Courseiva

PCNSA · domain

Policy Evaluation and Management

This domain covers how PAN-OS evaluates security policy: rule order, zone and address matching, application identification, and implicit rules. Questions present traffic scenarios—often with exhibits—and ask why traffic is allowed or denied, which rule is hit, or what the firewall does next.

65 questions17 easy23 medium25 hard

Focused practice

Practice Policy Evaluation and Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Policy Evaluation and Management

Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.

Interpreting security rule match criteria: source/destination zone, address, user, application, and service.

Using the Traffic log and session details to identify the rule that allowed or denied a session.

Applying App-ID and Service/Application Override behavior to determine whether a rule matches.

Understanding implicit intrazone and interzone default rules and rule-order evaluation.

Watch out for

Common Policy Evaluation and Management exam traps

  • ▸Assuming a rule with application web-browsing matches all web traffic; App-ID may identify a different application and skip the rule.
  • ▸Forgetting that a new subnet must be added to both the security rule and any NAT or routing configuration to work.
  • ▸Overlooking the implicit deny or default intrazone allow rules when no explicit rule matches traffic.

Question index

All Policy Evaluation and Management questions (65)

Click any question to see the full explanation, or start a practice session above.

1

An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?

Hard
2

A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?

Medium
3

An administrator is troubleshooting why a security rule that allows traffic from the Trust zone to the DMZ zone is not being hit. The administrator confirms that the source IP, destination IP, and application are correct. Which factor should the administrator check next to determine why the rule is being bypassed?

Hard
4

Which TWO are best practices for managing security policies in a Palo Alto Networks firewall?

Medium
5

An administrator needs to implement a policy where traffic from the 'Sales' zone to the 'Finance' zone is allowed only for the 'ms-office365' application, but traffic from 'Sales' to 'Finance' using any other application must be denied. Which rule design meets this requirement efficiently?

Hard
6

How can an administrator quickly identify which security rules are not being used in order to clean up the rulebase?

Easy
7

An administrator is configuring a security policy on a PA-3260 firewall. The administrator wants to ensure that a rule allowing SSH from the 'Management' zone to the 'Internal' zone is only active during business hours (9 AM to 5 PM) on weekdays. The administrator creates a schedule object named 'BusinessHours' and attaches it to the rule. However, after applying the policy, SSH access is allowed at all times. What is the most likely reason?

Hard
8

What does a 'shadowed' rule mean in the context of policy evaluation?

Easy
9

An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)

Medium
10

Drag and drop the steps to configure Active/Passive High Availability on a Palo Alto Networks firewall into the correct order.

Medium
11

A network security administrator is configuring a security policy on a PA-5220 firewall. The administrator wants to allow HTTP and HTTPS traffic from the 'Guest' zone to the 'Internet' zone, but only for specific users in the 'guest-users' group. The administrator creates a rule with source zone 'Guest', destination zone 'Internet', source user 'guest-users', and application 'web-browsing' and 'ssl'. However, when testing, all Guest users can access the Internet, not just those in the group. What is the most likely cause?

Hard
12

Refer to the exhibit. The administrator sees that traffic from 10.10.1.12 is being denied by rule2. Which action should the administrator take to allow this traffic while maintaining security?

Hard
13

An administrator is reviewing the security policy and notices a rule that allows all traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only web browsing (HTTP and HTTPS) is allowed, while all other traffic is blocked. What should the administrator do?

Medium
14

An administrator is configuring a security policy to allow access to a critical application. The application uses multiple protocols and dynamic ports. The administrator wants to ensure that the policy is as secure as possible while allowing legitimate traffic. Which two actions should the administrator take? (Choose two.)

Hard
15

An administrator wants to ensure that all traffic from the engineering zone to the server zone is logged, but only when a session is established. Which log setting should be configured in the security rule?

Easy
16

An administrator is designing a security policy for a Palo Alto Networks firewall. The administrator wants to ensure that the policy is efficient and follows best practices for rule evaluation. Which two actions should the administrator take? (Choose two.)

