Courseiva

PCNSA Policy Evaluation and Management Practice Question

A security administrator is reviewing the rulebase and notices that a rule allowing traffic from the 'Trust' zone to the 'Untrust' zone has the action set to 'Allow' but is not being hit. The administrator confirms that there is traffic matching the source and destination zones, addresses, and applications. What is the most likely reason the rule is not being hit?

⚠ Common exam trap

The trap here is focusing on the rule itself rather than the rules above it, when rule order is the most likely cause of a rule not being hit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A rule above it with a broader match is already allowing the traffic, so the lower rule is never evaluated.

A rule is not hit if a rule above it matches the traffic first. The administrator should examine the rules above the one in question to see if any of them match the same traffic. This is the most common reason for a rule not being hit when its criteria seem correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The rule is not being hit because the application is not recognized by App-ID and is being denied by the implicit deny rule.

    Why it's wrong here

    If the application were not recognized, it would not match the rule, but the administrator confirms that the applications match. The issue is that the rule is not being hit despite matching criteria. If the application were unrecognized, it might be denied, but the rule would still not be hit. However, the administrator states the applications match, so this is not the cause.

  • ✓

    A rule above it with a broader match is already allowing the traffic, so the lower rule is never evaluated.

    Why this is correct

    Security rules are evaluated top-down. If a rule above the one in question matches the traffic, that rule's action is taken and the lower rule is not evaluated. The administrator should check for any rule above that might be matching the same traffic, possibly with broader match criteria. This is a common cause of a rule not being hit.

  • ✗

    The rule is not being hit because the security policy is not committed.

    Why it's wrong here

    If the policy were not committed, the rule would not be active at all. However, the administrator confirms that there is traffic and the rule exists. The question states the rule is not being hit, implying other rules might be. If uncommitted, no rules would be active. But the scenario implies the firewall is operational, so commit is likely done.

  • ✗

    The rule is not being hit because the source and destination addresses are incorrect.

    Why it's wrong here

    The administrator confirms that the source and destination addresses match the traffic. If they were incorrect, the rule would not match, but the administrator has already verified them. The issue is likely that another rule above is matching first. Incorrect addresses would be a different problem.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.