easyMultiple Choice
PCNSA Practice Question: A security administrator wants to block traffic…
A security administrator wants to block traffic from a specific country using the firewall. How can this be achieved with minimal administrative overhead?
⚠ Common exam trap
It's easy for candidates to think an EDL (Option A) is required for country-based blocking, overlooking the built-in Geolocation feature that directly supports region-based rules with zero external configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security rule with a source region of the specified country.
Palo Alto Networks firewalls include a built-in Geolocation database that maps IP addresses to countries. By creating a security rule with the source region set to the specific country, the firewall automatically applies the block without requiring manual IP management or external feeds, minimizing administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an External Dynamic List (EDL) and reference it in a rule.
Why it's wrong here
An EDL pulls IP addresses from an external URL but lacks geolocation context, so it cannot block an entire country without manually compiling and updating every national IP range. This option tempts because EDLs efficiently manage dynamic, threat-intel feeds like known malware C2 servers, where they are the correct choice for automated blocklists.
- ✓
Create a security rule with a source region of the specified country.
Why this is correct
A source-region security rule leverages Palo Alto's built-in region-to-IP database, so the firewall resolves the country's address space automatically. This satisfies the minimal-administrative-overhead constraint: no external feeds, no manual IP list maintenance, and no dynamic address group updates are needed as the country's ranges change.
- ✗
Manually add all IP subnets from that country to a block rule.
Why it's wrong here
Manually enumerating every subnet is labour-intensive and quickly becomes stale as allocations change, defeating the minimal-overhead requirement. It is tempting because static block rules are simple to reason about, and it would be correct for a small, stable set of addresses that rarely changes.
- ✗
Disable routing to that country through the firewall.
Why it's wrong here
Removing routing stops all traffic to and from that country, including legitimate business flows, and requires ongoing route maintenance. It is tempting because it blocks the traffic outright, and it would be correct when no legitimate communication with that region exists at all.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.