PCNSA Policy Evaluation and Management Practice Question
After a policy change, a security administrator commits the candidate configuration, but the changes do not take effect immediately for all users. Some users report connectivity issues while others do not. What should the administrator check first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The commit was successful but the changes are applied only to new sessions, not existing sessions.
Firewall policy changes only affect new sessions. Existing sessions continue to use the old policy until they time out. This explains why some users (with existing sessions) may still be affected by the old policy, while new users (new sessions) experience the new policy. Option A is incorrect because an incorrect source zone would cause consistent issues for all traffic matching that rule, not just some users. Option B is unrelated to the commit process; interface type mismatch would cause connectivity issues regardless of session state. Option C is incorrect because a committed configuration is no longer in candidate state; if it were still candidate, the changes would not take effect at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The new rule has an incorrect source zone.
Why it's wrong here
Incorrect zone would affect all traffic from that zone.
- ✗
There is a mismatch between the virtual wire vs layer3 interface.
Why it's wrong here
Interface type does not cause selective session impact.
- ✗
The committed configuration is still in candidate state.
Why it's wrong here
After commit, configuration moves to running state.
- ✓
The commit was successful but the changes are applied only to new sessions, not existing sessions.
Why this is correct
Policy changes only affect new sessions; existing sessions continue with the old policy until they timeout.
Go deeper
Related to this question
About these practice questions
One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.