PCNSA Policy Evaluation and Management Practice Question
An administrator is troubleshooting why a policy is not being matched. Which THREE of the following are valid reasons a security rule might not be hit? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic does not match the source zone specified.
Options with null label, A, and D are correct. The null option is correct because if the destination address object is not in the rule's referenced address group, the rule will not match the traffic. Option A is correct because the traffic must match the source zone specified in the rule; otherwise, the rule is skipped. Option D is correct because a disabled rule is not evaluated and thus will not be hit. Option B is incorrect because a high hit count indicates the rule is being hit, not that it is not matched. Option C is incorrect because log forwarding configuration does not affect rule matching. Option E is incorrect because even though the action is set to drop, the rule can still be matched (and then drops traffic), so it can be hit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The traffic does not match the source zone specified.
Why this is correct
If source zone differs, the rule is not evaluated.
- ✗
The rule has a high hit count.
Why it's wrong here
High hit count means the rule is being matched.
- ✗
The rule has a log forwarding profile configured.
Why it's wrong here
Log forwarding does not prevent rule matching.
- ✓
The rule is in a disabled state.
Why this is correct
Disabled rules are not evaluated.
- ✗
The rule's action is set to drop.
Why it's wrong here
A drop action still causes the rule to be hit; it drops the packet.
- ✓
The destination address object is not in the rule's referenced address group.
Why this is correct
If the address group does not contain the destination IP, the rule does not match.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.