PCNSA Policy Evaluation and Management Practice Question
An administrator has configured a security policy with a rule that allows traffic from the 'Guest' zone to the 'Internet' zone. The rule uses the application 'web-browsing' and 'ssl' with service 'application-default'. Users in the Guest zone report that they cannot access a specific website that uses a non-standard port for HTTPS (port 8443). What is the most likely cause of the issue?
⚠ Common exam trap
The trap here is assuming that specifying the application 'ssl' automatically allows any port, but the service setting controls the port and 'application-default' only permits default ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service 'application-default' only allows default ports, so port 8443 is blocked. A custom service must be added to the rule.
The service 'application-default' restricts traffic to the default ports for the selected applications. For 'ssl', the default port is 443. Since the website uses port 8443, the traffic does not match the service and is blocked. To allow it, the administrator must create a custom service for port 8443 and add it to the security rule, ensuring the application is still identified correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The service 'application-default' only allows default ports, so port 8443 is blocked. A custom service must be added to the rule.
Why this is correct
The service 'application-default' uses the default ports defined for the application. For 'ssl', the default port is 443. Since the website uses port 8443, the traffic is not matching the service and is therefore blocked. Adding a custom service for port 8443 and including it in the rule would resolve the issue.
- ✗
The security rule is not matching because the application 'web-browsing' does not cover HTTPS traffic.
Why it's wrong here
'web-browsing' covers HTTP, while 'ssl' covers HTTPS. The rule includes both, so HTTPS traffic on port 443 would be allowed. The issue is specifically with the non-standard port, not the application coverage. The rule would work for standard HTTPS but not for port 8443.
- ✗
The firewall is configured to block non-standard ports by default, and a security profile must be applied to allow them.
Why it's wrong here
The firewall does not block non-standard ports by default; it depends on the security rule's service definition. Security profiles are for threat inspection, not for permitting ports. The rule's service specification is what controls which ports are allowed. No implicit block exists for non-standard ports.
- ✗
The application 'ssl' does not support non-standard ports; a custom application must be created.
Why it's wrong here
The 'ssl' application can be used on non-standard ports if the service is defined accordingly. It is not that 'ssl' does not support non-standard ports; rather, the service 'application-default' restricts to default ports. Creating a custom application is not necessary; you can simply specify a custom service.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.