PCNSA Policy Evaluation and Management Practice Question
An administrator is designing a security policy for a Palo Alto Networks firewall. The administrator wants to ensure that the policy is efficient and follows best practices for rule evaluation. Which two actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that a deny all rule at the top is a good security practice, when it actually blocks all traffic and makes other rules unreachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable logging at the end of the session for rules that allow critical traffic.
Ordering rules from specific to general ensures that intended traffic matches the correct rule before a broader rule can apply. Logging at session end for critical allow rules provides necessary visibility. Using any in source/destination or placing a deny all at the top would create security gaps or block legitimate traffic. Application filters may be too broad for precise control. These two practices support an efficient and secure rulebase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use any as the source and destination in rules to simplify policy management.
Why it's wrong here
Using any for source and destination creates overly permissive rules that can allow unintended traffic. Best practice is to use specific addresses or groups to enforce least privilege. While any may be used in some cases, it should be avoided in security rules that permit access to sensitive resources. Overly broad rules also make it harder to audit and troubleshoot.
- ✓
Enable logging at the end of the session for rules that allow critical traffic.
Why this is correct
Enabling logging at session end for critical allow rules provides visibility into allowed traffic, including source, destination, application, and bytes. This is essential for auditing, troubleshooting, and detecting anomalies. While logging at session start can be useful for long-lived sessions, session-end logging captures the full session details and is a common best practice for critical rules.
- ✓
Place rules with more specific source and destination addresses above rules with broader address ranges.
Why this is correct
Placing more specific rules above broader ones ensures that traffic matching the specific criteria is handled by the intended rule before a general rule can match it. This follows the top-down evaluation order and prevents unintended permission or denial. It also improves readability and reduces the risk of shadowed rules, where a broader rule above makes a specific rule unreachable.
- ✗
Place a deny all rule at the top of the rulebase to block unwanted traffic immediately.
Why it's wrong here
A deny all rule at the top would block all traffic, including legitimate traffic, because rules are evaluated top-down. Best practice is to have an explicit deny all rule at the bottom of the rulebase to catch traffic not explicitly allowed. Placing it at the top would make all other rules unreachable and disrupt operations. The implicit deny at the bottom already blocks unmatched traffic, but an explicit deny can provide logging.
- ✗
Use application filters instead of specific applications to reduce the number of rules.
Why it's wrong here
Application filters can group applications by category, subcategory, technology, or risk, but they are broader than specific applications and may allow unintended applications. Best practice is to use specific applications when possible to enforce precise control. Application filters can be useful for broad policies, but they should be used with caution. Reducing rule count at the expense of precision can weaken security.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.