PCNSA Policy Evaluation and Management Practice Question
An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse User Groups with Application Filters or External Dynamic Lists, which are also used in rules but for different purposes (applications and IP addresses, respectively).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User Group
To restrict a security rule to a specific user group and to weekdays, the administrator must use a User Group in the Source User field and a Schedule in the Schedule field. User Groups require User-ID to be configured. Schedules define the active times. Other options like Application Filters, External Dynamic Lists, and Security Profiles do not fulfill these specific requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
External Dynamic List
Why it's wrong here
External Dynamic Lists (EDLs) are used to dynamically import IP addresses, URLs, or domains. They are not used to specify user groups or schedules. EDLs could be used to restrict based on IP addresses, but the scenario requires user group and time restrictions, not IP-based restrictions.
- ✓
User Group
Why this is correct
A User Group (or dynamic user group) can be referenced in the security rule to restrict access to users in the 'Finance' group. This requires User-ID to be configured and mapping users to groups. By specifying the User Group in the rule's Source User field, only users in that group will match the rule. This is necessary to restrict the rule to Finance users.
- ✗
Application Filter
Why it's wrong here
Application Filters are used to group applications based on characteristics like category, subcategory, technology, and risk. They are not used to restrict access based on user groups or time. While they can be used to specify applications in a rule, they do not fulfill the requirements of user group or schedule restrictions.
- ✗
Security Profile
Why it's wrong here
Security Profiles are used to attach threat prevention settings to a security rule. They do not control user group or time-based activation. While they are important for security, they do not meet the requirements of restricting the rule to a specific user group and weekdays only.
- ✓
Schedule
Why this is correct
A Schedule object defines specific time ranges and days. Attaching a Schedule to the security rule ensures the rule is only active during the defined times, such as weekdays. This is necessary to restrict the rule to weekdays only. Without a Schedule, the rule would be active at all times.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.