Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse User Groups with Application Filters or External Dynamic Lists, which are also used in rules but for different purposes (applications and IP addresses, respectively).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User Group

To restrict a security rule to a specific user group and to weekdays, the administrator must use a User Group in the Source User field and a Schedule in the Schedule field. User Groups require User-ID to be configured. Schedules define the active times. Other options like Application Filters, External Dynamic Lists, and Security Profiles do not fulfill these specific requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    External Dynamic List

    Why it's wrong here

    External Dynamic Lists (EDLs) are used to dynamically import IP addresses, URLs, or domains. They are not used to specify user groups or schedules. EDLs could be used to restrict based on IP addresses, but the scenario requires user group and time restrictions, not IP-based restrictions.

  • ✓

    User Group

    Why this is correct

    A User Group (or dynamic user group) can be referenced in the security rule to restrict access to users in the 'Finance' group. This requires User-ID to be configured and mapping users to groups. By specifying the User Group in the rule's Source User field, only users in that group will match the rule. This is necessary to restrict the rule to Finance users.

  • ✗

    Application Filter

    Why it's wrong here

    Application Filters are used to group applications based on characteristics like category, subcategory, technology, and risk. They are not used to restrict access based on user groups or time. While they can be used to specify applications in a rule, they do not fulfill the requirements of user group or schedule restrictions.

  • ✗

    Security Profile

    Why it's wrong here

    Security Profiles are used to attach threat prevention settings to a security rule. They do not control user group or time-based activation. While they are important for security, they do not meet the requirements of restricting the rule to a specific user group and weekdays only.

  • ✓

    Schedule

    Why this is correct

    A Schedule object defines specific time ranges and days. Attaching a Schedule to the security rule ensures the rule is only active during the defined times, such as weekdays. This is necessary to restrict the rule to weekdays only. Without a Schedule, the rule would be active at all times.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.