PCNSA Policy Evaluation and Management Practice Question
An administrator is auditing the security policy on a PA-3220 firewall. The administrator notices that a rule allowing RDP from the 'Trust' zone to the 'DMZ' zone has a source user of 'domain\jdoe' and is positioned below a broader rule that allows any application from Trust to DMZ for any user. The administrator wants the user-specific rule to be evaluated first. What is the most efficient way to achieve this?
⚠ Common exam trap
The trap here is assuming that rule order can be overridden by other means such as user negation or application matching, when in fact rule position is the primary factor in evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Move the user-specific rule above the broader rule in the security policy.
Security rules are processed in a top-down sequence, and the first rule that matches all criteria (source zone, destination zone, source address, destination address, application, user, etc.) is applied. To ensure a specific rule takes precedence over a more general one, it must be placed above the general rule. Moving the user-specific rule above the broader rule guarantees it is evaluated first, allowing the intended access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new rule with the same source user and place it at the bottom of the rulebase.
Why it's wrong here
Placing a new rule at the bottom will not help because the broader rule above it will still match first. The firewall evaluates rules from top to bottom and stops at the first match. A rule at the bottom will only be evaluated if no other rules match. Therefore, this approach is ineffective for ensuring the user-specific rule is applied.
- ✓
Move the user-specific rule above the broader rule in the security policy.
Why this is correct
Security rules are evaluated top-down, and the first matching rule is applied. Placing the user-specific rule above the broader rule ensures it is evaluated first. This is the correct approach because rule order is critical; the broader rule would otherwise match all traffic, including that from the specific user, and the user-specific rule would never be hit. This is a fundamental best practice for policy management.
- ✗
Change the source user on the broader rule to 'any' and rely on application-based matching.
Why it's wrong here
Changing the source user to 'any' does not help; the broader rule already likely has 'any' user. Relying on application-based matching does not address user-specific requirements. The issue is rule order, not application identification. The user-specific rule must be evaluated before the broader rule to take effect, so modifying the broader rule's user field does not solve the problem.
- ✗
Add a negative source user to the broader rule to exclude 'domain\jdoe'.
Why it's wrong here
While you can negate a source user on a rule, this approach is not the most efficient and can lead to complex, hard-to-manage policies. The broader rule would still match other users, but the specific user would be excluded. However, this does not guarantee the user-specific rule is hit if other rules above also match. The recommended method is to reorder rules to place more specific rules first.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.