Courseiva

CCNA Policy Evaluation and Management Questions

65 questions · Policy Evaluation and Management · All types, answers revealed

1
MCQhard

An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?

A.The application 'web-browsing' is not correctly defined in the application filter.
B.The security rule is placed below the implicit deny rule.
C.The destination zone in the rule is incorrectly set to 'Untrust' instead of 'Trust'.
D.The source user group 'Marketing' is not properly synchronized with the firewall's user-ID agent.
AnswerD

If User-ID is not correctly mapping users to the 'Marketing' group, the firewall cannot match the source user in the rule. The traffic will then fall through to the implicit deny rule. Ensuring the User-ID agent is connected and group mapping is configured is essential for user-based rules to function.

Why this answer

User-based rules require User-ID to map IP addresses to users and groups. If the 'Marketing' group is not synchronized, the firewall cannot match the source user, and the session falls through to the implicit deny. Verifying User-ID agent connectivity and group mapping is the first troubleshooting step for user-based policy failures.

Exam trap

The trap here is overlooking User-ID as a dependency for user-based rules and instead blaming application definitions or rule order.

2
MCQmedium

A company needs to restrict access to a critical server from external IP addresses, but internal users should have full access. Which rule structure should be used?

A.Create a deny rule for external IP addresses, then an allow rule for internal.
B.Place the allow rule after the deny rule.
C.Create an allow rule for internal source addresses, then a deny rule for any source.
D.Create a single rule with a 'Deny' action and apply a user-ID condition.
AnswerC

Security rules evaluate top-down, so placing the internal allow rule first permits trusted users, then the trailing deny rule blocks all remaining external sources. This satisfies the stem's split requirement for internal access and external restriction.

Why this answer

The correct structure is to create an allow rule for internal source addresses first, then a deny rule for any source. Firewalls evaluate rules top-down and stop at the first match, so placing the specific allow rule before the broad deny ensures internal users are permitted while all other traffic, including external IPs, is denied by the subsequent catch-all deny. This implements a whitelist model with an explicit deny-all fallback, which is the recommended security posture.

Exam trap

The trap here is the common misconception that rule order does not matter or that a deny rule can be placed before an allow rule without blocking the intended traffic; candidates forget that firewalls evaluate top-down and stop at the first match.

How to eliminate wrong answers

Option A is wrong because placing the deny rule for external IPs before the allow rule for internal would still work only if the deny rule is specific to external IPs, but the option as stated creates a deny for external then an allow for internal, which does not provide a catch-all deny and leaves other sources potentially allowed. Option B is wrong because placing the allow rule after the deny rule means the deny rule is evaluated first; if the deny rule matches any source, internal traffic would be blocked before reaching the allow rule. Option D is wrong because a single rule with a Deny action and a User-ID condition does not differentiate internal from external sources and would deny all users matching that condition, including internal users, and User-ID is not a source-IP-based control.

3
MCQhard

An administrator is troubleshooting why a security rule that allows traffic from the Trust zone to the DMZ zone is not being hit. The administrator confirms that the source IP, destination IP, and application are correct. Which factor should the administrator check next to determine why the rule is being bypassed?

A.Whether the rule is placed below a more general rule that also matches the traffic.
B.Whether a NAT rule is translating the destination IP and changing the destination zone before security policy evaluation.
C.Whether the application is identified as a different application due to App-ID signature updates.
D.Whether the security rule has a schedule applied that is currently inactive.
AnswerB

NAT rules are evaluated before security rules, and destination NAT can change the destination zone. If a NAT rule translates the destination IP to an address in a different zone, the security rule's destination zone may no longer match. The administrator should verify NAT rules to ensure the destination zone after NAT matches the security rule's expected zone. This is a common reason for a rule not being hit.

Why this answer

NAT rules are processed before security rules. Destination NAT can change the destination IP and therefore the destination zone. If the translated destination falls into a different zone than the one specified in the security rule, the rule will not match.

The administrator should examine the NAT policy to see if a rule is altering the destination zone. This is a frequent cause of unexpected rule bypass in Palo Alto Networks firewalls.

Exam trap

The trap here is forgetting that NAT is evaluated before security policy and can change the zone used for security rule matching.

4
Multi-Selectmedium

Which TWO are best practices for managing security policies in a Palo Alto Networks firewall?

Select 2 answers
A.Enable logging on all rules for maximum visibility.
B.Place most specific rules at the top of the rulebase.
C.Use a single 'allow all' rule to simplify management.
D.Regularly review and remove unused rules using hit counts.
E.Disable unused rules instead of removing them.
AnswersB, D

Palo Alto Networks evaluates rules top-down and stops at the first match, so a broad rule placed above a narrow one shadows it. Ordering most specific rules first ensures targeted permits or denies actually take effect before general rules intercept the traffic.

Why this answer

Option B is correct because Palo Alto Networks evaluates security rules top-down and stops at the first match, so placing the most specific rules above broader ones ensures precise traffic handling and prevents a general rule from shadowing a narrower one. Option D is correct because the firewall tracks hit counts per rule, and periodically reviewing those counters to identify and delete rules with zero hits reduces rulebase bloat and shrinks the attack surface. Option A is not a best practice since logging every rule, including high-volume allow rules, generates excessive log traffic and storage overhead; logging should be targeted to security-relevant events.

Option C is wrong because a single 'allow all' rule defeats the purpose of a least-privilege, zone-based policy and provides no visibility or control. Option E is wrong because disabling rather than removing unused rules leaves dead configuration in the rulebase, and proper hygiene calls for deletion after confirming zero hits.

Exam trap

PCNSA often tests the misconception that disabling unused rules is sufficient, but best practice is to remove them after confirming they are no longer needed, and to place specific rules above general ones.

5
MCQhard

An administrator needs to implement a policy where traffic from the 'Sales' zone to the 'Finance' zone is allowed only for the 'ms-office365' application, but traffic from 'Sales' to 'Finance' using any other application must be denied. Which rule design meets this requirement efficiently?

A.Create a rule that denies all traffic from Sales to Finance, and then an application default deny rule that allows ms-office365.
B.Create a rule that allows all traffic from Sales to Finance, then a rule that denies ms-office365.
C.Create a rule that allows ms-office365 from Sales to Finance, and place a deny all rule after it.
D.Create one rule that allows ms-office365 and denies all other traffic from Sales to Finance.
AnswerC

Palo Alto Networks evaluates security rules top-down, so an allow rule matching ms-office365 from Sales to Finance followed by a deny-all rule permits only that application while blocking all other traffic between the zones. This satisfies the requirement with minimal rules.

Why this answer

In Palo Alto firewalls, security rules are either allow or deny, not both. To allow only 'ms-office365' and deny all other traffic from Sales to Finance, you create an allow rule for that application, followed by a deny-all rule for the same source/destination. This ensures efficiency by allowing the specific traffic first, then blocking everything else.

Option A is incorrect as it uses a deny-all first, then tries to allow with an application default deny, which is not a valid concept and would require an explicit allow rule. Option B is incorrect because allowing all traffic and then denying the specific application defeats the purpose. Option D is invalid because a single rule cannot contain both allow and deny actions.

6
MCQeasy

How can an administrator quickly identify which security rules are not being used in order to clean up the rulebase?

A.Use the 'show rulebase' command.
B.Check the commit logs for recent changes.
C.Sort rules by rule number in descending order.
D.Use the Policy Optimizer tool to view rule hit counts.
AnswerD

Policy Optimizer directly satisfies the unused-rule identification requirement by surfacing per-rule hit counts, letting the administrator filter rules with zero matches across the specified timeframe. Unlike App-ID dependency or traffic log inspection, it aggregates match statistics natively within the firewall rulebase view, enabling rapid cleanup decisions without manual correlation.

Why this answer

The Policy Optimizer tool in Palo Alto Networks firewalls provides rule hit counts, allowing administrators to quickly identify which security rules are not being used. Option A, 'show rulebase', displays the rulebase but does not show hit counts. Option B, checking commit logs, reveals recent changes but not usage frequency.

Option C, sorting rules by rule number, does not indicate whether rules are used.

7
MCQhard

An administrator is configuring a security policy on a PA-3260 firewall. The administrator wants to ensure that a rule allowing SSH from the 'Management' zone to the 'Internal' zone is only active during business hours (9 AM to 5 PM) on weekdays. The administrator creates a schedule object named 'BusinessHours' and attaches it to the rule. However, after applying the policy, SSH access is allowed at all times. What is the most likely reason?

A.The schedule object was not applied to the correct rule.
B.The schedule object 'BusinessHours' is not committed to the firewall.
C.The schedule object 'BusinessHours' is defined with the wrong time zone.
D.Another rule above the scheduled rule allows SSH from Management to Internal without a schedule.
AnswerD

If a more general rule above allows SSH without a schedule, it will match first and permit access at all times, rendering the scheduled rule ineffective. This is a common rule order issue. The scheduled rule is shadowed by the broader rule. The administrator must ensure the scheduled rule is above any other rules that might match the same traffic.

Why this answer

In PAN-OS, schedule objects are used to define time-based rules. If a rule with a schedule is placed below another rule that matches the same traffic without a schedule, the first rule will match and allow traffic at all times. The scheduled rule will never be evaluated.

To enforce time-based access, the scheduled rule must be placed above any broader rules that could match the same traffic.

Exam trap

The trap here is assuming that attaching a schedule to a rule is sufficient, without considering rule order and shadowing by a more general rule.

8
MCQeasy

What does a 'shadowed' rule mean in the context of policy evaluation?

A.A rule that is never evaluated because a previous rule with same or broader match already matches the traffic.
B.A rule that is never hit because it is at the bottom of the rulebase.
C.A rule that is disabled.
D.A rule that matches traffic but has no action configured.
AnswerA

Policy evaluation proceeds top-down and stops at the first matching rule. A shadowed rule sits below an earlier rule whose match criteria are identical or broader, so any traffic it could match is already consumed upstream and it never receives evaluation.

Why this answer

A shadowed rule is one that is never evaluated because a previous rule with the same or broader match already matches the traffic. This occurs when a rule is redundant due to an earlier rule covering the same or a superset of conditions. Option B is incorrect because a rule at the bottom is still evaluated if no earlier rule matches.

Option C is incorrect because a disabled rule is not the same as a shadowed rule. Option D is incorrect because a rule without an action would still be evaluated but would likely result in an error or default action, not shadowing.

9
Multi-Selectmedium

An administrator is configuring a security policy rule to allow access to a critical application. The administrator wants to ensure that the rule is only active for users in the 'Finance' group and only during weekdays. Which two configuration elements must be used to achieve this? (Choose two.)

