Courseiva
Policy Evaluation and ManagementmediumMultiple ChoiceObjective-mapped

PCNSA Policy Evaluation and Management Practice Question

A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?

⚠ Common exam trap

Many candidates assume a rule allowing traffic to one zone implicitly covers all zones, but Palo Alto Networks firewalls require explicit zone matching for each rule, and failing to specify the correct destination zone results in a deny.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The rule only allows traffic from Engineering to Servers zone, not DMZ.

The security rule explicitly permits traffic from the 'Engineering' zone to the 'Servers' zone. Traffic destined to the 'DMZ' zone is a different zone, so the rule does not apply. By default, Palo Alto Networks firewalls enforce a deny-all policy for any traffic that does not match an explicit allow rule, which is why the traffic is denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The rule only allows traffic from Engineering to Servers zone, not DMZ.

    Why this is correct

    The rule explicitly allows Engineering to Servers; traffic to DMZ is not covered and is denied by default.

  • The rule is configured as an intrazone rule.

    Why it's wrong here

    An intrazone rule would apply within the same zone, but the traffic is between different zones (Engineering and DMZ).

  • The rule is disabled in the rulebase.

    Why it's wrong here

    If disabled, the rule would not appear in the rulebase or would be greyed out; there is no such indication.

  • SSL decryption is blocking the traffic.

    Why it's wrong here

    There is no indication of decryption; the issue is policy mismatch.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.