PCNSA Policy Evaluation and Management Practice Question
An administrator is configuring a security policy on a Palo Alto Networks firewall. The administrator wants to allow only HTTP and HTTPS traffic from the Trust zone to the Untrust zone, and block all other applications. The administrator creates a rule with source zone Trust, destination zone Untrust, application 'web-browsing' and 'ssl', action allow. However, after committing, users can still access other applications like SSH. What is the most likely explanation?
⚠ Common exam trap
The trap here is assuming that a rule allowing only specific applications will block all others, but an earlier rule allowing all applications will take precedence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
There is another rule above this rule that allows all applications from Trust to Untrust.
The most likely explanation is that there is another rule above the newly created rule that allows all applications or specifically SSH from Trust to Untrust. Because rules are evaluated top-down, the first matching rule is applied. The administrator should check the rule order and ensure the new rule is placed above any broader allow rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rule's application field is set to 'any' instead of the specific applications.
Why it's wrong here
If the application field were set to 'any', the rule would allow all applications, including SSH. However, the scenario states that the administrator set the application to 'web-browsing' and 'ssl'. If that were true, SSH should be blocked unless another rule allows it. The issue is more likely that another rule is allowing SSH, or the rule is not matching correctly. But the most straightforward explanation is that the application field is actually 'any' due to misconfiguration, but the scenario says the administrator set it to web-browsing and ssl. So this is not the most likely if we trust the scenario.
- ✗
The firewall is not licensed for App-ID, so it cannot enforce application-based rules.
Why it's wrong here
Without App-ID, the firewall cannot identify applications, and application-based rules would not work. However, the scenario implies that HTTP and HTTPS are allowed as intended, which suggests App-ID is functioning. If App-ID were not licensed, the firewall would likely not allow any traffic or would use default rules, not selectively allow web browsing. Thus, this is unlikely.
- ✓
There is another rule above this rule that allows all applications from Trust to Untrust.
Why this is correct
Security rules are evaluated top-down. If there is a rule above the newly created rule that allows all applications (or specifically SSH) from Trust to Untrust, that rule will be matched first, and the new rule will not be evaluated. This is a common cause of unexpected allowed traffic. The administrator should review the rulebase for overlapping rules above the intended rule.
- ✗
The security rule is not committed, so the old rules are still in effect.
Why it's wrong here
The scenario states that the administrator committed the policy. If the rule were not committed, the changes would not be active, but the administrator did commit. Therefore, this is not the cause. The issue is that another rule is allowing SSH, or the rule is not matching as expected.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.