Courseiva

PCNSA Policy Evaluation and Management Practice Question

A security administrator is configuring a security policy rule to allow access to a web server from the internet. The rule is set to allow HTTP and HTTPS traffic to the server's public IP address. However, after committing the change, users report that they cannot access the web server from the internet. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit rule. What is the most likely cause of the issue?

⚠ Common exam trap

The trap here is focusing on rule order or destination address when the issue is actually the source zone configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security rule does not have the correct source zone specified.

The correct answer is that the source zone is likely incorrect. For inbound traffic from the internet, the source zone should be the Untrust zone (or the zone of the external interface). If the source zone is set to Trust or another internal zone, the rule will not match, and the traffic will be denied by the interzone-default rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security rule is placed below the intrazone-default rule.

    Why it's wrong here

    The intrazone-default rule allows traffic within the same zone. Traffic from the internet to the web server is typically interzone (Untrust to DMZ or Trust). The intrazone-default rule would not deny this traffic. Therefore, this is not the cause.

  • ✓

    The security rule does not have the correct source zone specified.

    Why this is correct

    For traffic from the internet to a web server, the source zone is typically the Untrust zone (or the zone where the internet-facing interface resides). If the source zone is incorrectly set to Trust or any other zone, the rule will not match, and the traffic will be denied by the interzone-default rule. This is a common misconfiguration.

  • ✗

    The security rule is placed below the interzone-default rule.

    Why it's wrong here

    The interzone-default rule denies interzone traffic by default, but it is an implicit rule that is always at the bottom of the rulebase. Custom rules are evaluated before implicit rules. If the custom rule is correctly configured and placed anywhere above the interzone-default, it should match. Thus, placement below interzone-default is not possible because implicit rules are always last.

  • ✗

    The security rule is configured with the wrong destination address.

    Why it's wrong here

    While an incorrect destination address could cause the rule not to match, the scenario states that the rule is set to allow traffic to the server's public IP address. The administrator likely verified that. The more subtle issue is often the source zone, especially when the rule is intended for inbound access.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.