HTTPS traffic, and direct IP access may not be categorized.
URL categories are derived from the URL or SNI in the request. When users connect directly to an IP address without a hostname, the firewall often cannot determine a URL category, so a rule that references a URL category will not match. The traffic may then be evaluated against other rules or the implicit deny. To allow such traffic, the administrator should use an IP address or address group in the destination field instead of a URL category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security profile attached to the rule is blocking the traffic before the rule can match.
Why it's wrong here
Security profiles are applied after a rule matches, not before. They inspect allowed traffic and can block threats, but they do not prevent a rule from matching. If the rule is not matching, it is due to rule criteria not being met. The profile would only act if the rule matched and allowed the session.
- ✓
URL categories are only evaluated for HTTP and HTTPS traffic, and direct IP access may not be categorized.
Why this is correct
URL categories are determined by the URL filtering engine based on the URL or SNI in the request. When users connect directly to an IP address without a hostname, the firewall may not be able to categorize the traffic, so the rule referencing a URL category will not match. The rule would match only if the traffic is identified with a known URL category. This is expected behavior for URL category-based rules.
- ✗
The firewall requires a DNS sinkhole to be configured for URL category rules to work.
Why it's wrong here
DNS sinkhole is a feature used to redirect malicious DNS requests, not a requirement for URL category rules. URL category rules rely on the URL filtering engine and its database. While DNS sinkhole can be used with URL filtering, it is not needed for the rule to match. The lack of categorization for direct IP access is the real issue.
- ✗
The rule's source zone is incorrect, causing the traffic to be evaluated against a different rule.
Why it's wrong here
If the source zone were incorrect, the rule would not match regardless of URL category. However, the scenario states that the rule is not matching traffic to the web server's IP when users connect directly. The issue is specifically related to URL category evaluation, not zone configuration. Zone misconfiguration would affect all traffic, not just direct IP access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.