easyMultiple Select
PCNSA Practice Question: A security administrator is troubleshooting an…
A security administrator is troubleshooting an issue where users cannot access a specific website. The security policy allows web-browsing from the internal zone to the external zone. Which TWO actions should the administrator take to verify the traffic is being matched and allowed?
⚠ Common exam trap
PCNSA often tests the confusion between traffic logs and threat logs — candidates may pick Threat log for policy matching issues, but only the traffic log shows allow/deny decisions and policy names.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the policy has the correct source zone.
Option B is correct because a security policy only matches traffic when its source zone matches the ingress zone of the packet, so verifying the policy's source zone (internal) confirms the rule can actually match the users' web-browsing traffic. Option C is correct because the traffic log records each session with its matched policy, action (allow/deny), and source/destination zones, which directly shows whether the traffic is being matched and allowed. Option A is not relevant because CPU usage is a performance metric and does not indicate policy matching. Option D is not relevant because the Threat log records security profile detections such as malware, not whether a policy allowed the session. Option E is not relevant because a URL filtering profile affects content inspection after policy matching, not whether the traffic is matched and allowed by the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the system resources to check CPU usage.
Why it's wrong here
CPU usage reflects device health and dataplane load, not whether a specific session matched a security policy rule. It is tempting during troubleshooting because resource exhaustion can cause drops, but system resources would be the right check when traffic is broadly failing rather than one website being unreachable.
- ✓
Verify that the policy has the correct source zone.
Why this is correct
Zone matching is evaluated before other policy criteria, so a wrong source zone prevents the rule from ever matching the session. Confirming the source zone is set to the internal zone verifies the policy can actually match traffic originating from users.
- ✓
Check the traffic log for the session.
Why this is correct
The traffic log records each session's match against policy, showing whether the flow hit the intended rule or was denied by an implicit rule. Inspecting it confirms the session is being matched and allowed as expected.
- ✗
Look at the Threat log for any malware detections.
Why it's wrong here
The Threat log records signatures, antivirus and vulnerability events after traffic is allowed, so it cannot confirm whether the policy rule matched the session. It is tempting because a blocked website feels security-related, but Threat logs are the correct place when traffic passes the policy and a threat inspection action drops it.
- ✗
Examine the URL filtering profile applied to the policy.
Why it's wrong here
A URL filtering profile inspects HTTP request URLs for category or custom blocking, not whether the security policy rule matched the session. It is tempting because the symptom involves a specific website, but URL filtering would be the right check when the policy already permits traffic and a category block is suspected.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.