PCNSA Securing Traffic Practice Question
An organization wants to segment internal traffic between the Engineering and Finance departments and apply threat prevention. Which TWO actions should be taken? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse NAT or QoS with security controls, thinking address translation or bandwidth management can segment traffic, when in fact only zones and security rules enforce access control and threat inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define separate security zones for Engineering and Finance.
Option B is correct because defining separate security zones for Engineering and Finance is the foundational step for segmenting internal traffic; zones are the logical containers that security rules reference, so distinct zones allow you to control and inspect traffic flowing between the two departments. Option E is correct because, once inter-zone rules exist between the Engineering and Finance zones, attaching Threat Prevention profiles (which bundle Anti-Virus, Anti-Spyware, Vulnerability Protection, and URL Filtering) to those rules enforces the required threat inspection on that east-west traffic. Option A is incorrect because NAT policies only translate addresses for routing or hiding purposes and do not segment traffic or apply threat prevention. Option C is incorrect because a single security zone for all internal traffic collapses the segmentation boundary, preventing distinct inter-zone policy enforcement. Option D is incorrect because QoS policies manage bandwidth and prioritization, not segmentation or threat prevention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure NAT policies to translate internal addresses.
Why it's wrong here
NAT rewrites addresses and ports for routing or concealment; it does not separate departments into distinct zones or attach threat prevention profiles to their traffic. NAT is tempting because it is configured on the same firewall and often accompanies segmentation projects, and would be correct when internal addresses must be hidden from external networks.
- ✓
Define separate security zones for Engineering and Finance.
Why this is correct
Separate zones for Engineering and Finance create the trust boundaries that inter-zone security rules reference, enabling traffic between the departments to be inspected and controlled. Without distinct zones, segmentation policy cannot distinguish the two departments' traffic at the firewall.
- ✗
Create a single security zone for all internal traffic.
Why it's wrong here
A single internal zone places Engineering and Finance in the same trust boundary, so intra-zone traffic bypasses policy enforcement and no threat inspection occurs between them. Consolidating zones is tempting for reducing rule count and administrative overhead, and suits environments where all internal users share one identical trust level.
- ✗
Enable QoS policies between the zones.
Why it's wrong here
QoS policies classify and prioritise or shape bandwidth; they neither create the inter-zone segmentation nor apply security profiles to permitted traffic. QoS is tempting because it also uses zone-based policy rules, and would be correct where the requirement is guaranteeing latency or bandwidth for specific applications across existing zones.
- ✓
Apply Threat Prevention profiles to the inter-zone security rules.
Why this is correct
Attaching Threat Prevention profiles to the inter-zone rules enforces vulnerability, anti-spyware, and antivirus inspection on traffic crossing between Engineering and Finance. Zone definition alone only segments traffic; the profile supplies the actual threat inspection the scenario requires.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.