Hard
17

A firewall administrator is troubleshooting a situation where traffic from the 'Engineering' zone (source zone) to the 'Servers' zone (destination zone) is being allowed, but the desired behavior is to block it. The administrator runs 'show running security-policy' and sees the following rules in order: Rule1: from Engineering to Servers allow; Rule2: from Engineering to Servers deny; Rule3: from any to Servers allow. Which TWO statements are true regarding policy evaluation?

Hard
18

A security administrator is troubleshooting a rule that appears to be matching correctly but is not allowing traffic. The rule uses source zone 'Trust' and destination zone 'Untrust', and the action is 'allow'. The traffic source is in the 'DMZ' zone. What is the most likely reason the traffic is denied?

Medium
19

An administrator is troubleshooting why a security rule is not being hit. The rule is for traffic from the 'Trust' zone to the 'Untrust' zone, source address 10.1.1.0/24, destination address any, application 'web-browsing', service 'application-default', action allow. The traffic in question is from 10.1.1.5 to 8.8.8.8 on port 80. The administrator checks the traffic logs and sees that the session is being denied by the interzone default rule. What is the most likely cause?

Hard
20

An administrator wants to ensure that a security policy rule is only active during business hours (9 AM to 5 PM) on weekdays. Which configuration element should be used?

Easy
21

A security administrator is reviewing the rulebase and notices that a rule allowing traffic from the 'Trust' zone to the 'Untrust' zone has the action set to 'Allow' but is not being hit. The administrator confirms that there is traffic matching the source and destination zones, addresses, and applications. What is the most likely reason the rule is not being hit?

Hard
22

A network security administrator needs to create a rule that allows DNS traffic from the Trust zone to the Untrust zone. Which application should be selected in the security rule to allow DNS?

Easy
23

An administrator has configured a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web-browsing and ssl applications. The rule is placed at the top of the rulebase. Users in the Guest zone report that they can access websites but cannot use other applications like SSH or FTP. Which statement explains this behavior?

Hard
24

An administrator is reviewing the security policy on a Palo Alto Networks firewall and notices that a rule allowing web browsing from the Trust zone to the Untrust zone has no application specified. The administrator wants the firewall to permit only web-browsing and ssl while blocking all other applications on ports 80 and 443. What should the administrator do to meet this requirement?

Easy
25

A security administrator is configuring a Palo Alto Networks firewall with a security policy that allows traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only specific users can access certain applications. The administrator creates a rule with source zone Trust, destination zone Untrust, source user 'domain\jdoe', application 'web-browsing', action allow. However, after committing, the user jdoe reports that they cannot access the web. The administrator checks the traffic logs and sees that the traffic is being denied by the implicit rule. What is the most likely cause?

Hard
26

A company wants to block file-sharing applications like BitTorrent, but allow HTTP and HTTPS. Which type of policy is most appropriate to achieve this granular control?

Easy
27

An administrator is configuring a security policy on a Palo Alto Networks firewall. The administrator wants to allow only HTTP and HTTPS traffic from the Trust zone to the Untrust zone, and block all other applications. The administrator creates a rule with source zone Trust, destination zone Untrust, application 'web-browsing' and 'ssl', action allow. However, after committing, users can still access other applications like SSH. What is the most likely explanation?

Easy
28

Which THREE actions can be taken based on hit counts in security rules? (Select three.)

Medium
29

An administrator is reviewing the rulebase and finds a rule with a hit count of 0 over the past 30 days. What action should the administrator consider?

Easy
30

An administrator is troubleshooting why a rule is not being hit. The rule has source zone Trust, destination zone Untrust, source address 10.0.0.0/8, destination address any, application web-browsing, action allow, and log at session end. The traffic is coming from 10.1.1.1 to 1.2.3.4 on port 80, zone Trust to Untrust. The rule count shows zero hits. What could be the issue?

Medium
31

A firewall administrator is reviewing the security policy and notices that a rule allowing traffic from the Trust zone to the DMZ zone is not being hit. The rule is placed after a rule that denies all traffic from Trust to DMZ. What is the most likely explanation?

