PCNSA Policy Evaluation and Management Practice Question
A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?
⚠ Common exam trap
Many candidates assume a rule allowing traffic to one zone implicitly covers all zones, but Palo Alto Networks firewalls require explicit zone matching for each rule, and failing to specify the correct destination zone results in a deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule only allows traffic from Engineering to Servers zone, not DMZ.
The security rule explicitly permits traffic from the 'Engineering' zone to the 'Servers' zone. Traffic destined to the 'DMZ' zone is a different zone, so the rule does not apply. By default, Palo Alto Networks firewalls enforce a deny-all policy for any traffic that does not match an explicit allow rule, which is why the traffic is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The rule only allows traffic from Engineering to Servers zone, not DMZ.
Why this is correct
Security rules match on both source and destination zones, so a rule permitting Engineering to Servers does not cover Engineering to DMZ. Traffic destined for the DMZ zone matches no allow rule and hits the default interzone deny, producing the observed denial.
- ✗
The rule is configured as an intrazone rule.
Why it's wrong here
An intrazone rule governs traffic within a single zone, so it cannot permit Engineering-to-Servers or Engineering-to-DMZ flows. The denial stems from the interzone rule's zone pair not matching the DMZ destination. Intrazone rules are the right choice when both endpoints reside in the same zone, such as server-to-server traffic inside Servers.
- ✗
The rule is disabled in the rulebase.
Why it's wrong here
A disabled rule would also block Engineering-to-Servers traffic, yet the stem states that rule permits it. Disabling is the right diagnosis when a rule matches intended traffic but is administratively turned off, not when the destination zone differs.
- ✗
SSL decryption is blocking the traffic.
Why it's wrong here
SSL decryption inspects encrypted sessions; it does not deny traffic based on zone membership. Decryption would be the correct focus when encrypted application content must be inspected, not when a zone-to-zone rule fails to match.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.