Courseiva
Securing TrafficmediumMultiple ChoiceObjective-mapped

PCNSA Securing Traffic Practice Question

A security administrator notices that traffic from the internal trust zone to the external untrust zone is being allowed despite a security policy rule explicitly denying that traffic. The rule is present in the policy list and the match conditions seem correct. What is the most likely cause of this issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

There is an allow rule above the deny rule that matches the traffic first.

Any deny rule placed after a matching allow rule will not be evaluated if the allow rule is hit first. Rule order is critical in PAN-OS. Option A is wrong because removing the rule is not the cause. Option B is wrong because policy is not optional. Option C is wrong because implicit deny exists but only if no rule matches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The security policy is not enabled on the firewall.

    Why it's wrong here

    Security policy is always enforced.

  • The deny rule was removed from the configuration.

    Why it's wrong here

    If the rule were removed, it wouldn't be present.

  • The traffic is matching the implicit deny rule at the end.

    Why it's wrong here

    Implicit deny would block, not allow.

  • There is an allow rule above the deny rule that matches the traffic first.

    Why this is correct

    Rule order evaluation stops on first match; allow rule above the deny will permit traffic.

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.