Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator is reviewing the security policy on a Palo Alto Networks firewall and notices that a rule allowing web browsing from the Trust zone to the Untrust zone has no application specified. The administrator wants the firewall to permit only web-browsing and ssl while blocking all other applications on ports 80 and 443. What should the administrator do to meet this requirement?

⚠ Common exam trap

The trap here is assuming that a rule without an application specified will automatically allow only common web applications, when in fact it allows all applications on the specified ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the applications web-browsing and ssl to the rule and set the action to Allow.

The Application column in a security rule determines which applications are allowed. By specifying web-browsing and ssl, the rule only permits those applications, and all other applications on ports 80 and 443 will not match and will be denied by subsequent rules or the default deny. This is the correct way to restrict traffic to specific applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the applications web-browsing and ssl to the rule and set the action to Allow.

    Why this is correct

    Specifying web-browsing and ssl in the Application column makes the rule match only those applications, so App-ID identifies the actual application regardless of port. Traffic that is not one of these applications will not match this rule and will fall through to subsequent rules or the default deny, effectively blocking all other applications on ports 80 and 443.

  • ✗

    Enable the 'Log at Session Start' option and monitor which applications are in use.

    Why it's wrong here

    Logging at session start provides visibility but does not enforce any restriction. The rule would still allow all applications on ports 80 and 443. While useful for troubleshooting, it does not fulfill the requirement to permit only web-browsing and ssl. The administrator must modify the rule's application list to enforce the policy.

  • ✗

    Create a new rule below the existing rule that denies any application on ports 80 and 443.

    Why it's wrong here

    A deny rule placed below the existing rule will never be evaluated for traffic that already matched the permissive rule above it. Because the original rule has no application specified, it matches all applications on those ports, so the new deny rule remains unused. The correct approach is to restrict the original rule rather than add a lower rule.

  • ✗

    Change the service to application-default and remove any application specification.

    Why it's wrong here

    Using application-default without specifying applications still allows any application that uses the default ports for the selected services. Since no application is selected, the rule continues to permit all applications on ports 80 and 443. To restrict to specific applications, they must be explicitly listed in the Application column.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.