Courseiva
easyMultiple Select

PCNSA Practice Question: A security administrator is troubleshooting an…

A security administrator is troubleshooting an issue where users cannot access a specific website. The security policy allows web-browsing from the internal zone to the external zone. Which TWO actions should the administrator take to verify the traffic is being matched and allowed?

⚠ Common exam trap

PCNSA often tests the confusion between traffic logs and threat logs — candidates may pick Threat log for policy matching issues, but only the traffic log shows allow/deny decisions and policy names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the policy has the correct source zone.

Option B is correct because a security policy only matches traffic when its source zone matches the ingress zone of the packet, so verifying the policy's source zone (internal) confirms the rule can actually match the users' web-browsing traffic. Option C is correct because the traffic log records each session with its matched policy, action (allow/deny), and source/destination zones, which directly shows whether the traffic is being matched and allowed. Option A is not relevant because CPU usage is a performance metric and does not indicate policy matching. Option D is not relevant because the Threat log records security profile detections such as malware, not whether a policy allowed the session. Option E is not relevant because a URL filtering profile affects content inspection after policy matching, not whether the traffic is matched and allowed by the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review the system resources to check CPU usage.

    Why it's wrong here

    CPU usage reflects device health and dataplane load, not whether a specific session matched a security policy rule. It is tempting during troubleshooting because resource exhaustion can cause drops, but system resources would be the right check when traffic is broadly failing rather than one website being unreachable.

  • ✓

    Verify that the policy has the correct source zone.

    Why this is correct

    Zone matching is evaluated before other policy criteria, so a wrong source zone prevents the rule from ever matching the session. Confirming the source zone is set to the internal zone verifies the policy can actually match traffic originating from users.

  • ✓

    Check the traffic log for the session.

    Why this is correct

    The traffic log records each session's match against policy, showing whether the flow hit the intended rule or was denied by an implicit rule. Inspecting it confirms the session is being matched and allowed as expected.

  • ✗

    Look at the Threat log for any malware detections.

    Why it's wrong here

    The Threat log records signatures, antivirus and vulnerability events after traffic is allowed, so it cannot confirm whether the policy rule matched the session. It is tempting because a blocked website feels security-related, but Threat logs are the correct place when traffic passes the policy and a threat inspection action drops it.

  • ✗

    Examine the URL filtering profile applied to the policy.

    Why it's wrong here

    A URL filtering profile inspects HTTP request URLs for category or custom blocking, not whether the security policy rule matched the session. It is tempting because the symptom involves a specific website, but URL filtering would be the right check when the policy already permits traffic and a category block is suspected.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.