Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?

⚠ Common exam trap

Many candidates confuse a service object like 'udp-53' with an application, leading to a rule that allows any traffic on that port rather than just DNS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dns

The 'dns' application in PAN-OS accurately identifies DNS traffic based on its signature, typically on port 53. Using this application in the security rule ensures that only DNS traffic is allowed from the Guest zone to the DMZ zone, while other traffic is blocked. This approach leverages App-ID for precise control, rather than relying solely on port numbers, which can be less secure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    dns

    Why this is correct

    The 'dns' application in PAN-OS is specifically designed to identify DNS traffic, which typically uses UDP or TCP port 53. By using the 'dns' application in the security rule, the firewall will allow only DNS traffic that matches the application signature, ensuring that other traffic is not permitted. This is the correct application to meet the requirement of allowing only DNS traffic from Guest to DMZ.

  • ✗

    dns-over-https

    Why it's wrong here

    'dns-over-https' is an application for DNS queries sent over HTTPS (port 443), which is different from traditional DNS. The scenario does not specify DNS over HTTPS; it simply says DNS traffic. Traditional DNS uses port 53 and is identified by the 'dns' application. Using 'dns-over-https' would not allow standard DNS queries and would likely not match the traffic, resulting in denied DNS requests. Therefore, this is not the correct choice.

  • ✗

    dns-base

    Why it's wrong here

    'dns-base' is not a valid application name in PAN-OS. The correct application for DNS is simply 'dns'. Using an invalid application would result in the rule not matching any traffic, or potentially a configuration error. The administrator should use the standard 'dns' application to correctly identify DNS traffic. This option is a distractor and does not exist in the application database.

  • ✗

    udp-53

    Why it's wrong here

    'udp-53' is not an application; it is a service object that represents UDP port 53. While DNS primarily uses UDP port 53, using a service object instead of an application means the rule will allow any traffic on that port, not specifically DNS. This could allow other protocols that use UDP 53, such as some tunneling or malicious traffic. The requirement is to allow only DNS traffic, so the application 'dns' is more precise and secure.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.