Select 2 answers
A.External Dynamic List
B.User Group
C.Application Filter
D.Security Profile
E.Schedule
AnswersB, E

A User Group (or dynamic user group) can be referenced in the security rule to restrict access to users in the 'Finance' group. This requires User-ID to be configured and mapping users to groups. By specifying the User Group in the rule's Source User field, only users in that group will match the rule. This is necessary to restrict the rule to Finance users.

Why this answer

To restrict a security rule to a specific user group and to weekdays, the administrator must use a User Group in the Source User field and a Schedule in the Schedule field. User Groups require User-ID to be configured. Schedules define the active times.

Other options like Application Filters, External Dynamic Lists, and Security Profiles do not fulfill these specific requirements.

Exam trap

The trap here is confusing User Groups with Application Filters or External Dynamic Lists, which are also used in rules but for different purposes (applications and IP addresses, respectively).

10
Drag & Dropmedium

Drag and drop the steps to configure Active/Passive High Availability on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

HA configuration requires setting up interfaces, mode, priority, peer IP, preemption, and synchronization.

11
MCQhard

A network security administrator is configuring a security policy on a PA-5220 firewall. The administrator wants to allow HTTP and HTTPS traffic from the 'Guest' zone to the 'Internet' zone, but only for specific users in the 'guest-users' group. The administrator creates a rule with source zone 'Guest', destination zone 'Internet', source user 'guest-users', and application 'web-browsing' and 'ssl'. However, when testing, all Guest users can access the Internet, not just those in the group. What is the most likely cause?

A.The application 'ssl' is not a valid application for HTTP and HTTPS traffic.
B.The source user group 'guest-users' does not exist in the local user database.
C.User-ID is not enabled on the firewall, so user-based rules are ignored.
D.The rule is placed below a more general rule that allows all Guest traffic to the Internet.
AnswerD

If a more general rule allowing all Guest traffic exists above the user-specific rule, it will match first, granting access to all users. The user-specific rule would never be evaluated. This is a common misconfiguration. The administrator must ensure the user-specific rule is above any broader rules that might match the same traffic. Rule order is critical in PAN-OS security policy.

Why this answer

In PAN-OS, security rules are evaluated from top to bottom. If a rule that allows all Guest users to the Internet exists above the user-specific rule, it will match first and permit all traffic. The user-specific rule will never be evaluated.

To restrict access to only the 'guest-users' group, the specific rule must be placed above any broader rules that could match the same traffic.

Exam trap

The trap here is focusing on User-ID or application configuration when the actual issue is rule order allowing a broader rule to take precedence.

12
MCQhard

Refer to the exhibit. The administrator sees that traffic from 10.10.1.12 is being denied by rule2. Which action should the administrator take to allow this traffic while maintaining security?

A.Add 10.10.1.12 to rule1's source address.
B.Change rule2 to allow.
C.Create a new rule above rule2 that allows the specific traffic with appropriate security profiles.
D.Move rule2 above rule1.
AnswerC

Placing a new rule above rule2 lets the firewall match 10.10.1.12's traffic before the deny rule evaluates it, since PAN-OS processes rules top-down and stops at the first match. Attaching security profiles to that rule preserves inspection, satisfying the requirement to allow the traffic while maintaining security.

Why this answer

Creating a new rule above rule2 that specifically allows traffic from 10.10.1.12 with appropriate security profiles will permit the desired traffic without affecting other rules. Rule order matters in Palo Alto firewalls; a rule placed higher in the list is evaluated first. Option A would broaden rule1's source, potentially allowing unintended traffic.

Option B would change rule2 to allow, which could permit traffic that should still be denied. Option D would move rule2 above rule1, but since rule2 is a deny rule, the traffic would still be denied. Thus, adding a new allow rule above the deny rule is the best approach.

13
MCQmedium

An administrator is reviewing the security policy and notices a rule that allows all traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only web browsing (HTTP and HTTPS) is allowed, while all other traffic is blocked. What should the administrator do?

A.Create a new rule to deny all traffic from Trust to Untrust, and place it above the existing allow rule.
B.Modify the existing rule to allow only the 'web-browsing' and 'ssl' applications, and add a deny rule below for all other traffic.
C.Leave the rule as is and create a new rule to deny all non-web traffic, placing it below the allow rule.
D.Modify the existing rule to allow only the 'web-browsing' and 'ssl' applications, and ensure the rule is placed above any other permissive rules.
AnswerD

The best practice is to modify the existing rule to allow only the specific applications (web-browsing and ssl) and ensure it is placed correctly in the rulebase. The implicit deny will block all other traffic. Placing it above other permissive rules ensures it is evaluated first. This achieves the goal without unnecessary deny rules.

Why this answer

To restrict traffic to only HTTP and HTTPS, the existing permissive rule should be modified to allow only the 'web-browsing' and 'ssl' applications. The implicit deny at the bottom will block all other traffic. It is also important to ensure the rule is positioned correctly in the rulebase, above any other rules that might allow broader traffic.

Creating unnecessary deny rules is not best practice.

Exam trap

The trap here is thinking that adding a deny rule below an allow-all rule will restrict traffic, when in fact the allow-all rule above will match all traffic first, making the deny rule ineffective.

14
Multi-Selecthard

An administrator is configuring a security policy to allow access to a critical application. The application uses multiple protocols and dynamic ports. The administrator wants to ensure that the policy is as secure as possible while allowing legitimate traffic. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Set the security rule to allow the application based on the destination port only, as dynamic ports are not supported by App-ID.
B.Use App-ID to identify the application and allow only the specific application, rather than allowing the underlying ports.
C.Allow all TCP and UDP ports from the source zone to the destination zone to ensure the application works.
D.Create a custom application signature for the application if it is not recognized by the built-in App-ID database.
E.Disable application inspection for the traffic to improve performance, since the application uses dynamic ports.
AnswersB, D

Using App-ID allows the firewall to identify the application regardless of port or protocol, and to enforce policy based on the actual application. This is more secure than allowing ports because it prevents other applications from using the same ports. It also handles dynamic ports automatically, as App-ID tracks the application's behavior.

Why this answer

To securely allow an application with dynamic ports, the administrator should use App-ID to identify the application and create a custom signature if needed. These actions ensure that only the specific application is allowed, regardless of port, while maintaining security. Allowing all ports or disabling inspection would weaken security and are not recommended.

Exam trap

The trap here is thinking that dynamic ports require opening all ports or disabling inspection, when App-ID can handle them securely.

15
MCQeasy

An administrator wants to ensure that all traffic from the engineering zone to the server zone is logged, but only when a session is established. Which log setting should be configured in the security rule?

A.Log at both session start and end
B.No log
C.Log at session end
D.Log at session start
AnswerD

Logging at session start records only the first packet that establishes a session, satisfying the requirement to log solely when a session is established. Session-end logging would capture teardown instead, and logging at both start and end would duplicate entries, breaching the "only when established" constraint.

Why this answer

In Palo Alto Networks security rules, the Log at Session Start option generates a log entry when the session is first established, which satisfies the requirement to log only when a session is established. This captures the connection initiation without logging at session end.

Exam trap

PCNSA often tests the precise semantics of log settings — candidates assume 'log at session end' captures establishment, but only 'log at session start' logs when the session is established.

How to eliminate wrong answers

Option A is wrong because logging at both start and end produces two log entries per session, exceeding the requirement to log only when a session is established. Option B is wrong because no log means no visibility, failing the logging requirement entirely. Option C is wrong because logging at session end records the session only when it terminates, not when it is established — and sessions may be long-lived or never close cleanly.

16
Multi-Selecthard

An administrator is designing a security policy for a Palo Alto Networks firewall. The administrator wants to ensure that the policy is efficient and follows best practices for rule evaluation. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Use any as the source and destination in rules to simplify policy management.
B.Enable logging at the end of the session for rules that allow critical traffic.
C.Place rules with more specific source and destination addresses above rules with broader address ranges.
D.Place a deny all rule at the top of the rulebase to block unwanted traffic immediately.
E.Use application filters instead of specific applications to reduce the number of rules.
AnswersB, C

Enabling logging at session end for critical allow rules provides visibility into allowed traffic, including source, destination, application, and bytes. This is essential for auditing, troubleshooting, and detecting anomalies. While logging at session start can be useful for long-lived sessions, session-end logging captures the full session details and is a common best practice for critical rules.

Why this answer

Ordering rules from specific to general ensures that intended traffic matches the correct rule before a broader rule can apply. Logging at session end for critical allow rules provides necessary visibility. Using any in source/destination or placing a deny all at the top would create security gaps or block legitimate traffic.

Application filters may be too broad for precise control. These two practices support an efficient and secure rulebase.

Exam trap

The trap here is assuming that a deny all rule at the top is a good security practice, when it actually blocks all traffic and makes other rules unreachable.

17
Multi-Selecthard

A firewall administrator is troubleshooting a situation where traffic from the 'Engineering' zone (source zone) to the 'Servers' zone (destination zone) is being allowed, but the desired behavior is to block it. The administrator runs 'show running security-policy' and sees the following rules in order: Rule1: from Engineering to Servers allow; Rule2: from Engineering to Servers deny; Rule3: from any to Servers allow. Which TWO statements are true regarding policy evaluation?

Select 2 answers
A.The traffic will be allowed because Rule1 matches before Rule2.
B.To block the traffic, you can set the source zone in Rule2 to 'Negate' Engineering.
C.Moving Rule2 to the end of the rulebase will ensure it blocks the traffic.
D.The administrator should move Rule2 above Rule1 to block the traffic.
E.The firewall evaluates all rules and applies the most restrictive action (deny).
AnswersA, D

First-match logic: Rule1 matches first, so the action is allow; Rule2 is not evaluated.

Why this answer

Palo Alto Networks firewalls use first-match policy evaluation: the first rule that matches the traffic's source zone, destination zone, source/destination IP, application, and user determines the action. Since Rule1 (allow) appears before Rule2 (deny), traffic from Engineering to Servers matches Rule1 first and is allowed, regardless of later deny rules.

Exam trap

The trap here is that candidates often assume firewalls use a 'most restrictive wins' model (like some ACL implementations) rather than the first-match model used by Palo Alto Networks, leading them to incorrectly select Option E.

18
MCQmedium

A security administrator is troubleshooting a rule that appears to be matching correctly but is not allowing traffic. The rule uses source zone 'Trust' and destination zone 'Untrust', and the action is 'allow'. The traffic source is in the 'DMZ' zone. What is the most likely reason the traffic is denied?

A.Security profiles are blocking the traffic.
B.The application is not identified.
C.The source zone of the rule does not match the traffic's ingress zone.
D.The rule is placed after a deny rule.
AnswerC

Security policy evaluates the source zone against the traffic's ingress zone, which is DMZ here, not Trust. Because the rule specifies Trust as its source zone, it never matches this session, so the implicit interzone default deny drops the traffic despite the allow action.

