Courseiva
mediumMultiple Choice

PCNSA Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.

show security-policy

1.  From trust -> untrust, source any, destination any, application any, service any, action allow, schedule none, log start none, log end yes
2.  From trust -> untrust, source any, destination any, application ssl, service application-default, action deny, schedule none, log start no, log end yes
3.  From trust -> untrust, source any, destination any, application web-browsing, service application-default, action allow, schedule none, log start no, log end yes

Refer to the exhibit. A user in the trust zone attempts to access https://www.example.com. The traffic matches rule 2 first. What is the expected behavior?

⚠ Common exam trap

PCNSA often tests the misconception that a later allow rule can override an earlier deny rule, or that the implicit allow at the end will permit traffic if no explicit deny exists; the trap is forgetting that the first matching rule wins and its action is final.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The traffic is denied because of rule 2.

In Palo Alto Networks security policy, rules are evaluated top-down and the first match wins. Since the traffic matches rule 2 first, rule 2's action (deny) is applied immediately, and no further rules are evaluated. Therefore, the traffic is denied, regardless of rule 3 allowing web-browsing or the implicit allow at the end.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The traffic is allowed due to the implicit allow at the end.

    Why it's wrong here

    Rule 2 matches first, so its action applies and evaluation stops; the implicit deny or allow at the end is never reached. The implicit rule only governs traffic matching no explicit rule. This option would be correct if no rule matched the session.

  • ✓

    The traffic is denied because of rule 2.

    Why this is correct

    PAN-OS evaluates rules top-down and stops at the first match, so rule 2's action applies regardless of later rules permitting the traffic. If rule 2 denies, the session is dropped and no further rule lookup occurs, satisfying the stem's constraint that rule 2 matches first.

  • ✗

    The traffic is allowed because rule 3 allows web-browsing.

    Why it's wrong here

    PAN-OS applies the first matching rule and stops; rule 3 is never evaluated for this session, so its web-browsing allowance cannot permit the traffic. Rule 3 would govern only if rule 2 did not match first, which is why ordering matters in policy evaluation.

  • ✗

    The traffic is allowed because no explicit deny is configured.

    Why it's wrong here

    PAN-OS enforces an implicit deny for inter-zone traffic that matches no rule, so absence of an explicit deny does not grant access. A permissive default applies only where an explicit allow rule exists, such as an any-any rule placed after specific policies.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.