PCNSA Policy Evaluation and Management Practice Question
An administrator is designing a security policy for a new branch office. The policy must allow outbound web traffic from the Trust zone to the Untrust zone, but only for specific users in the 'Marketing' group. The firewall is integrated with Active Directory. Which TWO configurations are required to enforce this policy? (Choose two.)
⚠ Common exam trap
The trap here is assuming that SSL decryption or URL filtering is required for user-based policies, when actually User-ID and a security rule with user group are sufficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security rule with source zone Trust, destination zone Untrust, application web-browsing and ssl, and action Allow.
To allow outbound web traffic only for the Marketing group, two things are needed: a security rule that permits web-browsing and ssl from Trust to Untrust, and User-ID configuration to map users to IP addresses so that the Marketing group can be specified as the source user in the rule. Without both, the policy cannot be enforced correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a security rule with source zone Trust, destination zone Untrust, application web-browsing and ssl, and action Allow.
Why this is correct
This rule is necessary to allow web traffic from Trust to Untrust. It must include both web-browsing and ssl applications to cover HTTP and HTTPS. Without this rule, the default deny would block all web traffic. The rule provides the basic allow action, and user-based enforcement will be added via the user field in the rule.
- ✗
Configure a decryption policy to decrypt all outbound web traffic.
Why it's wrong here
A decryption policy is used to decrypt and inspect SSL traffic for threats and data filtering. It is not required to enforce user-based access control. The policy in question is about allowing specific users to access the web, not about inspecting the content. Therefore, decryption is not necessary to meet the requirement, though it might be used for other security purposes.
- ✗
Enable SSL decryption to identify users in the Marketing group.
Why it's wrong here
SSL decryption is not required to identify users for policy enforcement. User-ID works by mapping IP addresses to users through various methods such as AD agent, terminal services agent, or captive portal, independent of SSL decryption. While SSL decryption can provide additional visibility, it is not a prerequisite for user-based security policies.
- ✗
Create a URL filtering profile that allows only Marketing-related websites.
Why it's wrong here
URL filtering profiles are used to control access to websites based on categories or URL lists. They do not enforce user group membership. The requirement is to allow web traffic only for the Marketing group, which is achieved through user-based rules, not URL filtering. URL filtering could be used for additional control, but it is not required to meet the stated policy.
- ✓
Configure User-ID to map IP addresses to users and add the 'Marketing' group as a source user in the security rule.
Why this is correct
To enforce policy based on user groups, User-ID must be configured to map IP addresses to user identities, typically via Active Directory integration. Then, in the security rule, the source user field must include the 'Marketing' group. This ensures that only users in that group match the rule and are allowed web access. Without User-ID, the firewall cannot identify users, and the rule would either not match or match all users.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.