Courseiva
easyMultiple Choice

PCNSA Practice Question: Based on the exhibit, what action did the…

Exhibit

Refer to the exhibit.

2023/07/25 14:35:12,THREAT,url,1,2023/07/25 14:35:12,192.168.1.10,203.0.113.5,192.168.1.10,203.0.113.5,allow,,,web-browsing,vsys1,trust,untrust,ethernet1/1,ethernet1/2,2012,1,1,45,2023/07/25 14:35:12,0,any,0,2621440000,10.0.0.1,0,0,0,0,,PA-5250,from-policy,,,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0

Note: The log entry is truncated for readability.

Based on the exhibit, what action did the firewall take on this traffic?

⚠ Common exam trap

Watch out — candidates often confuse the firewall's action with the result of a security profile (e.g., URL filtering or threat prevention), but the question specifically asks for the action taken on the traffic, which is determined solely by the security policy rule's action field.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allowed the traffic.

The exhibit shows a traffic log entry with the action 'allow' (or a green checkmark indicating a permit), meaning the firewall evaluated the traffic against security policies and determined it matched a rule set to allow. The session was established and forwarded without being blocked or reset, confirming the correct answer is C.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the connection.

    Why it's wrong here

    A reset action terminates the session by sending TCP RST packets, but the exhibit's log shows the firewall blocked the URL through URL filtering, not a reset. Reset would be correct where a security profile configured to reset-client-and-server applies; here the URL category block is the actual action.

  • ✗

    Blocked the URL.

    Why it's wrong here

    No URL filtering block shown.

  • ✓

    Allowed the traffic.

    Why this is correct

    The session log shows the firewall permitted the flow, with the action field indicating allow and the session reaching established state. Traffic matching a permit rule in the security policy was forwarded rather than dropped or reset.

  • ✗

    Denied the traffic.

    Why it's wrong here

    A deny action appears in the log, but the exhibit shows the firewall reset the session rather than silently dropping it, so 'denied' misstates the mechanism. Deny is correct when the firewall drops packets without a reset; here the reset action distinguishes it from a plain deny.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.