Medium
32

A security administrator is configuring a security policy rule to allow access to a web server from the internet. The rule is set to allow HTTP and HTTPS traffic to the server's public IP address. However, after committing the change, users report that they cannot access the web server from the internet. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit rule. What is the most likely cause of the issue?

Hard
33

An administrator configures a security policy with three rules in order: Rule1 allows any to any with log at session start, Rule2 allows HTTP from trust to untrust, Rule3 denies any. Traffic from an internal user to an external web server is logged as allowed. Which rule processed the traffic?

Hard
34

Which TWO methods can be used to help prevent rule shadowing? (Select two.)

Easy
35

A firewall administrator is tasked with implementing a policy that allows SSH access from the 'Admin' zone to the 'Core' zone only for specific administrators, and all other SSH attempts should be logged and dropped. The company has a large number of administrators. Which method is most efficient and scalable?

Hard
36

A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?

Medium
37

An administrator is auditing the security policy on a PA-3220 firewall. The administrator notices that a rule allowing RDP from the 'Trust' zone to the 'DMZ' zone has a source user of 'domain\jdoe' and is positioned below a broader rule that allows any application from Trust to DMZ for any user. The administrator wants the user-specific rule to be evaluated first. What is the most efficient way to achieve this?

Medium
38

A network administrator adds a new security rule allowing HTTP from the Trust zone to the Untrust zone. After committing, traffic from the Trust zone to the Untrust zone is still blocked. What is the most likely cause?

Easy
39

An administrator is designing a security policy for a new branch office. The policy must allow outbound web traffic from the Trust zone to the Untrust zone, but only for specific users in the 'Marketing' group. The firewall is integrated with Active Directory. Which TWO configurations are required to enforce this policy? (Choose two.)

Hard
40

A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?

Easy
41

A security administrator is configuring a policy to allow access from the Guest zone to the Internet zone. The administrator wants to ensure that only HTTP and HTTPS traffic is allowed, and all other traffic is blocked. The administrator creates a rule with source zone Guest, destination zone Internet, application web-browsing and ssl, and action Allow. However, users report that they cannot access websites. What is the most likely cause?

Medium
42

A small business has a Palo Alto Networks firewall with a single security policy rule that allows all traffic from the 'Trust' zone to the 'Untrust' zone. The business recently experienced a malware infection originating from an internal host that communicated with known malicious IP addresses. The administrator wants to implement a security policy to block traffic to these malicious IP destinations. The administrator has a list of 500 malicious IP addresses that may change frequently. What is the most efficient way to create a policy to block traffic to these IPs?

Easy
43

A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?

Easy
44

After a policy change, a security administrator commits the candidate configuration, but the changes do not take effect immediately for all users. Some users report connectivity issues while others do not. What should the administrator check first?

Hard
45

A security administrator is configuring a rule to allow access to a web server. The rule uses a URL category as the destination. The administrator notices that the rule is not matching traffic to the web server's IP address when users connect directly via IP. What is the most likely reason?

Medium
46

A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?

Medium
47

A firewall administrator is reviewing the security policy and notices that a rule allowing DNS from the Trust zone to the Untrust zone has a hit count of zero. The administrator confirms that DNS traffic is being generated and that the rule is enabled. Which action should the administrator take to troubleshoot why the rule is not being hit?

Medium
48

An administrator is creating a new security rule at the top of the rulebase to allow specific web traffic. After committing, users report that all web traffic is now blocked, including traffic that was previously allowed by a lower rule. The new rule's action is set to 'Deny' and its source and destination are set to 'any'. What is the most likely cause?

Medium
49

A network administrator notices that traffic from a specific subnet is being denied even though there is a permit rule that matches the source and destination. The rulebase has over 500 rules. What is the most likely cause?

Medium
50

A security administrator is troubleshooting why a security rule that allows traffic from the 'Trust' zone to the 'DMZ' zone is not being matched. The administrator confirms that the source IP, destination IP, and application are correct. The rule is placed at the top of the rulebase. What is the most likely reason the rule is not being hit?

