Courseiva

PCNSA · topic practice

Securing Traffic practice questions

Securing Traffic covers how the firewall classifies, decrypts, and inspects traffic after a session matches a Security policy rule. Questions use exhibits of rules and profiles, asking you to identify rule roles, pick the right Security Profile for a threat such as DNS tunneling, and explain why allowed traffic bypasses a block rule.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Securing Traffic

What the exam tests

What to know about Securing Traffic

Read the rulebase top-down and identify which rule actually matches the session, then map the threat to the correct Security Profile. The single most important thing is rule order: the first matching rule wins, so a block rule below an allow rule never fires.

Security policy rule roles and how rule order and match criteria determine which rule applies

Applying Security Profiles such as Anti-Spyware, Vulnerability Protection, URL Filtering, and DNS Security to traffic

SSL/TLS decryption methods including forward proxy and inbound inspection, and decryption policy exceptions

Why traffic is allowed despite a block rule, including rule order, negated match, or an earlier allow rule

Watch out for

Common Securing Traffic exam traps

  • ▸Assuming a block rule takes effect when an earlier rule above it already matches and allows the session
  • ▸Applying the wrong profile to DNS, such as URL Filtering instead of DNS Security, to stop DNS tunneling
  • ▸Forgetting that decryption must be configured before content-based profiles can inspect encrypted sessions

Practice set

Securing Traffic questions

20 questions · select your answer, then reveal the explanation

When configuring a security policy rule to allow HTTP traffic from the internal zone to the external zone, which mandatory components must be defined?

A financial services company uses a Palo Alto Networks PA-5220 firewall in an active/passive HA pair at their headquarters. They have a single zone 'Trust-LAN' for internal users and a single zone 'Untrust-WAN' for internet traffic. The security policy currently includes a rule that allows all outbound HTTP/HTTPS traffic from 'Trust-LAN' to 'Untrust-WAN' with no security profiles applied. Recently, users have been complaining about slow internet performance, and the IT team suspects malware or botnet activity. The firewall's logs show numerous sessions to known malicious IPs, but the firewall is not blocking them. The network architect decides to implement URL Filtering and Threat Prevention profiles on the outbound rule. However, after committing the changes, some users report that legitimate websites (e.g., online banking, cloud apps) are being blocked. The IT team verifies that the URL Filtering profile is set to 'alert' for all categories except 'malware' which is 'block', and the Threat Prevention profile is set to 'default' action. What is the most likely cause of the legitimate website blocking?

Which TWO actions can be taken in a security policy rule to allow traffic from the corporate network to the internet while also logging the traffic?

Refer to the exhibit. A user at IP 10.10.10.10 tries to browse to http://192.0.2.50. Which rule matches this traffic?

Exhibit

Refer to the exhibit.

admin@PA-5050> show running security-policy

  name                      from     to       source          destination  application  service    action
  ------------------------  -------  -------  --------------  -----------  ------------  ---------  -------
  1 allow-web               trust    untrust  10.0.0.0/8      192.0.2.0/24 web-browsing  http       allow
  2 block-malware           trust    untrust  any             any          any           any        deny
  3 allow-dns               trust    untrust  any             any          dns           udp/53     allow

  Total rules: 3
Question 5mediummultiple choice
Read the full Securing Traffic explanation →

A company is experiencing performance issues due to large amounts of encrypted traffic. They want to offload decryption to a dedicated appliance but still maintain visibility. Which feature should they configure on the Palo Alto Networks firewall?

A firewall administrator wants to ensure that all traffic from the inside zone to the outside zone is inspected for threats, but without causing a bottleneck. Which profile group should be applied to the security rule?

During a security audit, it is discovered that some applications are being incorrectly identified by the Palo Alto Networks firewall. What should the administrator do to improve application identification accuracy?

An administrator needs to block all traffic from a specific IP address on the external interface. What is the simplest method?

Question 9mediummultiple choice
Read the full Securing Traffic explanation →

A user reports being unable to access an external FTP server, but other users can access it. The firewall logs show the traffic being denied. What should the administrator check first?

An administrator wants to enforce that only certain approved applications can be used on the network. Which TWO features should be configured?