Why this answer

The rule is configured with source zone 'Trust', but the traffic originates from the 'DMZ' zone. Since zones must match for a rule to apply, the rule does not match the traffic, so it is denied by the implicit deny rule. Options A, B, and D are incorrect: Security profiles (A) only apply after a rule matches; application identification (B) is not related to zone mismatch; and rule order (D) is irrelevant because the rule does not match due to zone mismatch.

19
MCQhard

An administrator is troubleshooting why a security rule is not being hit. The rule is for traffic from the 'Trust' zone to the 'Untrust' zone, source address 10.1.1.0/24, destination address any, application 'web-browsing', service 'application-default', action allow. The traffic in question is from 10.1.1.5 to 8.8.8.8 on port 80. The administrator checks the traffic logs and sees that the session is being denied by the interzone default rule. What is the most likely cause?

A.The zone assigned to the ingress interface for the traffic is not 'Trust'.
B.The rule is disabled.
C.The source address in the rule does not match the actual source IP of the traffic.
D.The application 'web-browsing' is not matching because the traffic is actually HTTPS on port 80.
AnswerA

If the interface receiving the traffic is not assigned to the 'Trust' zone, the source zone in the rule will not match. The traffic log would show the actual zone, which might be different. The rule would not be hit, and the interzone default rule would deny it. This is a common misconfiguration when interfaces are not properly zoned.

Why this answer

The traffic is denied by the interzone default rule, meaning the custom rule was not matched. The most likely cause is that the ingress interface is not assigned to the 'Trust' zone. The source zone in the rule must match the zone of the incoming interface.

If the interface is in a different zone, the rule will not be evaluated. Checking the zone configuration on the interface would resolve this.

Exam trap

The trap here is focusing on the source address or application, but the denial by the interzone default rule points to a zone mismatch, which is a common oversight.

20
MCQeasy

An administrator wants to ensure that a security policy rule is only active during business hours (9 AM to 5 PM) on weekdays. Which configuration element should be used?

A.Application Filters
B.Schedule
C.External Dynamic Lists
D.Security Profiles
AnswerB

A Schedule object defines specific time ranges and days of the week. When attached to a security rule, the rule is only active during those times. This allows administrators to enforce policies only during business hours. The Schedule object is the correct configuration element to achieve time-based rule activation.

Why this answer

To activate a security rule only during specific times, a Schedule object must be created and attached to the rule. Schedules define time ranges and days of the week. Security Profiles, Application Filters, and External Dynamic Lists serve different purposes and do not control rule activation timing.

Exam trap

The trap here is confusing Schedule with other policy objects like Security Profiles, which are also configured within a rule but serve a different purpose.

21
MCQhard

A security administrator is reviewing the rulebase and notices that a rule allowing traffic from the 'Trust' zone to the 'Untrust' zone has the action set to 'Allow' but is not being hit. The administrator confirms that there is traffic matching the source and destination zones, addresses, and applications. What is the most likely reason the rule is not being hit?

A.The rule is not being hit because the application is not recognized by App-ID and is being denied by the implicit deny rule.
B.A rule above it with a broader match is already allowing the traffic, so the lower rule is never evaluated.
C.The rule is not being hit because the security policy is not committed.
D.The rule is not being hit because the source and destination addresses are incorrect.
AnswerB

Security rules are evaluated top-down. If a rule above the one in question matches the traffic, that rule's action is taken and the lower rule is not evaluated. The administrator should check for any rule above that might be matching the same traffic, possibly with broader match criteria. This is a common cause of a rule not being hit.

Why this answer

A rule is not hit if a rule above it matches the traffic first. The administrator should examine the rules above the one in question to see if any of them match the same traffic. This is the most common reason for a rule not being hit when its criteria seem correct.

Exam trap

The trap here is focusing on the rule itself rather than the rules above it, when rule order is the most likely cause of a rule not being hit.

22
MCQeasy

A network security administrator needs to create a rule that allows DNS traffic from the Trust zone to the Untrust zone. Which application should be selected in the security rule to allow DNS?

A.ssl
B.ping
C.dns
D.web-browsing
AnswerC

The 'dns' application in PAN-OS is specifically designed to identify and allow DNS traffic. When selected in a security rule, it permits DNS queries and responses over UDP and TCP port 53. This is the correct application to use for allowing DNS traffic from the Trust zone to the Untrust zone, ensuring that name resolution functions properly.

Why this answer

The correct application to allow DNS traffic is 'dns'. This application is predefined in PAN-OS and matches DNS queries and responses on port 53. Selecting it in a security rule ensures that DNS traffic from Trust to Untrust is permitted, allowing clients to resolve domain names.

Exam trap

The trap here is confusing the DNS application with other common applications like web-browsing or ssl, which do not cover DNS traffic.

23
MCQhard

An administrator has configured a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web-browsing and ssl applications. The rule is placed at the top of the rulebase. Users in the Guest zone report that they can access websites but cannot use other applications like SSH or FTP. Which statement explains this behavior?

A.The rule is at the top, so it allows all traffic, but the applications are not properly defined.
B.The rule is missing a security profile, which is required to allow non-web applications.
C.The rule allows only web-browsing and ssl, so other applications are implicitly denied by the default deny rule at the bottom.
D.The firewall is configured to block SSH and FTP by default, regardless of rule configuration.
AnswerC

The security rule explicitly allows only web-browsing and ssl applications. Any traffic that does not match these applications will continue down the rulebase and eventually hit the default deny rule (interzone-default or intrazone-default), which denies all traffic not explicitly allowed. Therefore, SSH and FTP are denied.

Why this answer

The security rule only allows web-browsing and ssl applications. Traffic for SSH and FTP does not match this rule and is therefore evaluated against subsequent rules. Since there is no explicit allow rule for those applications, they are denied by the default deny rule at the bottom of the rulebase.

This is the expected behavior of a default-deny security policy.

Exam trap

The trap here is thinking that a rule at the top allows all traffic, but the rule's application match criteria restrict it to only the specified applications.

24
MCQeasy

An administrator is reviewing the security policy on a Palo Alto Networks firewall and notices that a rule allowing web browsing from the Trust zone to the Untrust zone has no application specified. The administrator wants the firewall to permit only web-browsing and ssl while blocking all other applications on ports 80 and 443. What should the administrator do to meet this requirement?

A.Add the applications web-browsing and ssl to the rule and set the action to Allow.
B.Enable the 'Log at Session Start' option and monitor which applications are in use.
C.Create a new rule below the existing rule that denies any application on ports 80 and 443.
D.Change the service to application-default and remove any application specification.
AnswerA

Specifying web-browsing and ssl in the Application column makes the rule match only those applications, so App-ID identifies the actual application regardless of port. Traffic that is not one of these applications will not match this rule and will fall through to subsequent rules or the default deny, effectively blocking all other applications on ports 80 and 443.

Why this answer

The Application column in a security rule determines which applications are allowed. By specifying web-browsing and ssl, the rule only permits those applications, and all other applications on ports 80 and 443 will not match and will be denied by subsequent rules or the default deny. This is the correct way to restrict traffic to specific applications.

Exam trap

The trap here is assuming that a rule without an application specified will automatically allow only common web applications, when in fact it allows all applications on the specified ports.

25
MCQhard

A security administrator is configuring a Palo Alto Networks firewall with a security policy that allows traffic from the Trust zone to the Untrust zone. The administrator wants to ensure that only specific users can access certain applications. The administrator creates a rule with source zone Trust, destination zone Untrust, source user 'domain\jdoe', application 'web-browsing', action allow. However, after committing, the user jdoe reports that they cannot access the web. The administrator checks the traffic logs and sees that the traffic is being denied by the implicit rule. What is the most likely cause?

A.The user 'domain\jdoe' is not in the local user database of the firewall.
B.The security rule is placed below a rule that denies all traffic from Trust to Untrust.
C.The application 'web-browsing' is not allowed for the user 'domain\jdoe' because of an application override.
D.User-ID is not enabled on the Trust zone, so the firewall cannot map the source IP to the user.
AnswerD

For a security rule that includes a source user, the firewall must be able to map the source IP address to a username using User-ID. If User-ID is not enabled on the zone where the user's traffic originates (Trust zone), the firewall cannot identify the user, and the rule will not match. This causes the traffic to fall through to the implicit deny. Enabling User-ID on the Trust zone is required for user-based rules to work.

Why this answer

The most likely cause is that User-ID is not enabled on the Trust zone. For a security rule with a source user criterion to match, the firewall must map the source IP to a username. If User-ID is not enabled on the zone, the mapping does not occur, and the rule is skipped.

The traffic then hits the implicit deny. The administrator should enable User-ID on the Trust zone and ensure the user mapping is working.

Exam trap

The trap here is assuming that simply referencing a username in a rule is enough, but User-ID must be enabled on the source zone to map IP addresses to users.

26
MCQeasy

A company wants to block file-sharing applications like BitTorrent, but allow HTTP and HTTPS. Which type of policy is most appropriate to achieve this granular control?

A.Security policy with application-ID.
B.Decryption policy.
C.Security policy with service only.
D.Policy-based forwarding.
AnswerA

A Security policy with application-ID identifies BitTorrent by its application signatures regardless of port or protocol, then blocks it, while separate rules permit HTTP and HTTPS. Port-based rules alone cannot distinguish file-sharing traffic from web traffic.

Why this answer

Application-ID allows granular control over applications, not just ports. Option B is a decryption policy and does not control application access. Option C is a security policy with service only, which restricts based on port/protocol, not application.

Option D is policy-based forwarding, used for path selection, not for blocking applications.

27
MCQeasy

An administrator is configuring a security policy on a Palo Alto Networks firewall. The administrator wants to allow only HTTP and HTTPS traffic from the Trust zone to the Untrust zone, and block all other applications. The administrator creates a rule with source zone Trust, destination zone Untrust, application 'web-browsing' and 'ssl', action allow. However, after committing, users can still access other applications like SSH. What is the most likely explanation?

A.The rule's application field is set to 'any' instead of the specific applications.
B.The firewall is not licensed for App-ID, so it cannot enforce application-based rules.
C.There is another rule above this rule that allows all applications from Trust to Untrust.
D.The security rule is not committed, so the old rules are still in effect.
AnswerC

Security rules are evaluated top-down. If there is a rule above the newly created rule that allows all applications (or specifically SSH) from Trust to Untrust, that rule will be matched first, and the new rule will not be evaluated. This is a common cause of unexpected allowed traffic. The administrator should review the rulebase for overlapping rules above the intended rule.

