PCNSA Policy Evaluation and Management Practice Question
A security administrator is troubleshooting a rule that appears to be matching correctly but is not allowing traffic. The rule uses source zone 'Trust' and destination zone 'Untrust', and the action is 'allow'. The traffic source is in the 'DMZ' zone. What is the most likely reason the traffic is denied?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source zone of the rule does not match the traffic's ingress zone.
The rule is configured with source zone 'Trust', but the traffic originates from the 'DMZ' zone. Since zones must match for a rule to apply, the rule does not match the traffic, so it is denied by the implicit deny rule. Options A, B, and D are incorrect: Security profiles (A) only apply after a rule matches; application identification (B) is not related to zone mismatch; and rule order (D) is irrelevant because the rule does not match due to zone mismatch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security profiles are blocking the traffic.
Why it's wrong here
Security profiles apply only after a rule's zone pair matches and permits the session, so they cannot deny traffic whose source sits in DMZ rather than the rule's Trust zone. Profiles are the right suspect when a permitted session is dropped for threat or content reasons.
- ✗
The application is not identified.
Why it's wrong here
Application identification affects App-ID based rules and security profiles, not zone matching; an unidentified application does not stop a zone-pair rule from permitting traffic. App-ID matters when a rule or profile is scoped to specific applications rather than any.
- ✓
The source zone of the rule does not match the traffic's ingress zone.
Why this is correct
Security policy evaluates the source zone against the traffic's ingress zone, which is DMZ here, not Trust. Because the rule specifies Trust as its source zone, it never matches this session, so the implicit interzone default deny drops the traffic despite the allow action.
- ✗
The rule is placed after a deny rule.
Why it's wrong here
Rule order matters only among rules the traffic actually matches; here the source is in DMZ, so the Trust-to-Untrust rule never matches and no deny rule below it is reached. Ordering is the correct diagnosis when a broader deny rule precedes a more specific permit for the same zone pair.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.