PCNSA Policy Evaluation and Management Practice Question
An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?
⚠ Common exam trap
The trap here is overlooking User-ID as a dependency for user-based rules and instead blaming application definitions or rule order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source user group 'Marketing' is not properly synchronized with the firewall's user-ID agent.
User-based rules require User-ID to map IP addresses to users and groups. If the 'Marketing' group is not synchronized, the firewall cannot match the source user, and the session falls through to the implicit deny. Verifying User-ID agent connectivity and group mapping is the first troubleshooting step for user-based policy failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application 'web-browsing' is not correctly defined in the application filter.
Why it's wrong here
The application 'web-browsing' is a predefined application in Palo Alto Networks firewalls and is correctly defined by default. It is unlikely to be the cause unless it was manually modified, which is not indicated. The issue is more likely related to user identification.
- ✗
The security rule is placed below the implicit deny rule.
Why it's wrong here
The implicit deny rule is always at the bottom of the rulebase and cannot be moved. Placing a rule below it is impossible. The implicit deny is a default rule that denies all traffic not explicitly allowed, so the rule cannot be below it.
- ✗
The destination zone in the rule is incorrectly set to 'Untrust' instead of 'Trust'.
Why it's wrong here
For outbound internet traffic from Trust to Untrust, the destination zone should be 'Untrust'. Setting it to 'Trust' would be incorrect for this scenario. The rule as described has the correct zones, so this is not the cause of the denial.
- ✓
The source user group 'Marketing' is not properly synchronized with the firewall's user-ID agent.
Why this is correct
If User-ID is not correctly mapping users to the 'Marketing' group, the firewall cannot match the source user in the rule. The traffic will then fall through to the implicit deny rule. Ensuring the User-ID agent is connected and group mapping is configured is essential for user-based rules to function.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.