Courseiva
Securing Traffic →mediumMultiple Choice

PCNSA Securing Traffic Practice Question

A security administrator needs to create a policy that allows users in the 'trust' zone to access the internet, but blocks access to a specific set of known malicious URLs. The administrator has subscribed to a URL filtering service and wants to use a custom URL category to block the malicious sites. Which configuration should be used?

⚠ Common exam trap

The trap here is using a predefined URL category like 'malware' instead of a custom category, which may not contain the specific malicious URLs the administrator wants to block and could lead to unintended blocking or allowing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom URL category containing the malicious URLs, then create a security policy rule that allows web-browsing and applies a URL filtering profile that blocks the custom category.

To block specific malicious URLs while allowing general internet access, the administrator should create a custom URL category with those URLs and apply a URL filtering profile that blocks that category. The security policy rule must allow web-browsing so that traffic is permitted and then inspected by the URL filtering profile. This ensures that only the listed malicious URLs are blocked, while all other web traffic is allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom URL category containing the malicious URLs, then create a security policy rule that denies web-browsing and applies a URL filtering profile that allows the custom category.

    Why it's wrong here

    Denying web-browsing in the security rule would block all web traffic, not just the malicious URLs. The URL filtering profile allowing the custom category would be irrelevant because the traffic is already denied at the application level. This configuration would prevent users from accessing any websites, which is not the requirement.

  • ✗

    Create a security policy rule that allows web-browsing and applies a URL filtering profile that blocks the 'malware' URL category.

    Why it's wrong here

    The 'malware' URL category is a predefined category that may include many sites, but it does not allow for a custom list of specific malicious URLs. The requirement is to block a specific set of known malicious URLs, which may not be covered by the predefined category. Using the predefined category could result in over-blocking or under-blocking, and does not meet the need for a custom list.

  • ✗

    Create a security policy rule that denies web-browsing and applies a URL filtering profile that blocks the 'malware' URL category.

    Why it's wrong here

    This rule denies all web-browsing traffic, which would block all internet access, not just the malicious URLs. The URL filtering profile is not effective because the traffic is denied before URL filtering can be applied. This fails to allow general internet access while blocking specific malicious sites.

  • ✓

    Create a custom URL category containing the malicious URLs, then create a security policy rule that allows web-browsing and applies a URL filtering profile that blocks the custom category.

    Why this is correct

    This approach uses a custom URL category to list the malicious URLs and a URL filtering profile to block that category. The security rule allows web-browsing but enforces the URL filtering profile, which will deny access to the malicious sites. This is the correct method to selectively block specific URLs while allowing general internet access.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.