Why this answer

The most likely explanation is that there is another rule above the newly created rule that allows all applications or specifically SSH from Trust to Untrust. Because rules are evaluated top-down, the first matching rule is applied. The administrator should check the rule order and ensure the new rule is placed above any broader allow rules.

Exam trap

The trap here is assuming that a rule allowing only specific applications will block all others, but an earlier rule allowing all applications will take precedence.

28
Multi-Selectmedium

Which THREE actions can be taken based on hit counts in security rules? (Select three.)

Select 3 answers
A.Identify unused rules for cleanup
B.Create dynamic updates to rules
C.Prioritize rule optimization efforts
D.Troubleshoot traffic mis-matches
E.Determine rule shadowing
AnswersA, C, D

Hit counts expose rules matching no traffic, so unused rules can be identified for cleanup. This satisfies the scenario's requirement to act on hit count data by removing redundant policy, reducing rulebase bloat and administrative overhead without affecting legitimate traffic flows.

Why this answer

Hit counts record how many times each security rule has matched traffic, so option A is correct because rules showing zero or near-zero hits over a long period are strong candidates for removal during rule cleanup. Option C is correct because hit counts reveal which rules are heavily used versus rarely used, letting administrators focus optimization and consolidation efforts on the rules that matter most. Option D is correct because comparing expected traffic against actual hit counts helps diagnose why traffic is or is not matching a given rule, exposing mis-ordered or mis-scoped rules.

Option B is not correct because hit counts are observational statistics and do not themselves trigger or generate dynamic rule updates. Option E is not correct because shadowing is determined by analyzing rule order and overlapping match criteria, not by hit-count values alone.

Exam trap

The trap is selecting 'determine rule shadowing' because zero-hit rules seem related to shadowing, but hit counts alone cannot distinguish a shadowed rule from a simply unused one — shadowing requires rule-order analysis.

29
MCQeasy

An administrator is reviewing the rulebase and finds a rule with a hit count of 0 over the past 30 days. What action should the administrator consider?

A.Move the rule higher in the rulebase.
B.Consider removing the rule as it is not being used.
C.Increase the log setting to capture more data.
D.Disable the rule to see if any traffic matches.
AnswerB

A hit count of zero across 30 days indicates the rule matches no traffic, so it contributes nothing while enlarging the rulebase and its audit surface. Removing it satisfies the stem's implied goal of rulebase hygiene, though the administrator should first confirm no dependent rules or expected seasonal traffic exist.

Why this answer

A rule with a hit count of 0 over 30 days indicates no traffic has matched it, meaning it is likely obsolete, redundant, or misconfigured. Removing unused rules reduces the attack surface and simplifies the rulebase, which is a recommended hygiene practice in Palo Alto Networks best-practice assessments.

Exam trap

The trap is thinking that a zero hit count means the rule is broken or needs to be moved — the exam tests whether you recognize that zero hits over a long period indicates the rule is unused and should be removed, not repositioned.

How to eliminate wrong answers

Option A is wrong because moving the rule higher would not change its hit count — if no traffic matches it at its current position, moving it up could actually cause it to shadow other rules and change behavior unexpectedly. Option C is wrong because increasing logging does not make traffic match the rule; it only captures more detail if traffic does match. Option D is wrong because disabling the rule is a temporary diagnostic step, but the question asks what the administrator should consider given 30 days of zero hits — removal is the appropriate action, not indefinite disabling.

30
MCQmedium

An administrator is troubleshooting why a rule is not being hit. The rule has source zone Trust, destination zone Untrust, source address 10.0.0.0/8, destination address any, application web-browsing, action allow, and log at session end. The traffic is coming from 10.1.1.1 to 1.2.3.4 on port 80, zone Trust to Untrust. The rule count shows zero hits. What could be the issue?

A.The application must be set to 'any'.
B.The application is incorrectly identified; perhaps the traffic is using a different app.
C.The log setting is preventing hits.
D.The destination address is too broad.
AnswerB

Zero hits with matching zones, addresses and port usually means App-ID resolved the session to a different application than web-browsing, so the rule never matches. SSL, proxy or non-standard behaviour can cause this misidentification, requiring the application to be corrected or the rule broadened.

Why this answer

The rule specifies application 'web-browsing', but the traffic may be classified as a different application (e.g., 'ssl' or 'http-proxy'), causing a mismatch. Even though the traffic uses port 80, the firewall identifies applications by signature, not just port. Option A is not necessary; the application does not need to be 'any' to match.

Option C is false; the log setting does not affect whether the rule is hit. Option D is incorrect; a broad destination address (any) is not an issue.

31
MCQmedium

A firewall administrator is reviewing the security policy and notices that a rule allowing traffic from the Trust zone to the DMZ zone is not being hit. The rule is placed after a rule that denies all traffic from Trust to DMZ. What is the most likely explanation?

A.The deny rule is more specific and therefore takes precedence.
B.The allow rule requires a URL filtering profile to be hit.
C.The allow rule is shadowed by the deny rule above it.
D.The deny rule has a higher priority due to its action.
AnswerC

In PAN-OS, security rules are evaluated from top to bottom. If a deny rule is placed above an allow rule and matches the same traffic, the deny rule will be hit first, and the allow rule will never be evaluated. This is known as shadowing. The allow rule is effectively useless because the deny rule above it blocks all matching traffic before it can be reached.

Why this answer

Security rules in PAN-OS are evaluated in top-down order. If a deny rule is placed above an allow rule and both match the same traffic, the deny rule will be hit first, preventing the allow rule from ever being evaluated. This is called shadowing, and the allow rule is effectively disabled.

Exam trap

The trap here is thinking that rule specificity or action determines priority, when in fact only the order of rules matters.

32
MCQhard

A security administrator is configuring a security policy rule to allow access to a web server from the internet. The rule is set to allow HTTP and HTTPS traffic to the server's public IP address. However, after committing the change, users report that they cannot access the web server from the internet. The administrator checks the traffic logs and sees that the traffic is being denied by an implicit rule. What is the most likely cause of the issue?

A.The security rule is placed below the intrazone-default rule.
B.The security rule does not have the correct source zone specified.
C.The security rule is placed below the interzone-default rule.
D.The security rule is configured with the wrong destination address.
AnswerB

For traffic from the internet to a web server, the source zone is typically the Untrust zone (or the zone where the internet-facing interface resides). If the source zone is incorrectly set to Trust or any other zone, the rule will not match, and the traffic will be denied by the interzone-default rule. This is a common misconfiguration.

Why this answer

The correct answer is that the source zone is likely incorrect. For inbound traffic from the internet, the source zone should be the Untrust zone (or the zone of the external interface). If the source zone is set to Trust or another internal zone, the rule will not match, and the traffic will be denied by the interzone-default rule.

Exam trap

The trap here is focusing on rule order or destination address when the issue is actually the source zone configuration.

33
MCQhard

An administrator configures a security policy with three rules in order: Rule1 allows any to any with log at session start, Rule2 allows HTTP from trust to untrust, Rule3 denies any. Traffic from an internal user to an external web server is logged as allowed. Which rule processed the traffic?

A.Rule1
B.Rule3
C.Rule2
D.No rule matched
AnswerA

Rule1 sits first and matches any-to-any, so it processes the traffic before Rule2's HTTP-specific match is ever evaluated. Palo Alto firewalls evaluate rules top-down and stop at the first match, and its log-at-session-start setting produces the allowed entry observed.

Why this answer

Rule1 allows any to any with logging at session start, so it matches the traffic first and permits it, generating a log entry. Since Rule1 is evaluated before Rule2 and Rule3, the traffic is processed by Rule1 and never reaches the subsequent rules. The log confirms that the session was allowed, consistent with Rule1's action.

Exam trap

The trap is assuming that the more specific Rule2 would process HTTP traffic, but candidates must remember that firewall rules are evaluated in order and the first match wins, regardless of specificity.

How to eliminate wrong answers

Option B is wrong because Rule3 denies any, but the traffic was allowed, so it could not have been processed by Rule3. Option C is wrong because Rule2 allows HTTP from trust to untrust, but Rule1 already matches all traffic and is evaluated first, so Rule2 is never reached. Option D is wrong because a rule did match (Rule1), as evidenced by the log entry.

34
Multi-Selecteasy

Which TWO methods can be used to help prevent rule shadowing? (Select two.)

Select 2 answers
A.Using rule hit counts
B.Placing more specific rules above general rules
C.Using policy optimizer reports to reorder rules
D.Using dynamic address groups
E.Using rule order analysis tools
AnswersB, C

Correct. This ensures specific rules are evaluated first, reducing the chance they are shadowed.

Why this answer

Placing more specific rules above general rules prevents rule shadowing by ensuring that traffic matching a specific condition is evaluated and permitted or denied by the intended rule before reaching a broader rule that might otherwise match it. In Palo Alto Networks firewalls, rule evaluation is first-match, so a general rule placed above a specific rule will shadow the specific rule, making it unreachable. This ordering principle directly addresses the root cause of shadowing.

Exam trap

The trap here is that candidates often confuse detection tools (like rule order analysis or hit counts) with prevention methods, but the question specifically asks for methods that help prevent shadowing, which requires proactive ordering or reordering of rules.

35
MCQhard

A firewall administrator is tasked with implementing a policy that allows SSH access from the 'Admin' zone to the 'Core' zone only for specific administrators, and all other SSH attempts should be logged and dropped. The company has a large number of administrators. Which method is most efficient and scalable?

A.Create a single rule with source zone 'Admin', destination zone 'Core', application 'ssh', source user 'any', action 'allow' and enable logging.
B.Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', source user set to an LDAP group containing the administrators, action 'allow', and a second rule with same match criteria but action 'drop' and log at end.
C.Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', action 'allow', and rely on the firewall's default deny rule for others.
D.Create a rule with source zone 'Admin', destination zone 'Core', application 'ssh', source address list of all administrators' IPs, action 'allow', and a catch-all drop rule.
AnswerB

User-ID integration allows scalable user-based policies.

Why this answer

It uses an LDAP group as the source user attribute, which allows dynamic membership management without manual IP updates. The first rule permits SSH for the group, and the second rule logs and drops all other SSH attempts, ensuring only authorized administrators are allowed while unauthorized attempts are recorded for auditing. This approach is scalable for a large number of administrators because it leverages user-based policies rather than IP-based rules.

Exam trap

The trap here is that candidates often choose Option A, thinking that logging all SSH attempts is sufficient, but they overlook the requirement to restrict access to specific administrators, which necessitates a user-based filter rather than allowing all users.

