PCNSA Device Management and Services Practice Question
An administrator is configuring a new PA-3220 firewall and needs to allow DNS queries from the internal network to an external DNS server. The internal network is in the Trust zone, and the external DNS server is reachable via the Untrust zone. Which type of security policy rule should be created to permit this traffic?
⚠ Common exam trap
The trap here is selecting an intrazone rule when the traffic crosses between two different zones, which requires an interzone rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An interzone rule from Trust to Untrust allowing UDP port 53
DNS queries from the internal network to an external server traverse from the Trust zone to the Untrust zone, which is interzone traffic. A security policy rule that specifies source zone Trust and destination zone Untrust, with the DNS application or UDP port 53, will correctly permit this traffic while enforcing zone-based security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A universal rule allowing UDP port 53 regardless of zone
Why it's wrong here
Universal rules are used in Panorama and apply to all firewalls in a device group, but they still require zone matching. A universal rule without zone restrictions would be overly permissive and is not the correct approach for a specific interzone requirement. It does not inherently match Trust to Untrust traffic unless zones are specified.
- ✓
An interzone rule from Trust to Untrust allowing UDP port 53
Why this is correct
Traffic from the internal network (Trust zone) to the external DNS server (Untrust zone) is interzone traffic. A security policy rule with source zone Trust and destination zone Untrust, application dns, and service application-default will permit DNS queries. This correctly allows the required traffic while maintaining zone-based segmentation.
- ✗
An intrazone rule from Trust to Trust allowing UDP port 53
Why it's wrong here
An intrazone rule applies to traffic within the same zone. Since the DNS server is in the Untrust zone, traffic from Trust to Untrust is not intrazone. This rule would not match the traffic and would not permit DNS queries to the external server. It is the wrong rule type for this scenario.
- ✗
An intrazone rule from Untrust to Untrust allowing UDP port 53
Why it's wrong here
This rule would apply to traffic within the Untrust zone, such as between two external interfaces. The DNS queries originate from the Trust zone and go to the Untrust zone, so this rule would not match. It does not address the required traffic flow and would not permit internal hosts to reach the external DNS server.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.