Hard
51

A company is migrating from a legacy firewall to a Palo Alto Networks firewall. The legacy policy has many rules with overlapping source and destination objects. Which feature should the administrator use to simplify the policy before migration?

Medium
52

An administrator has created a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web browsing. Users in the Guest zone report that they can access some websites but not others. The administrator checks the traffic logs and sees that some sessions are being denied by the implicit deny rule. What is the most likely reason?

Medium
53

Refer to the exhibit. An administrator is analyzing the rulebase. Traffic from source 10.1.1.5 to destination 8.8.8.8 using web-browsing application (HTTP TCP/80). Which rule will match?

Medium
54

A network engineer needs to ensure that all traffic from the 'Guest' zone to the 'Internet' zone is inspected for malware, but also wants to allow high-bandwidth video conferencing traffic to bypass threat inspection for performance reasons. Which approach best achieves this?

Hard
55

A network security administrator is reviewing the security policy on a Palo Alto Networks firewall. The administrator wants to ensure that traffic from the Trust zone to the Untrust zone is inspected by a specific security profile group. Which policy component should the administrator configure to attach the security profile group?

Easy
56

An administrator has configured a security rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for specific applications. The rule is placed at position 5 in the rulebase. A user reports that traffic matching this rule is being denied. Upon inspection, the administrator finds that a rule at position 3 denies all traffic from 'Trust' to 'Untrust' for any application. What is the most likely cause of the denial?

Medium
57

An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?

Easy
58

A network security administrator at a university wants to allow students in the 'Student' zone to access the internet, but only during exam periods should they be blocked from social media. The administrator creates a security rule at the top of the rulebase that denies social media applications from the Student zone to the Internet zone and schedules it to be active only during exam weeks using a schedule object. Which statement correctly describes the evaluation of this rule?

Medium
59

An administrator has configured a security policy with a rule that allows traffic from the 'Guest' zone to the 'Internet' zone. The rule uses the application 'web-browsing' and 'ssl' with service 'application-default'. Users in the Guest zone report that they cannot access a specific website that uses a non-standard port for HTTPS (port 8443). What is the most likely cause of the issue?

Hard
60

An administrator needs to allow a specific set of external IP addresses to access an internal web server on port 443, but all other traffic to that server must be blocked. The administrator creates a security policy rule that allows the specific IP addresses and places it at the bottom of the rulebase. What will be the result?

Medium
61

Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)

Hard
62

A company has a Palo Alto Networks firewall with multiple virtual routers. The security policy has a rule that allows SSH from the 'Internal' zone to the 'DMZ' zone. Recently, a new subnet 10.10.20.0/24 was added to the Internal zone. Users in that subnet report they cannot SSH to a server at 192.168.1.10 in the DMZ, while users from other subnets in Internal can. The rule has source address object '10.0.0.0/8' which includes the new subnet. The rule's source zone is Internal, destination zone is DMZ, and application is SSH. The administrator confirms the new subnet's IPs are within 10.0.0.0/8. What is the most likely cause of the problem?

Hard
63

A security administrator is reviewing the security policy on a PA-220 firewall. The administrator notices that a rule allowing DNS from the 'Trust' zone to the 'Untrust' zone is being shadowed by a rule above it that denies all traffic from 'Trust' to 'Untrust'. What is the term for this situation?

Easy
64

A security administrator is configuring a rule to allow access to a web application hosted on multiple servers with changing IP addresses. The administrator wants to ensure the rule automatically updates as the IP addresses change, without manual intervention. Which feature should be used?

Hard
65

An administrator is configuring a security rule that allows access from the Trust zone to the DMZ zone for a specific application. The administrator wants to ensure that the rule only allows the application on its default port and blocks the application if it attempts to use a non-standard port. Which setting should be used in the Service column of the security rule?

Hard

Frequently asked questions

What does the Policy Evaluation and Management domain cover on the PCNSA exam?
Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.
How many questions are in this domain?
This page lists all 65 Policy Evaluation and Management questions in the PCNSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Policy Evaluation and Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
paloalto-pcnsa PALOALTO-PCNSA policy evaluation management Practice Questions