Courseiva
Securing Traffic →hardMultiple Choice

PCNSA Rule Ordering Practice Question

An organization has a security policy that allows all traffic from the corporate user zone to the internet, but they want to block access to social media sites only for a specific group of users in the HR department. What is the best approach?

⚠ Common exam trap

PCNSA often tests the importance of rule order and the use of User-ID for granular control, trapping candidates who forget that deny rules must precede allow rules to be effective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use user-ID to identify HR users and create a deny rule with source zone corporate, source user HR, application social-media, action deny, and place it before the allow rule.

The best approach is to use User-ID to identify HR users and create a deny rule with source zone corporate, source user HR, application social-media, action deny, and place it before the allow rule. This ensures that the deny rule is evaluated first, blocking social media for HR while allowing all other traffic. User-ID enables user-specific policies, and rule order is critical in Palo Alto Networks firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an allow rule for all users, then a deny rule for HR with application social-media.

    Why it's wrong here

    This approach fails because the allow rule is placed first, so all traffic, including HR users attempting to access social media, will match the allow rule and be permitted. The subsequent deny rule will never be evaluated for traffic that already matched the allow rule. Additionally, it does not explicitly use User-ID to identify HR users dynamically.

  • ✗

    Create a deny rule for the HR user group with application social-media before the allow rule.

    Why it's wrong here

    This approach places the deny rule with the correct order (before the allow rule). However, it is incorrect because it does not specify the source zone (corporate) and may rely on a static user group rather than dynamic User-ID identification. Without specifying the source zone, the rule could apply to traffic from other zones, potentially blocking unintended traffic, and it may not correctly identify the HR users if they are not part of a static group.

  • ✗

    Use user-ID to identify HR users and create a deny rule with source zone corporate, source user HR, application social-media, action deny, and place it after the allow rule.

    Why it's wrong here

    This approach uses User-ID and correct conditions (source zone corporate, source user HR, application social-media), but places the deny rule after the allow rule. Due to top-down rule evaluation, the allow rule matches first, permitting access to social media for all users including HR, so the deny rule never applies.

  • ✓

    Use user-ID to identify HR users and create a deny rule with source zone corporate, source user HR, application social-media, action deny, and place it before the allow rule.

    Why this is correct

    This approach correctly uses User-ID to dynamically identify HR users, specifies the source zone corporate and the application social-media, and places the deny rule before the allow rule. This ensures that traffic from HR users to social media is blocked by the deny rule, while all other traffic matches the subsequent allow rule.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.