PCNSA Policy Evaluation and Management Practice Question
An administrator is reviewing the security policy and notices a rule that allows all traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only web browsing (HTTP and HTTPS) is allowed, while all other traffic is blocked. What should the administrator do?
⚠ Common exam trap
The trap here is thinking that adding a deny rule below an allow-all rule will restrict traffic, when in fact the allow-all rule above will match all traffic first, making the deny rule ineffective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the existing rule to allow only the 'web-browsing' and 'ssl' applications, and ensure the rule is placed above any other permissive rules.
To restrict traffic to only HTTP and HTTPS, the existing permissive rule should be modified to allow only the 'web-browsing' and 'ssl' applications. The implicit deny at the bottom will block all other traffic. It is also important to ensure the rule is positioned correctly in the rulebase, above any other rules that might allow broader traffic. Creating unnecessary deny rules is not best practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new rule to deny all traffic from Trust to Untrust, and place it above the existing allow rule.
Why it's wrong here
Placing a deny all rule above the existing allow rule would block all traffic, including the desired web browsing. The deny rule would match first, preventing the allow rule from being evaluated. This would not achieve the goal of allowing only HTTP and HTTPS. The correct approach is to modify the allow rule to be more specific.
- ✗
Modify the existing rule to allow only the 'web-browsing' and 'ssl' applications, and add a deny rule below for all other traffic.
Why it's wrong here
Modifying the existing rule to allow only web-browsing and ssl applications is correct, but adding a deny rule below for all other traffic is unnecessary because the implicit deny will block all other traffic. However, the implicit deny is at the bottom, so if the modified rule allows only those applications, all other traffic will be denied by the implicit deny. Adding an explicit deny rule is redundant and not best practice. The better approach is to modify the rule and rely on the implicit deny.
- ✗
Leave the rule as is and create a new rule to deny all non-web traffic, placing it below the allow rule.
Why it's wrong here
The existing allow rule permits all traffic, so any traffic will match it and be allowed. A deny rule placed below will never be evaluated because the allow rule above matches all traffic first. Therefore, this approach does not restrict traffic to only web browsing. The existing rule must be modified to be more specific.
- ✓
Modify the existing rule to allow only the 'web-browsing' and 'ssl' applications, and ensure the rule is placed above any other permissive rules.
Why this is correct
The best practice is to modify the existing rule to allow only the specific applications (web-browsing and ssl) and ensure it is placed correctly in the rulebase. The implicit deny will block all other traffic. Placing it above other permissive rules ensures it is evaluated first. This achieves the goal without unnecessary deny rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.