PCNSA Policy Evaluation and Management Practice Question
An administrator needs to implement a policy where traffic from the 'Sales' zone to the 'Finance' zone is allowed only for the 'ms-office365' application, but traffic from 'Sales' to 'Finance' using any other application must be denied. Which rule design meets this requirement efficiently?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a rule that allows ms-office365 from Sales to Finance, and place a deny all rule after it.
In Palo Alto firewalls, security rules are either allow or deny, not both. To allow only 'ms-office365' and deny all other traffic from Sales to Finance, you create an allow rule for that application, followed by a deny-all rule for the same source/destination. This ensures efficiency by allowing the specific traffic first, then blocking everything else. Option A is incorrect as it uses a deny-all first, then tries to allow with an application default deny, which is not a valid concept and would require an explicit allow rule. Option B is incorrect because allowing all traffic and then denying the specific application defeats the purpose. Option D is invalid because a single rule cannot contain both allow and deny actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a rule that denies all traffic from Sales to Finance, and then an application default deny rule that allows ms-office365.
Why it's wrong here
A deny-all rule placed before the allow rule blocks ms-office365 traffic too, because PAN-OS evaluates rules top-down and stops at the first match. It is tempting because explicit deny rules feel like tight security, and this ordering would work if the allow rule sat above the deny.
- ✗
Create a rule that allows all traffic from Sales to Finance, then a rule that denies ms-office365.
Why it's wrong here
Allowing all Sales-to-Finance traffic first means the subsequent deny for ms-office365 is never reached, since PAN-OS stops at the first matching rule. It is tempting because it inverts the intended logic, and would be correct if the goal were to block only Office 365 while permitting everything else.
- ✓
Create a rule that allows ms-office365 from Sales to Finance, and place a deny all rule after it.
Why this is correct
Palo Alto Networks evaluates security rules top-down, so an allow rule matching ms-office365 from Sales to Finance followed by a deny-all rule permits only that application while blocking all other traffic between the zones. This satisfies the requirement with minimal rules.
- ✗
Create one rule that allows ms-office365 and denies all other traffic from Sales to Finance.
Why it's wrong here
PAN-OS security rules carry a single action, so one rule cannot both allow ms-office365 and deny everything else. It is tempting because it appears to express the whole requirement in one object, and it would be correct if the platform supported per-application actions within a rule.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.