PCNSA Policy Evaluation and Management Practice Question
An administrator is creating a new security rule at the top of the rulebase to allow specific web traffic. After committing, users report that all web traffic is now blocked, including traffic that was previously allowed by a lower rule. The new rule's action is set to 'Deny' and its source and destination are set to 'any'. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that rule order does not matter or that newer rules have priority, when in fact position in the rulebase is the sole determinant of evaluation order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The new deny rule is placed above the existing allow rules, so it matches all web traffic before the allow rules can be evaluated.
Security rules are processed in order from top to bottom. The first rule that matches the traffic determines the action. A broad deny rule placed at the top will match all web traffic and block it before any lower allow rules can be evaluated. To fix this, the administrator should move the deny rule below specific allow rules or narrow its match criteria.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The new deny rule is placed above the existing allow rules, so it matches all web traffic before the allow rules can be evaluated.
Why this is correct
Security rules are evaluated top-down, and the first matching rule is applied. Placing a broad deny rule with any source and destination above existing allow rules causes all web traffic to match the deny rule first, blocking it. The administrator should place specific allow rules above broad deny rules or make the deny rule more specific.
- ✗
The new rule has a higher priority because it was created more recently, overriding older rules regardless of position.
Why it's wrong here
Rule priority is based on position in the rulebase, not creation time. Newer rules do not automatically take precedence. The administrator must explicitly place the rule in the desired order. Creation timestamp has no effect on rule evaluation order.
- ✗
The firewall applies security rules in a random order, so the deny rule sometimes matches before the allow rules.
Why it's wrong here
Palo Alto Networks firewalls evaluate security rules in a deterministic top-down order, not randomly. The order is defined by the rulebase position. Random evaluation does not occur, so this cannot explain the consistent blocking of all web traffic after adding the deny rule.
- ✗
The deny rule is only evaluated after the allow rules, so it should not block allowed traffic; the issue is likely a misconfigured application filter.
Why it's wrong here
If the deny rule were evaluated after the allow rules, allowed traffic would not be blocked. However, the rule was placed at the top, so it is evaluated first. The symptom of all web traffic being blocked is consistent with a top-positioned broad deny rule, not an application filter issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.