An organization uses GlobalProtect for remote access. They want to ensure that only compliant devices can connect. Which TWO GlobalProtect features should be enabled?

Question 12mediummultiple choice
Read the full Securing Traffic explanation →

Based on the exhibit, what will happen to an HTTPS request from an untrust zone user to destination IP 10.1.1.50?

Exhibit

Refer to the exhibit.
Exhibit: CLI output from 'show running security-policy' shows:

```
set rulebase security rules "Allow_Web" from untrust to dmz source any destination 10.1.1.0/24 application web-browsing,ssl service tcp/80, tcp/443 action allow log-end
set rulebase security rules "Block_ALL" from any to any source any destination any application any service any action deny
```

An administrator notices that SSH tunnels are being blocked by the firewall. According to the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit.
Exhibit: Config snippet:

```
set shared application-tunnel time-to-live 30
set shared application-tunnel policy "Block_Tor" action deny
set shared application-tunnel policy "Allow_SSH" action allow tunnel detection none
```
Question 14mediummultiple choice
Read the full Securing Traffic explanation →

A security administrator notices that traffic from the internal trust zone to the external untrust zone is being allowed despite a security policy rule explicitly denying that traffic. The rule is present in the policy list and the match conditions seem correct. What is the most likely cause of this issue?

Question 15easymultiple choice
Read the full NAT/PAT explanation →

An organization wants to hide internal IP addresses when accessing the Internet. Which type of NAT should be configured?

A firewall is configured with multiple virtual systems (vsys). An administrator wants to allow traffic from vsys1 to vsys2 while keeping other inter-vsys traffic blocked. How should this be accomplished?

Which TWO security profile types are used to block known malware? (Choose two.)

Question 18mediummultiple choice
Read the full Securing Traffic explanation →

A user at source IP 10.1.1.1 initiates an HTTPS connection to a web server on the internet. Which rule will the traffic match?

Exhibit

Refer to the exhibit.

admin@PA-500> show running security-policy

Rules:
1. name: allow-http-from-trust-to-untrust
   source: 10.0.0.0/8
   destination: any
   application: http
   action: allow

2. name: deny-all-from-trust-to-untrust
   source: 10.0.0.0/8
   destination: any
   application: any
   action: deny

3. name: allow-dns-from-trust-to-untrust
   source: 10.0.0.0/8
   destination: any
   application: dns
   action: allow

Note: There are no other security rules.
Question 19easymultiple choice
Read the full NAT/PAT explanation →

A workstation at 10.0.0.5 sends traffic to destination 8.8.8.8. Which NAT rule will be applied?

Exhibit

Refer to the exhibit.

admin@PA-500> show running nat-policy

Rules:
1. name: source-nat-1
   source: 10.0.0.0/8
   destination: any
   service: any
   source-translation: interface-ip-address (ethernet1/2)
   action: dynamic-ip-and-port

2. name: no-nat-for-servers
   source: 10.0.0.0/8
   destination: 192.168.1.0/24
   service: any
   action: no-nat

Based on the log entry, what is the most likely reason for the TCP reset from the client?

Exhibit

Refer to the exhibit.

Log entry:

Time: 2024-03-01 10:00:00
Source IP: 10.1.1.100
Destination IP: 203.0.113.50
Application: ssl
Action: allow
Session End Reason: tcp-rst-from-client
Bytes Sent: 1024
Bytes Received: 10240

Context: The security policy allows all outbound traffic. The client is a web browser.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Securing Traffic sessions

Start a Securing Traffic only practice session

Every question in these sessions is drawn from the Securing Traffic domain — nothing else.

Related practice questions

Related PCNSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSA exam test about Securing Traffic?
Read the rulebase top-down and identify which rule actually matches the session, then map the threat to the correct Security Profile. The single most important thing is rule order: the first matching rule wins, so a block rule below an allow rule never fires.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Securing Traffic questions in a focused session?
Yes — the session launcher on this page draws every question from the Securing Traffic domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSA topics?
Use the topic links above to move to related areas, or go back to the PCNSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSA exam covers. They are not copied from any real exam or dump site.