How to eliminate wrong answers

Option A is wrong because setting source user to 'any' would allow all users from the Admin zone to access the Core zone via SSH, violating the requirement to restrict access to specific administrators only. Option C is wrong because relying on the default deny rule would silently drop unauthorized SSH attempts without logging them, failing the requirement to log and drop all other SSH attempts. Option D is wrong because using a source address list of all administrators' IPs is not scalable for a large number of administrators, as it requires manual updates whenever an administrator's IP changes or new administrators are added, and it does not leverage user-based identification.

36
MCQmedium

A security administrator is troubleshooting a policy misconfiguration. The firewall is configured with a security rule that allows traffic from the 'Engineering' zone to the 'Servers' zone. However, traffic from an Engineering user to a server in the 'DMZ' zone is being denied. What is the most likely cause?

A.The rule only allows traffic from Engineering to Servers zone, not DMZ.
B.The rule is configured as an intrazone rule.
C.The rule is disabled in the rulebase.
D.SSL decryption is blocking the traffic.
AnswerA

Security rules match on both source and destination zones, so a rule permitting Engineering to Servers does not cover Engineering to DMZ. Traffic destined for the DMZ zone matches no allow rule and hits the default interzone deny, producing the observed denial.

Why this answer

The security rule explicitly permits traffic from the 'Engineering' zone to the 'Servers' zone. Traffic destined to the 'DMZ' zone is a different zone, so the rule does not apply. By default, Palo Alto Networks firewalls enforce a deny-all policy for any traffic that does not match an explicit allow rule, which is why the traffic is denied.

Exam trap

The trap here is that candidates may assume a rule allowing traffic to one zone implicitly covers all zones, but Palo Alto Networks firewalls require explicit zone matching for each rule, and failing to specify the correct destination zone results in a deny.

How to eliminate wrong answers

Option B is wrong because an intrazone rule controls traffic within the same zone, not between different zones; the scenario involves interzone traffic from Engineering to DMZ. Option C is wrong because if the rule were disabled, it would not affect traffic to the Servers zone either, and the question states the rule allows traffic to Servers, implying it is enabled. Option D is wrong because SSL decryption is a separate feature that can inspect encrypted traffic but does not inherently block traffic; it would only affect traffic if a decryption policy explicitly denies or fails to decrypt, and there is no indication of SSL decryption involvement.

37
MCQmedium

An administrator is auditing the security policy on a PA-3220 firewall. The administrator notices that a rule allowing RDP from the 'Trust' zone to the 'DMZ' zone has a source user of 'domain\jdoe' and is positioned below a broader rule that allows any application from Trust to DMZ for any user. The administrator wants the user-specific rule to be evaluated first. What is the most efficient way to achieve this?

A.Create a new rule with the same source user and place it at the bottom of the rulebase.
B.Move the user-specific rule above the broader rule in the security policy.
C.Change the source user on the broader rule to 'any' and rely on application-based matching.
D.Add a negative source user to the broader rule to exclude 'domain\jdoe'.
AnswerB

Security rules are evaluated top-down, and the first matching rule is applied. Placing the user-specific rule above the broader rule ensures it is evaluated first. This is the correct approach because rule order is critical; the broader rule would otherwise match all traffic, including that from the specific user, and the user-specific rule would never be hit. This is a fundamental best practice for policy management.

Why this answer

Security rules are processed in a top-down sequence, and the first rule that matches all criteria (source zone, destination zone, source address, destination address, application, user, etc.) is applied. To ensure a specific rule takes precedence over a more general one, it must be placed above the general rule. Moving the user-specific rule above the broader rule guarantees it is evaluated first, allowing the intended access control.

Exam trap

The trap here is assuming that rule order can be overridden by other means such as user negation or application matching, when in fact rule position is the primary factor in evaluation.

38
MCQeasy

A network administrator adds a new security rule allowing HTTP from the Trust zone to the Untrust zone. After committing, traffic from the Trust zone to the Untrust zone is still blocked. What is the most likely cause?

A.The source zone in the new rule is set to 'Untrust' instead of 'Trust'.
B.The application in the new rule is set to 'ssl' instead of 'http'.
C.The new rule is placed at the bottom of the policy, below an existing deny rule that matches the same traffic.
D.The destination zone in the new rule is set to 'Trust' instead of 'Untrust'.
AnswerC

Palo Alto evaluates rules top-down and stops at the first match. A deny rule above the new permit shadows it, so HTTP from Trust to Untrust never reaches the new rule despite committing successfully. Moving the permit above the deny resolves the block.

Why this answer

Palo Alto Networks security policies are evaluated top-down, and the first rule that matches the traffic is applied. If an existing deny rule that matches HTTP from Trust to Untrust sits above the new allow rule, the deny rule wins and traffic remains blocked. The new rule must be moved above the deny rule (or the deny rule modified) to take effect.

Exam trap

PCNSA often tests policy evaluation order — candidates assume the new rule will take effect because it is more specific, but PAN-OS uses first-match top-down evaluation, so a deny rule above it blocks the traffic.

How to eliminate wrong answers

Option A is wrong because if the source zone were set to Untrust, the rule would not match Trust-to-Untrust traffic at all, but the question states the rule was added for Trust to Untrust — the issue is rule order, not zone misconfiguration. Option B is wrong because if the application were set to ssl instead of http, the rule would not match HTTP traffic, but the scenario says the rule allows HTTP, so the application is correct. Option D is wrong because if the destination zone were Trust instead of Untrust, the rule would not match the intended traffic, but again the question specifies the rule is for Trust to Untrust.

39
Multi-Selecthard

An administrator is designing a security policy for a new branch office. The policy must allow outbound web traffic from the Trust zone to the Untrust zone, but only for specific users in the 'Marketing' group. The firewall is integrated with Active Directory. Which TWO configurations are required to enforce this policy? (Choose two.)

Select 2 answers
A.Create a security rule with source zone Trust, destination zone Untrust, application web-browsing and ssl, and action Allow.
B.Configure a decryption policy to decrypt all outbound web traffic.
C.Enable SSL decryption to identify users in the Marketing group.
D.Create a URL filtering profile that allows only Marketing-related websites.
E.Configure User-ID to map IP addresses to users and add the 'Marketing' group as a source user in the security rule.
AnswersA, E

This rule is necessary to allow web traffic from Trust to Untrust. It must include both web-browsing and ssl applications to cover HTTP and HTTPS. Without this rule, the default deny would block all web traffic. The rule provides the basic allow action, and user-based enforcement will be added via the user field in the rule.

Why this answer

To allow outbound web traffic only for the Marketing group, two things are needed: a security rule that permits web-browsing and ssl from Trust to Untrust, and User-ID configuration to map users to IP addresses so that the Marketing group can be specified as the source user in the rule. Without both, the policy cannot be enforced correctly.

Exam trap

The trap here is assuming that SSL decryption or URL filtering is required for user-based policies, when actually User-ID and a security rule with user group are sufficient.

40
MCQeasy

A user at 192.168.1.10 attempts to access a social networking site (application: social-networking). Based on the exhibit, what will the firewall do?

A.Allow the traffic because rule 1 matches and allows all web traffic.
B.Allow the traffic because rule 3 allows all traffic.
C.Deny the traffic because no rule allows social-networking.
D.Deny the traffic because rule 2 matches and denies social-networking.
AnswerD

Palo Alto Networks evaluates security rules top-down and stops at the first match. Rule 2 matches the source zone, address and social-networking application, and its action is deny, so the firewall blocks the session before any later allow rule is evaluated.

Why this answer

The firewall evaluates rules in order from top to bottom. Rule 2 explicitly denies the application 'social-networking', and since the user at 192.168.1.10 is attempting to access a social-networking site, rule 2 matches before any subsequent rule. Therefore, the traffic is denied.

Option D is correct because rule 2 matches and denies the traffic.

Exam trap

The trap here is that candidates may assume a more permissive rule later in the policy (like rule 3 allowing all traffic) will override an earlier deny rule, but the firewall's first-match logic means the deny rule takes precedence.

How to eliminate wrong answers

Option A is wrong because rule 1 allows all web traffic, but the firewall processes rules sequentially and rule 2 (which denies social-networking) is evaluated before rule 3, so rule 1 does not apply to this traffic. Option B is wrong because rule 3 allows all traffic, but it is only reached if no earlier rule matches; since rule 2 matches and denies the traffic, rule 3 is never evaluated. Option C is wrong because rule 2 explicitly denies social-networking, so there is a rule that denies it; the traffic is denied due to rule 2, not because no rule allows it.

41
MCQmedium

A security administrator is configuring a policy to allow access from the Guest zone to the Internet zone. The administrator wants to ensure that only HTTP and HTTPS traffic is allowed, and all other traffic is blocked. The administrator creates a rule with source zone Guest, destination zone Internet, application web-browsing and ssl, and action Allow. However, users report that they cannot access websites. What is the most likely cause?

A.The rule is placed below a more general deny rule that blocks all traffic from Guest to Internet.
B.The rule is missing a security profile that allows web browsing.
C.The rule's service is set to application-default, but the users are using non-standard ports.
D.The application web-browsing does not include HTTPS traffic, so ssl must be replaced with web-browsing.
AnswerA

Security rules are evaluated top-down, and the first match wins. If a deny rule for all traffic from Guest to Internet is above the allow rule, it will match first and block the traffic. The allow rule will never be evaluated. This is a common misconfiguration that causes users to be unable to access websites even though an allow rule exists.

Why this answer

Security rules are processed in order from top to bottom, and the first rule that matches the traffic is applied. If a deny rule for all traffic from Guest to Internet is placed above the allow rule for web-browsing and ssl, the deny rule will match first and block all traffic, preventing users from accessing websites. The allow rule must be moved above the deny rule to take effect.

Exam trap

The trap here is focusing on the application or service settings when the real issue is rule order, which is a common oversight in policy evaluation.

42
MCQeasy

A small business has a Palo Alto Networks firewall with a single security policy rule that allows all traffic from the 'Trust' zone to the 'Untrust' zone. The business recently experienced a malware infection originating from an internal host that communicated with known malicious IP addresses. The administrator wants to implement a security policy to block traffic to these malicious IP destinations. The administrator has a list of 500 malicious IP addresses that may change frequently. What is the most efficient way to create a policy to block traffic to these IPs?

A.Create a security rule with an address group containing the 500 IPs as destination, action deny, placed above the allow rule.
B.Create a security rule with source zone Trust, destination zone Untrust, source address list containing the 500 IPs, action deny.
C.Create an External Dynamic List (EDL) of the malicious IPs and reference it in a security rule as destination address, with action deny, placed above the allow rule.
D.Create a security rule with source zone Trust, destination zone Untrust, destination address list containing the 500 IPs as separate address objects, action deny, placed above the allow rule.
AnswerC

An External Dynamic List hosts the 500 IPs externally, so the firewall rule references the list and updates happen automatically as the list changes, avoiding manual edits. Placing the deny rule above the allow rule enforces blocking, satisfying the frequently-changing list constraint.

