Courseiva
Policy Evaluation and ManagementhardMultiple ChoiceObjective-mapped

PCNSA Policy Evaluation and Management Practice Question

An administrator notices that traffic from a specific IP 10.10.10.5 is not matching the expected security rule that should allow HTTP traffic. The rule uses a source address object defined as '10.10.10.0/24'. Upon investigation, the administrator finds that the traffic is from IP 10.10.10.5, but the rule still does not match. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The source address object is defined with a netmask of /32 instead of /24.

The address object uses a /24 netmask, so it should include .5. However, the object might have been defined with a wrong netmask or the rule is not using the object correctly. In this scenario, the issue is that the address object was accidentally set to /32, which matches only .0.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The traffic is being decrypted by a decryption policy before reaching the security rule.

    Why it's wrong here

    Incorrect. Decryption occurs after policy match; it does not affect whether a rule matches.

  • The rule's source zone is set to 'DMZ' instead of 'Internal'.

    Why it's wrong here

    Incorrect. If the zone were wrong, the rule would not match at all, but this does not explain why the address object appears correct yet fails.

  • A rule above this rule shadows it, blocking the traffic before evaluation.

    Why it's wrong here

    Incorrect. While shadowing is possible, the symptom described is that the rule does not match at all (no hit count increase), not that it is overridden by a deny rule.

  • The source address object is defined with a netmask of /32 instead of /24.

    Why this is correct

    Correct. A /32 netmask means the object matches only the single IP 10.10.10.0, not the entire subnet.

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.