Courseiva

PCNSA Device Management and Services Practice Question

An administrator is configuring a new PA-3220 firewall and needs to allow DNS queries from the internal network to an external DNS server. The internal network is in the Trust zone, and the external DNS server is reachable via the Untrust zone. Which type of security policy rule should be created to permit this traffic?

⚠ Common exam trap

The trap here is selecting an intrazone rule when the traffic crosses between two different zones, which requires an interzone rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An interzone rule from Trust to Untrust allowing UDP port 53

DNS queries from the internal network to an external server traverse from the Trust zone to the Untrust zone, which is interzone traffic. A security policy rule that specifies source zone Trust and destination zone Untrust, with the DNS application or UDP port 53, will correctly permit this traffic while enforcing zone-based security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A universal rule allowing UDP port 53 regardless of zone

    Why it's wrong here

    Universal rules are used in Panorama and apply to all firewalls in a device group, but they still require zone matching. A universal rule without zone restrictions would be overly permissive and is not the correct approach for a specific interzone requirement. It does not inherently match Trust to Untrust traffic unless zones are specified.

  • ✓

    An interzone rule from Trust to Untrust allowing UDP port 53

    Why this is correct

    Traffic from the internal network (Trust zone) to the external DNS server (Untrust zone) is interzone traffic. A security policy rule with source zone Trust and destination zone Untrust, application dns, and service application-default will permit DNS queries. This correctly allows the required traffic while maintaining zone-based segmentation.

  • ✗

    An intrazone rule from Trust to Trust allowing UDP port 53

    Why it's wrong here

    An intrazone rule applies to traffic within the same zone. Since the DNS server is in the Untrust zone, traffic from Trust to Untrust is not intrazone. This rule would not match the traffic and would not permit DNS queries to the external server. It is the wrong rule type for this scenario.

  • ✗

    An intrazone rule from Untrust to Untrust allowing UDP port 53

    Why it's wrong here

    This rule would apply to traffic within the Untrust zone, such as between two external interfaces. The DNS queries originate from the Trust zone and go to the Untrust zone, so this rule would not match. It does not address the required traffic flow and would not permit internal hosts to reach the external DNS server.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.