Why this answer

An External Dynamic List (EDL) is the most efficient way to block a frequently changing list of 500 malicious IPs because the firewall automatically pulls updates from an external source (e.g., a text file on a web server), eliminating manual updates. The EDL is referenced as a destination address in a deny rule placed above the allow rule.

Exam trap

PCNSA often tests the difference between static address groups (manual updates) and External Dynamic Lists (automatic updates), and the common mistake of placing malicious IPs as source instead of destination in the deny rule.

How to eliminate wrong answers

Option A is wrong because an address group with 500 static IPs requires manual updates whenever the list changes, which is inefficient and error-prone for a frequently changing list. Option B is wrong because it places the 500 malicious IPs as the source address, but the threat is internal hosts communicating with malicious destinations — the IPs should be destinations. Option D is wrong because creating 500 separate address objects is even more manual and unmanageable than an address group, and it still requires manual updates.

43
MCQeasy

A firewall administrator notices that a security rule intended to block traffic from a specific IP address is not working. The rule is placed at the bottom of the security rulebase, and the traffic is being allowed by a rule higher in the list. What is the most likely cause?

A.The source IP is negated in the rule.
B.The rule is placed at the top of the rulebase and overridden by a later rule.
C.The rule is positioned below an allow rule that matches the same traffic.
D.The rule is disabled in the rulebase.
AnswerC

Palo Alto Networks evaluates security rules top-down and stops at the first match, so a rule placed below an allow rule covering the same source, destination and application is never reached. The blocking rule must be moved above the matching allow rule to take effect.

Why this answer

The Palo Alto Networks firewall evaluates security rules in top-down order, from the first rule in the rulebase to the last. If a rule that allows traffic is placed higher in the list, it will match and permit the traffic before the lower-placed block rule is ever evaluated. The block rule at the bottom is effectively never reached for that traffic, which is why the intended blocking action fails.

Exam trap

The trap here is that candidates may think rule order does not matter or that a block rule can override an allow rule regardless of position, but Palo Alto Networks enforces strict top-down evaluation where the first match wins, so a lower rule cannot override a higher rule's action.

How to eliminate wrong answers

Option A is wrong because negating the source IP in the rule would mean the rule matches traffic from any IP except the specified one, which would not block the intended IP; however, the question states the rule is intended to block a specific IP, and the issue is the rule's position, not its logic. Option B is wrong because if the rule were at the top of the rulebase, it would be evaluated first and would not be overridden by a later rule (Palo Alto Networks uses first-match, not last-match, semantics). Option D is wrong because a disabled rule is simply skipped during evaluation and would not cause traffic to be allowed by a higher rule; the traffic would still be evaluated against other enabled rules in order.

44
MCQhard

After a policy change, a security administrator commits the candidate configuration, but the changes do not take effect immediately for all users. Some users report connectivity issues while others do not. What should the administrator check first?

A.The new rule has an incorrect source zone.
B.There is a mismatch between the virtual wire vs layer3 interface.
C.The committed configuration is still in candidate state.
D.The commit was successful but the changes are applied only to new sessions, not existing sessions.
AnswerD

PAN-OS commits apply policy to new sessions only; established sessions retain their original policy until they time out or are cleared. The mixed user experience described in the stem is the expected behaviour, so the administrator should verify existing sessions rather than suspect a failed commit.

Why this answer

In PAN-OS, committing a candidate configuration pushes the new policy into the running configuration, but security policy evaluation happens at session setup. Existing sessions continue to be evaluated against the policy that was in force when the session was created, so users with long-lived or already-established sessions keep the old behavior while users opening new sessions get the new rule. This explains why only some users report issues after the commit.

Exam trap

The trap here is assuming a successful commit means the change is instantly effective for all traffic; PCNSA often tests the distinction between configuration commit and session-level policy enforcement.

How to eliminate wrong answers

Option A is wrong because an incorrect source zone would cause the rule to fail for all matching traffic consistently, not produce a split where only some users are affected. Option B is wrong because a virtual wire vs Layer 3 interface mismatch is a design/deployment error that would break traffic broadly and would not be introduced by a policy commit. Option C is wrong because if the configuration were still only in candidate state, the commit would not have been reported as successful and no users would see the new behavior at all.

45
MCQmedium

A security administrator is configuring a rule to allow access to a web server. The rule uses a URL category as the destination. The administrator notices that the rule is not matching traffic to the web server's IP address when users connect directly via IP. What is the most likely reason?

A.The security profile attached to the rule is blocking the traffic before the rule can match.
B.URL categories are only evaluated for HTTP and HTTPS traffic, and direct IP access may not be categorized.
C.The firewall requires a DNS sinkhole to be configured for URL category rules to work.
D.The rule's source zone is incorrect, causing the traffic to be evaluated against a different rule.
AnswerB

URL categories are determined by the URL filtering engine based on the URL or SNI in the request. When users connect directly to an IP address without a hostname, the firewall may not be able to categorize the traffic, so the rule referencing a URL category will not match. The rule would match only if the traffic is identified with a known URL category. This is expected behavior for URL category-based rules.

Why this answer

URL categories are derived from the URL or SNI in the request. When users connect directly to an IP address without a hostname, the firewall often cannot determine a URL category, so a rule that references a URL category will not match. The traffic may then be evaluated against other rules or the implicit deny.

To allow such traffic, the administrator should use an IP address or address group in the destination field instead of a URL category.

Exam trap

The trap here is assuming that a URL category will match any traffic to a server's IP, when URL categories are based on the requested URL or SNI.

46
MCQmedium

A company wants to block all traffic from the Guest zone to the Corporate zone except DNS. What is the best practice for configuring the security policy?

A.Create a deny rule for any traffic from Guest to Corporate, placed above an allow rule for DNS.
B.Rely on the interzone default rule, which blocks all traffic, and add a rule to allow DNS.
C.Create an allow rule for DNS from Guest to Corporate, placed above a deny rule for any other traffic.
D.Create a universal rule that applies to all zones with action 'allow' for DNS and 'deny' for everything else.
AnswerC

Security policy is evaluated top-down with first-match semantics, so the specific DNS allow rule must precede the broader deny. Placing the deny first would drop DNS too, since the deny matches any application and no later rule is consulted.

Why this answer

PAN-OS evaluates security policies top-down and stops at the first match, so the DNS allow rule must sit above the deny rule to permit DNS while blocking everything else. This explicit allow-then-deny ordering implements least privilege and makes the intent auditable.

Exam trap

PCNSA often tests rule ordering — candidates who place the deny rule first or rely on implicit defaults forget that PAN-OS stops at the first match, so the exception rule must precede the catch-all deny.

How to eliminate wrong answers

Option A is wrong because placing the deny-any rule above the DNS allow rule means DNS traffic matches the deny first and is blocked, defeating the exception. Option B is wrong because the interzone default rule is intrazone-allow/interzone-deny only in specific default configurations and relying on implicit behavior is not best practice; also, adding only a DNS allow without an explicit deny leaves the policy intent unclear and may not block all other traffic if the default is permissive. Option D is wrong because a universal rule spanning all zones is overly broad, violates least privilege, and can unintentionally allow DNS from zones that should not have it.

47
MCQmedium

A firewall administrator is reviewing the security policy and notices that a rule allowing DNS from the Trust zone to the Untrust zone has a hit count of zero. The administrator confirms that DNS traffic is being generated and that the rule is enabled. Which action should the administrator take to troubleshoot why the rule is not being hit?

A.Check if there is a rule above that matches DNS traffic and has a deny action.
B.Verify that the DNS application is included in the rule's Application column.
C.Ensure that the source and destination zones are correctly configured as Trust and Untrust.
D.Check if the rule is placed after a more general allow rule that permits all traffic.
AnswerA

If a rule above the DNS allow rule matches DNS traffic and denies it, the DNS allow rule will never be evaluated, resulting in a zero hit count. This is the most likely cause when a rule is not being hit despite traffic being present. The administrator should review the rules above for any that might match DNS.

Why this answer

Security rules are evaluated top-down. If a rule above the DNS allow rule matches DNS traffic and denies it, the DNS allow rule will never be reached, resulting in zero hits. The administrator should examine the rules above for any that might match DNS and have a deny action, or any action that would prevent the DNS rule from being evaluated.

Exam trap

The trap here is assuming the rule itself is misconfigured when the issue is actually rule order, specifically a preceding rule that matches and takes action first.

48
MCQmedium

An administrator is creating a new security rule at the top of the rulebase to allow specific web traffic. After committing, users report that all web traffic is now blocked, including traffic that was previously allowed by a lower rule. The new rule's action is set to 'Deny' and its source and destination are set to 'any'. What is the most likely cause?

A.The new deny rule is placed above the existing allow rules, so it matches all web traffic before the allow rules can be evaluated.
B.The new rule has a higher priority because it was created more recently, overriding older rules regardless of position.
C.The firewall applies security rules in a random order, so the deny rule sometimes matches before the allow rules.
D.The deny rule is only evaluated after the allow rules, so it should not block allowed traffic; the issue is likely a misconfigured application filter.
AnswerA

Security rules are evaluated top-down, and the first matching rule is applied. Placing a broad deny rule with any source and destination above existing allow rules causes all web traffic to match the deny rule first, blocking it. The administrator should place specific allow rules above broad deny rules or make the deny rule more specific.

Why this answer

Security rules are processed in order from top to bottom. The first rule that matches the traffic determines the action. A broad deny rule placed at the top will match all web traffic and block it before any lower allow rules can be evaluated.

To fix this, the administrator should move the deny rule below specific allow rules or narrow its match criteria.

Exam trap

The trap here is assuming that rule order does not matter or that newer rules have priority, when in fact position in the rulebase is the sole determinant of evaluation order.

49
MCQmedium

A network administrator notices that traffic from a specific subnet is being denied even though there is a permit rule that matches the source and destination. The rulebase has over 500 rules. What is the most likely cause?

A.The destination NAT is causing asymmetric routing.
B.The rule is too far down in the rulebase and a previous implicit deny is blocking.
C.A previous rule with a broader match is denying the traffic before reaching the permit rule.
D.The application override is misconfigured.
AnswerC

PAN-OS evaluates the rulebase top-down and stops at the first match. A broader deny rule positioned above the permit rule shadows it, so traffic from that subnet is dropped before the matching permit is ever evaluated.

Why this answer

In a firewall rulebase, rules are evaluated from top to bottom. If a previous rule with a broader match denies the traffic, it will be blocked before reaching the permit rule lower in the list. Option B is incorrect because the implicit deny is only at the end of the rulebase; there is no implicit deny earlier.

