Courseiva
App-ID and Content-IDeasyMultiple ChoiceObjective-mapped

PCNSA Zone-based policy enforcement Practice Question

A small business owner wants to block all social media applications during work hours for employees. The firewall is configured with App-ID and has a security rule that denies the 'social-networking' application category from the internal zone to the internet zone. However, employees are still able to access Facebook and Twitter. The traffic logs show these applications are being allowed by a different rule. The administrator checks the security policy and finds the deny rule for social-networking is present but not matched. What is the most likely reason the deny rule is not being matched?

⚠ Common exam trap

A common mistake is to focus on zone or IP configuration when the actual issue is rule order. Always check if there is a higher-priority rule allowing the traffic before concluding that the deny rule's settings are incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

There is a rule above the deny rule that allows all traffic.

The most likely reason the deny rule is not matched is that a higher-priority rule (placed above the deny rule) is allowing all traffic, including social networking. In Palo Alto firewalls, security rules are evaluated from top to bottom; the first matching rule is applied. Even if a deny rule exists for social-networking, if a preceding rule allows all traffic, the deny rule is never evaluated. The traffic logs indicate that the applications are allowed by a different rule, which supports this explanation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • There is a rule above the deny rule that allows all traffic.

    Why this is correct

    Correct. A rule above the deny rule that allows all traffic would match before the deny rule, allowing social networking despite the deny rule being present.

  • The source IP address range does not include the employees' subnet.

    Why it's wrong here

    Incorrect. The stem does not specify an IP address range issue; the deny rule is configured with zones, not IP addresses. Even if the IP range were incorrect, the zone-based rule would still not match based on zone mismatch, but this is not indicated as the problem.

  • The source zone is set to 'any' but the actual traffic is coming from a different zone than assumed.

    Why it's wrong here

    Incorrect. If the source zone were set to 'any', it would match any source zone, not cause the rule to be unmatched. The actual issue described in the stem is not zone misconfiguration but a higher-priority allow rule.

  • The security rule does not have a URL Filtering profile attached.

    Why it's wrong here

    Incorrect. A URL Filtering profile is not required for App-ID to detect social networking applications. App-ID can identify applications without URL filtering.

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.