Courseiva

PCNSA Device Management and Services Practice Question

An administrator at a branch office with a PA-440 needs to allow the firewall itself to resolve external hostnames and to forward DNS queries from internal clients to public resolvers. The administrator wants to configure a DNS proxy on the firewall so clients use the firewall's interface IP as their DNS server. Which configuration step is required to enable this behavior?

⚠ Common exam trap

The trap here is conflating the firewall's own DNS resolver settings under Device > Setup > Services with the DNS Proxy feature under Network, which serves clients.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a DNS Proxy object under Network > DNS Proxy and assign it to the ingress interface, then create a security policy rule allowing DNS from the internal zone to the untrust zone.

DNS Proxy is a Network configuration object bound to an interface where client queries arrive, with upstream servers the firewall forwards to. Enabling it requires both the proxy object assignment and a security policy allowing DNS from the client zone to the upstream zone, because proxied traffic is still evaluated by policy. The firewall's own DNS server list is separate and only affects management-plane lookups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable DNS resolution under Device > Setup > Services and add the public resolvers to the firewall's DNS server list; clients will be automatically redirected to the firewall.

    Why it's wrong here

    The DNS server list under Device > Setup > Services configures the firewall's own resolver for management-plane lookups such as updates and licenses. It does not create a listening DNS service for internal clients, nor does it redirect client queries. Clients must still point at a DNS server, so this step alone does not deliver the proxying behavior the administrator wants.

  • ✗

    Configure an Application Override policy for DNS on port 53 so the firewall inspects and answers queries on behalf of clients.

    Why it's wrong here

    Application Override changes which App-ID the firewall applies to traffic on a given port; it does not create a DNS responder on the firewall. The firewall would still pass queries to whatever server the client addressed. This feature is used to correct misidentified applications, not to stand up a DNS proxy service for internal clients, so it fails the scenario.

  • ✗

    Create a NAT rule translating TCP and UDP port 53 from the internal zone to a public resolver, which will cause the firewall to act as a DNS proxy.

    Why it's wrong here

    Destination NAT can redirect client DNS queries to a resolver, but it does not make the firewall a proxy that answers queries itself or selectively forwards based on domain. The DNS Proxy feature is a distinct service bound to an interface. NAT alone would also bypass any domain-based forwarding or caching the proxy provides, so it does not meet the requirement.

  • ✓

    Configure a DNS Proxy object under Network > DNS Proxy and assign it to the ingress interface, then create a security policy rule allowing DNS from the internal zone to the untrust zone.

    Why this is correct

    A DNS Proxy object defines the interface where clients send queries and the upstream DNS servers the firewall forwards to. After assigning it to an interface, a security policy permitting UDP/TCP 53 from the client zone toward the upstream zone is still required for the proxied traffic. This combination lets internal clients use the firewall as their resolver while the firewall performs the outbound lookups.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.