Options A and D are unrelated to the scenario: asymmetric routing from destination NAT and misconfigured application override do not cause denial when a matching permit rule exists.

50
MCQhard

A security administrator is troubleshooting why a security rule that allows traffic from the 'Trust' zone to the 'DMZ' zone is not being matched. The administrator confirms that the source IP, destination IP, and application are correct. The rule is placed at the top of the rulebase. What is the most likely reason the rule is not being hit?

A.The security profile attached to the rule is blocking the traffic.
B.The application is not recognized by App-ID due to encryption.
C.The destination zone is incorrectly configured on the firewall interface.
D.The rule is disabled.
AnswerC

For a security rule to match, the source and destination zones must be correctly associated with the ingress and egress interfaces. If the DMZ interface is not assigned to the 'DMZ' zone, the traffic will not match the rule's destination zone. This is a common misconfiguration. Verifying zone assignments on interfaces is essential when troubleshooting rule matches.

Why this answer

Security rules match on source and destination zones, which are determined by the interfaces the traffic enters and exits. If the DMZ interface is not assigned to the 'DMZ' zone, the destination zone in the rule will not match the actual zone of the egress interface. This prevents the rule from being hit.

Checking zone assignments is a critical troubleshooting step.

Exam trap

The trap here is focusing on application or security profiles when the rule is not matched at all, overlooking the fundamental requirement that zones must be correctly assigned to interfaces.

51
MCQmedium

A company is migrating from a legacy firewall to a Palo Alto Networks firewall. The legacy policy has many rules with overlapping source and destination objects. Which feature should the administrator use to simplify the policy before migration?

A.Policy Optimizer
B.WildFire
C.Application Override
D.User-ID
AnswerA

Policy Optimizer analyses traffic logs to identify redundant, unused and overlapping rules, and can consolidate them into App-ID based policy. This satisfies the migration constraint by shrinking the rulebase before it is recreated on the Palo Alto Networks firewall.

Why this answer

Policy Optimizer is a Palo Alto Networks tool that analyzes existing security policies to identify redundant, shadowed, or unused rules and recommends consolidation. It helps administrators simplify complex rule sets by showing which rules can be merged or removed, making it ideal for cleaning up a legacy policy before migration. This directly addresses the problem of overlapping source and destination objects.

Exam trap

PCNSA often tests the purpose of Palo Alto Networks features, and the trap is confusing Policy Optimizer with other tools like WildFire or Application Override — candidates who associate 'optimization' with performance rather than policy cleanup may pick the wrong feature.

How to eliminate wrong answers

Option B is wrong because WildFire is a cloud-based malware analysis and threat prevention service, not a policy analysis or optimization tool. Option C is wrong because Application Override is used to force specific applications to be identified on non-standard ports, not to simplify or consolidate security policies. Option D is wrong because User-ID is a feature that maps IP addresses to users for policy enforcement, not a tool for analyzing or simplifying rule sets.

52
MCQmedium

An administrator has created a security rule that allows traffic from the 'Guest' zone to the 'Internet' zone for web browsing. Users in the Guest zone report that they can access some websites but not others. The administrator checks the traffic logs and sees that some sessions are being denied by the implicit deny rule. What is the most likely reason?

A.The implicit deny rule is evaluated before the custom rule, so all traffic is denied unless explicitly allowed above it.
B.The security rule is only allowing the 'web-browsing' application, but some websites use other applications such as 'ssl' or 'facebook-base'.
C.The rule is placed below the implicit deny rule, so it is never evaluated.
D.The security rule is not logging traffic, so the administrator cannot see which rule is allowing the traffic.
AnswerB

The rule allows only 'web-browsing', which covers HTTP. However, many websites use HTTPS ('ssl') or other applications. If those applications are not allowed, the sessions will not match the rule and will be denied by the implicit deny rule. The administrator should add additional applications to the rule as needed.

Why this answer

The allow rule only permits the 'web-browsing' application. Some websites use HTTPS or other applications that are not matched by this rule, so those sessions fall through to the implicit deny. The administrator should add the necessary applications, such as 'ssl', to the rule to allow complete web access.

Exam trap

The trap here is assuming that allowing 'web-browsing' covers all web traffic, when in fact HTTPS and other web applications require separate application entries.

53
MCQmedium

Refer to the exhibit. An administrator is analyzing the rulebase. Traffic from source 10.1.1.5 to destination 8.8.8.8 using web-browsing application (HTTP TCP/80). Which rule will match?

A.rule3.
B.rule2.
C.rule1.
D.None, because rule1 and rule2 have specific applications.
AnswerA

rule3 matches the traffic because source subnet includes 10.1.1.5 and application any.

Why this answer

Rule3 has source 10.1.1.0/24 and application any, matching the traffic. rule1 does not match because it only allows ssl application. rule2 does not match because its source is 10.1.0.0/24, which does not include 10.1.1.5. Therefore, rule3 is the first matching rule, and it denies the traffic.

54
MCQhard

A network engineer needs to ensure that all traffic from the 'Guest' zone to the 'Internet' zone is inspected for malware, but also wants to allow high-bandwidth video conferencing traffic to bypass threat inspection for performance reasons. Which approach best achieves this?

A.Create two rules: one for general traffic with 'allow' action and a 'threat' profile, and a higher-priority rule for video conferencing traffic with 'allow' action and no threat profile.
B.Create a single rule with 'allow' action and no security profiles, and rely on the firewall's default behavior to inspect malware.
C.Create a single rule with 'allow' action and a 'threat' profile applied, and rely on the firewall's ability to skip inspection for video traffic automatically.
D.Use policy-based forwarding to route video traffic to a separate interface that has no security profiles.
AnswerA

Security policy is evaluated top-down, so a higher-priority rule matching video conferencing with no threat profile permits that traffic uninspected, while the lower general rule still applies the threat profile to all remaining Guest-to-Internet sessions.

Why this answer

It uses two security rules with different priorities: a higher-priority rule for video conferencing traffic with an 'allow' action and no threat profile to bypass inspection, and a lower-priority rule for general traffic with an 'allow' action and a threat profile to enforce malware inspection. This leverages the firewall's rule-ordering logic, where the first matching rule is applied, allowing selective bypass of threat inspection for specific traffic while maintaining security for other traffic.

Exam trap

The trap here is that candidates may assume the firewall can automatically detect and exempt video traffic from inspection without explicit rule configuration, or that a single rule with a threat profile can be configured to skip inspection for certain applications, but Palo Alto firewalls require separate rules or profile exceptions to achieve selective bypass.

How to eliminate wrong answers

Option B is wrong because creating a single rule with no security profiles would allow all traffic without any threat inspection, failing to meet the requirement to inspect general traffic for malware. Option C is wrong because firewalls do not automatically skip threat inspection for video traffic based on traffic type alone; a specific rule or profile exception must be configured. Option D is wrong because policy-based forwarding (PBF) is used to route traffic based on policies, not to selectively apply or bypass security profiles; it would add unnecessary complexity and does not directly control threat inspection on the same interface.

55
MCQeasy

A network security administrator is reviewing the security policy on a Palo Alto Networks firewall. The administrator wants to ensure that traffic from the Trust zone to the Untrust zone is inspected by a specific security profile group. Which policy component should the administrator configure to attach the security profile group?

A.The decryption policy rule that matches the traffic
B.The security rule that permits the traffic
C.The application override policy rule
D.The NAT rule that translates the source address
AnswerB

Security profiles are attached to security rules, and they are applied only to traffic that matches the rule. To inspect Trust-to-Untrust traffic with a specific profile group, the administrator must attach that profile group to the rule that allows the traffic. Other policy types, such as NAT or decryption, may influence traffic but do not directly apply security profiles for inspection.

Why this answer

Security profile groups are attached directly to security rules. When traffic matches a security rule, the firewall applies the attached profile group to inspect the traffic for threats, malware, and other risks. NAT, decryption, and application override rules serve different purposes and do not provide the field to attach security profile groups.

The administrator must edit the security rule that permits the traffic.

Exam trap

The trap here is thinking that security profiles can be attached to NAT or decryption rules, when they are configured on security rules only.

56
MCQmedium

An administrator has configured a security rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for specific applications. The rule is placed at position 5 in the rulebase. A user reports that traffic matching this rule is being denied. Upon inspection, the administrator finds that a rule at position 3 denies all traffic from 'Trust' to 'Untrust' for any application. What is the most likely cause of the denial?

A.The rule at position 3 is evaluated first and matches the traffic, so the deny action is applied.
B.The rule at position 5 is not correctly configured with the appropriate applications.
C.The deny rule at position 3 is a default rule and cannot be overridden by any other rule.
D.The firewall requires a security profile to be attached to the allow rule for it to take effect.
AnswerA

Security rules are evaluated top-down, and the first match is applied. The rule at position 3 denies all Trust-to-Untrust traffic, so any traffic from Trust to Untrust will match that rule before reaching the allow rule at position 5. Therefore, the traffic is denied.

Why this answer

Security rules are processed in order from top to bottom, and the first rule that matches the traffic determines the action. Because the deny rule at position 3 matches all Trust-to-Untrust traffic, it takes precedence over the allow rule at position 5. To resolve this, the administrator should move the allow rule above the deny rule or modify the deny rule to be more specific.

Exam trap

The trap here is assuming that a more specific allow rule will be evaluated before a broader deny rule, but rule order is strictly sequential.

57
MCQeasy

An administrator needs to create a security policy rule that allows only DNS traffic from the 'Guest' zone to the 'DMZ' zone. Which application should be used in the rule to achieve this?

A.dns
B.dns-over-https
C.dns-base
D.udp-53
AnswerA

The 'dns' application in PAN-OS is specifically designed to identify DNS traffic, which typically uses UDP or TCP port 53. By using the 'dns' application in the security rule, the firewall will allow only DNS traffic that matches the application signature, ensuring that other traffic is not permitted. This is the correct application to meet the requirement of allowing only DNS traffic from Guest to DMZ.

Why this answer

The 'dns' application in PAN-OS accurately identifies DNS traffic based on its signature, typically on port 53. Using this application in the security rule ensures that only DNS traffic is allowed from the Guest zone to the DMZ zone, while other traffic is blocked. This approach leverages App-ID for precise control, rather than relying solely on port numbers, which can be less secure.

Exam trap

The trap here is confusing a service object like 'udp-53' with an application, leading to a rule that allows any traffic on that port rather than just DNS.

