Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator is troubleshooting why a rule is not being hit. The rule has source zone Trust, destination zone Untrust, source address 10.0.0.0/8, destination address any, application web-browsing, action allow, and log at session end. The traffic is coming from 10.1.1.1 to 1.2.3.4 on port 80, zone Trust to Untrust. The rule count shows zero hits. What could be the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application is incorrectly identified; perhaps the traffic is using a different app.

The rule specifies application 'web-browsing', but the traffic may be classified as a different application (e.g., 'ssl' or 'http-proxy'), causing a mismatch. Even though the traffic uses port 80, the firewall identifies applications by signature, not just port. Option A is not necessary; the application does not need to be 'any' to match. Option C is false; the log setting does not affect whether the rule is hit. Option D is incorrect; a broad destination address (any) is not an issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application must be set to 'any'.

    Why it's wrong here

    Setting the application to web-browsing already matches HTTP traffic on port 80, so changing it to 'any' is unnecessary. App-ID resolves the actual application regardless of port. 'Any' would be correct only when the application is unknown or when you deliberately want to permit all applications in a broad rule.

  • ✓

    The application is incorrectly identified; perhaps the traffic is using a different app.

    Why this is correct

    Zero hits with matching zones, addresses and port usually means App-ID resolved the session to a different application than web-browsing, so the rule never matches. SSL, proxy or non-standard behaviour can cause this misidentification, requiring the application to be corrected or the rule broadened.

  • ✗

    The log setting is preventing hits.

    Why it's wrong here

    Log at session end only controls whether a log is generated when the session terminates; it has no bearing on rule matching or hit counters. The rule would still increment if traffic matched. This setting is correctly chosen when you want logging without affecting enforcement, so it is a plausible but irrelevant factor here.

  • ✗

    The destination address is too broad.

    Why it's wrong here

    A destination address of 'any' matches every destination, including 1.2.3.4, so it cannot prevent the rule from being hit. Broad destinations are normal in outbound rules. A narrower destination would be correct when you need to restrict egress to specific external hosts or subnets.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.