PCNSA Policy Evaluation and Management Practice Question
An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?
⚠ Common exam trap
Many candidates confuse a service object like 'udp-53' with an application, leading to a rule that allows any traffic on that port rather than just DNS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dns
The 'dns' application in PAN-OS accurately identifies DNS traffic based on its signature, typically on port 53. Using this application in the security rule ensures that only DNS traffic is allowed from the Guest zone to the DMZ zone, while other traffic is blocked. This approach leverages App-ID for precise control, rather than relying solely on port numbers, which can be less secure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
dns
Why this is correct
The 'dns' application in PAN-OS is specifically designed to identify DNS traffic, which typically uses UDP or TCP port 53. By using the 'dns' application in the security rule, the firewall will allow only DNS traffic that matches the application signature, ensuring that other traffic is not permitted. This is the correct application to meet the requirement of allowing only DNS traffic from Guest to DMZ.
- ✗
dns-over-https
Why it's wrong here
'dns-over-https' is an application for DNS queries sent over HTTPS (port 443), which is different from traditional DNS. The scenario does not specify DNS over HTTPS; it simply says DNS traffic. Traditional DNS uses port 53 and is identified by the 'dns' application. Using 'dns-over-https' would not allow standard DNS queries and would likely not match the traffic, resulting in denied DNS requests. Therefore, this is not the correct choice.
- ✗
dns-base
Why it's wrong here
'dns-base' is not a valid application name in PAN-OS. The correct application for DNS is simply 'dns'. Using an invalid application would result in the rule not matching any traffic, or potentially a configuration error. The administrator should use the standard 'dns' application to correctly identify DNS traffic. This option is a distractor and does not exist in the application database.
- ✗
udp-53
Why it's wrong here
'udp-53' is not an application; it is a service object that represents UDP port 53. While DNS primarily uses UDP port 53, using a service object instead of an application means the rule will allow any traffic on that port, not specifically DNS. This could allow other protocols that use UDP 53, such as some tunneling or malicious traffic. The requirement is to allow only DNS traffic, so the application 'dns' is more precise and secure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.