58
MCQmedium

A network security administrator at a university wants to allow students in the 'Student' zone to access the internet, but only during exam periods should they be blocked from social media. The administrator creates a security rule at the top of the rulebase that denies social media applications from the Student zone to the Internet zone and schedules it to be active only during exam weeks using a schedule object. Which statement correctly describes the evaluation of this rule?

A.The rule will be evaluated only when the schedule is active; outside the schedule, it is skipped and later rules are evaluated.
B.The rule will always be evaluated, but the action will be changed to allow when the schedule is inactive.
C.The rule will be evaluated only if the schedule is active, and if inactive, the default interzone-default rule will be applied immediately.
D.The rule will be evaluated regardless of schedule, but logging will be suppressed when the schedule is inactive.
AnswerA

Security rules with an attached schedule object are only active during the defined times. When the schedule is inactive, the firewall skips that rule and continues evaluating subsequent rules in the rulebase. This allows temporary policy enforcement without manual intervention, exactly as intended for blocking social media only during exam periods.

Why this answer

Security rules can be associated with schedule objects to make them active only during specific time periods. When the schedule is inactive, the rule is skipped entirely during policy evaluation, allowing subsequent rules to be processed. This enables temporary enforcement without manual rule changes, which is ideal for time-bound restrictions like exam-period social media blocks.

Exam trap

The trap here is assuming that an inactive schedule changes the rule's action or causes immediate fallback to the default rule, when in fact the rule is simply skipped and evaluation continues.

59
MCQhard

An administrator has configured a security policy with a rule that allows traffic from the 'Guest' zone to the 'Internet' zone. The rule uses the application 'web-browsing' and 'ssl' with service 'application-default'. Users in the Guest zone report that they cannot access a specific website that uses a non-standard port for HTTPS (port 8443). What is the most likely cause of the issue?

A.The service 'application-default' only allows default ports, so port 8443 is blocked. A custom service must be added to the rule.
B.The security rule is not matching because the application 'web-browsing' does not cover HTTPS traffic.
C.The firewall is configured to block non-standard ports by default, and a security profile must be applied to allow them.
D.The application 'ssl' does not support non-standard ports; a custom application must be created.
AnswerA

The service 'application-default' uses the default ports defined for the application. For 'ssl', the default port is 443. Since the website uses port 8443, the traffic is not matching the service and is therefore blocked. Adding a custom service for port 8443 and including it in the rule would resolve the issue.

Why this answer

The service 'application-default' restricts traffic to the default ports for the selected applications. For 'ssl', the default port is 443. Since the website uses port 8443, the traffic does not match the service and is blocked.

To allow it, the administrator must create a custom service for port 8443 and add it to the security rule, ensuring the application is still identified correctly.

Exam trap

The trap here is assuming that specifying the application 'ssl' automatically allows any port, but the service setting controls the port and 'application-default' only permits default ports.

60
MCQmedium

An administrator needs to allow a specific set of external IP addresses to access an internal web server on port 443, but all other traffic to that server must be blocked. The administrator creates a security policy rule that allows the specific IP addresses and places it at the bottom of the rulebase. What will be the result?

A.The rule will be ignored because the implicit deny rule at the top blocks all traffic first.
B.The rule will allow the specific IP addresses but also allow all other traffic because the implicit deny is overridden.
C.The rule will not be evaluated because rules are processed in alphabetical order.
D.The rule will be evaluated last, and if no other rule matches, the specific IP addresses will be allowed and all others will be blocked by the implicit deny.
AnswerD

Rules are evaluated top-down. If the allow rule is at the bottom, any traffic not matching earlier rules will eventually hit this rule. The specific IP addresses will be allowed, and all other traffic will fall through to the implicit deny at the end of the rulebase. This achieves the desired outcome, but it is not the most efficient placement because earlier rules might inadvertently match.

Why this answer

Security rules are evaluated from top to bottom. Placing a specific allow rule at the bottom means it will be evaluated after any earlier rules. If no earlier rule matches, the specific IP addresses will be allowed, and all other traffic will be blocked by the implicit deny.

However, best practice is to place more specific rules above more general ones to ensure they are hit first.

Exam trap

The trap here is assuming that rule order does not matter as long as the correct rule exists, when in fact a more general rule above can shadow a specific rule below.

61
Multi-Selecthard

Which THREE factors should be considered when troubleshooting a 'deny' rule that is unexpectedly blocking traffic? (Choose three.)

Select 3 answers
A.The position of the deny rule in the rulebase relative to allow rules.
B.Whether the deny rule is disabled.
C.Whether the source/destination zones or addresses are correctly defined.
D.Whether logging is enabled on the rule.
E.Whether SSL decryption is enabled for the traffic.
AnswersA, B, C

A higher-priority allow rule might match before the deny rule.

Why this answer

The firewall evaluates rules in top-down order, and a deny rule placed above an allow rule for the same traffic will match first and block the traffic, even if a subsequent allow rule would have permitted it. This is a fundamental aspect of policy evaluation in Palo Alto Networks firewalls, where the first matching rule is applied and no further rule processing occurs.

Exam trap

The trap here is that candidates may confuse operational features like logging or decryption with the core policy evaluation logic, assuming they influence rule matching, when in fact only rule order, rule state, and correct object definitions determine whether a deny rule blocks traffic.

62
MCQhard

A company has a Palo Alto Networks firewall with multiple virtual routers. The security policy has a rule that allows SSH from the 'Internal' zone to the 'DMZ' zone. Recently, a new subnet 10.10.20.0/24 was added to the Internal zone. Users in that subnet report they cannot SSH to a server at 192.168.1.10 in the DMZ, while users from other subnets in Internal can. The rule has source address object '10.0.0.0/8' which includes the new subnet. The rule's source zone is Internal, destination zone is DMZ, and application is SSH. The administrator confirms the new subnet's IPs are within 10.0.0.0/8. What is the most likely cause of the problem?

A.The application is not correctly identified because the SSH server uses a non-standard port.
B.There is a deny rule placed above the allow rule that matches the new subnet but not the other subnets.
C.The firewall's route table has a more specific route for 10.10.20.0/24 pointing to a different virtual router, causing traffic from that subnet to enter via an interface in a different zone.
D.The rule's source address object is incorrectly defined as '10.0.0.0/8' but the new subnet is not actually within that range.
AnswerC

A more specific 10.10.20.0/24 route pointing to another virtual router sends that subnet's traffic out a different interface, so it arrives in a zone other than Internal. The security rule's source zone then fails to match, denying SSH despite the 10.0.0.0/8 address object.

Why this answer

The most likely cause is that a more specific route for 10.10.20.0/24 in the virtual router's routing table points to a different virtual router or interface that belongs to a different zone. In Palo Alto Networks firewalls, zone membership is determined by the ingress interface, not by the source IP address alone. If traffic from the new subnet enters through an interface in a different zone, the security rule with source zone 'Internal' will not match, and the SSH connection is denied or dropped.

This explains why other subnets in Internal work while the new subnet does not, even though the source address object covers it.

Exam trap

PCNSA often tests the misconception that source IP address alone determines zone membership, when in fact the ingress interface and routing table determine which zone the traffic is classified into.

How to eliminate wrong answers

Option A is wrong because the question states the application is SSH and other subnets can SSH successfully, so application identification on a non-standard port is not the differentiator; if it were, all subnets would fail. Option B is wrong because a deny rule above the allow rule would have to match the new subnet specifically, but no such rule is described, and the scenario points to a routing/zone issue rather than policy ordering. Option D is wrong because 10.10.20.0/24 is mathematically within 10.0.0.0/8, so the source address object does include the new subnet; the administrator already confirmed this.

63
MCQeasy

A security administrator is reviewing the security policy on a PA-220 firewall. The administrator notices that a rule allowing DNS from the 'Trust' zone to the 'Untrust' zone is being shadowed by a rule above it that denies all traffic from 'Trust' to 'Untrust'. What is the term for this situation?

A.Rule duplication
B.Rule shadowing
C.Rule overlap
D.Rule conflict
AnswerB

Rule shadowing occurs when a rule is never matched because a preceding rule matches the same traffic and takes action. In this case, the deny rule above prevents the DNS allow rule from ever being evaluated. This is a common policy misconfiguration that can lead to unintended denial of legitimate traffic. Administrators should regularly audit rule order to avoid shadowing.

Why this answer

Rule shadowing in PAN-OS occurs when a rule is placed below another rule that matches the same traffic and takes a different action, causing the lower rule to never be evaluated. In this case, the deny rule above the DNS allow rule shadows it, effectively disabling the allow rule. This is a critical policy management issue that can be identified using the firewall's rule analysis tools.

Exam trap

The trap here is using a general term like 'rule conflict' when the specific phenomenon of a rule being completely obscured by a preceding rule is called shadowing.

64
MCQhard

A security administrator is configuring a rule to allow access to a web application hosted on multiple servers with changing IP addresses. The administrator wants to ensure the rule automatically updates as the IP addresses change, without manual intervention. Which feature should be used?

A.Dynamic Address Group
B.Static Address Group
C.Application Group
D.External Dynamic List
AnswerA

Dynamic Address Groups use tags to automatically include IP addresses that match certain criteria. When an IP address is tagged, it becomes a member of the group. This allows the security rule to automatically adapt as IP addresses change, without manual updates. This is the correct feature for dynamically updating rule membership based on IP addresses.

Why this answer

Dynamic Address Groups automatically update their members based on tags. When an IP address is tagged, it becomes part of the group. This allows security rules to dynamically adapt to changing IP addresses without manual intervention.

Static Address Groups, External Dynamic Lists, and Application Groups do not provide the same seamless dynamic membership based on tagging.

Exam trap

The trap here is confusing Dynamic Address Groups with External Dynamic Lists, as both can involve dynamic IP addresses, but only Dynamic Address Groups use tags for automatic membership.

65
MCQhard

An administrator is configuring a security rule that allows access from the Trust zone to the DMZ zone for a specific application. The administrator wants to ensure that the rule only allows the application on its default port and blocks the application if it attempts to use a non-standard port. Which setting should be used in the Service column of the security rule?

A.application-default
B.any
C.service-http
D.service-https
AnswerA

Application-default automatically restricts the service to the default ports defined for the selected application. If the application attempts to use a non-standard port, the rule will not match, and the traffic will be blocked by subsequent rules or the default deny. This precisely meets the requirement to allow only on default ports.

Why this answer

The application-default option in the Service column restricts the rule to the default ports for the selected application. This ensures that the application is only allowed on its standard ports, and any attempt to use a non-standard port will not match the rule, effectively blocking it. This is the correct way to enforce default port usage.

Exam trap

The trap here is selecting a specific service like service-http or service-https, which may not cover all default ports for the application, or selecting any, which allows all ports.

Ready to test yourself?

Try a timed practice session using only Policy Evaluation and Management questions.