Courseiva

PCNSA · topic practice

Policy Evaluation and Management practice questions

This domain covers how PAN-OS evaluates security policy: rule order, zone and address matching, application identification, and implicit rules. Questions present traffic scenarios—often with exhibits—and ask why traffic is allowed or denied, which rule is hit, or what the firewall does next.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Policy Evaluation and Management

What the exam tests

What to know about Policy Evaluation and Management

Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.

Interpreting security rule match criteria: source/destination zone, address, user, application, and service.

Using the Traffic log and session details to identify the rule that allowed or denied a session.

Applying App-ID and Service/Application Override behavior to determine whether a rule matches.

Understanding implicit intrazone and interzone default rules and rule-order evaluation.

Watch out for

Common Policy Evaluation and Management exam traps

  • ▸Assuming a rule with application web-browsing matches all web traffic; App-ID may identify a different application and skip the rule.
  • ▸Forgetting that a new subnet must be added to both the security rule and any NAT or routing configuration to work.
  • ▸Overlooking the implicit deny or default intrazone allow rules when no explicit rule matches traffic.

Practice set

Policy Evaluation and Management questions

20 questions · select your answer, then reveal the explanation

An organization has a security policy that requires all outbound HTTP traffic from the 'Corporate' zone to the 'Internet' zone to be inspected by the URL Filtering profile. However, the administrator notices that some users can still access blocked categories. What is the most likely cause?

Which TWO statements correctly describe best practices for managing security policies in Palo Alto Networks firewalls? (Choose two.)

A company has a Palo Alto Networks firewall in production. They recently configured a new security policy rule to allow outbound HTTPS traffic from the internal network (10.0.0.0/8) to the internet. The rule is placed after a block rule that denies all traffic from 10.0.0.0/8 to any external destination. After committing, users report that HTTPS access is still blocked. The administrator checks the firewall logs and sees that the traffic is being denied by the block rule. The administrator verifies the rule order: the new allow rule is at position 5, and the block rule is at position 3. The administrator also checks that the source zone (Trust) and destination zone (Untrust) are correct. What is the most likely cause of the issue?

A security administrator notices that traffic from an internal user to a specific external web application is being blocked unexpectedly. The user's IP is 10.10.1.50 and the destination is 203.0.113.5 on port 443. The administrator has already verified that there is a security rule allowing the traffic. Which two logs should the administrator check first to diagnose the issue?

Question 5easymultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A user on the Sales subnet (10.10.1.50) attempts to browse to an external website using HTTP (port 80) to download a legitimate file. The website's IP is 203.0.113.50. Which rule will match this traffic?

Exhibit

Refer to the exhibit.

admin@PA-5020> show running security-policy
Set application-default

rule  id  name                        from         to           source        destination  application  service   action
---  ---  --------------------------- ----------- ------------ ------------- ------------ ------------ ---------- -------
    1    Allow-Sales-to-App           Sales        App-Servers  10.10.1.0/24  10.20.1.100  any           tcp/80    allow
    2    Allow-Any-Web                any          any           any           any          web-browsing  tcp/80    allow
    3    Block-Restricted-Apps        any          any           any           any          bittorrent    any       deny
    4    Allow-DNS                    any          any           any           any          dns           udp/53    allow

Match each security rule type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Blocks known attack patterns

Controls access to websites

Prevents transfer of specific file types

Prevents sensitive data exfiltration

An administrator wants to use Policy Optimizer to consolidate rules. Which of the following is a prerequisite for using Policy Optimizer on a rule?

A security rule is configured with source zone 'Trust', destination zone 'Untrust', source address 'any', destination address '10.10.10.0/24', application 'ssl', service 'https', action 'allow', log at session end. A user from Trust zone tries to access https://10.10.10.5. The traffic is not matching. What is the most likely reason?

An administrator needs to apply a security profile that includes anti-malware and vulnerability protection to all traffic from the internal network to the internet. However, there is already a rule that allows this traffic without any profiles. What is the most efficient way to apply the profiles?

A security administrator is analyzing the rulebase for best practices. Which TWO of the following are recommended practices for security policy management? (Choose two.)

An administrator is troubleshooting why a policy is not being matched. Which THREE of the following are valid reasons a security rule might not be hit? (Choose three.)

An administrator wants to ensure that traffic from the corporate network to the internet is inspected by the firewall's threat prevention features. Which TWO of the following are required to achieve this? (Choose two.)

Refer to the exhibit. A security rule is configured with destination address group 'internal-servers'. A packet with destination IP 10.10.20.5 arrives. Will the rule match?

Exhibit

admin@PA-500> show object address-group "internal-servers"
group {
    members [ server1 server2 ]
}

admin@PA-500> show object address "server1"
address {
    ip-netmask 10.10.10.0/24
}

admin@PA-500> show object address "server2"
address {
    ip-range 10.10.20.1-10.10.20.10
}

A security administrator notices that a newly added security rule, designed to allow SSH traffic from the engineering department to a Linux server, is not being matched. The rule is placed above an existing 'deny all' rule. What is the most likely cause?

An administrator is using Policy Tester to validate a rule before deployment. The rule allows HTTP and HTTPS from user 'John' (IP 10.1.1.10) to server 192.168.1.100. The tester shows 'No match' for traffic from John's IP to the server on port 80. What could be the reason?

Which TWO factors affect the order in which security rules are evaluated?

Which THREE are valid methods to test security policy effectiveness before deployment?

Refer to the exhibit. The administrator wants to remove unused rules to improve performance. Which rule should be removed?

Exhibit

user@fw> show security-rule hit-count
rule_id: 1, name: allow-dns, hit_count: 14527
rule_id: 2, name: allow-web, hit_count: 8923
rule_id: 3, name: deny-ssh, hit_count: 0
rule_id: 4, name: allow-mail, hit_count: 2104
rule_id: 5, name: deny-all, hit_count: 73

Refer to the exhibit. Traffic from Sales zone to Finance zone reaches destination 10.10.10.10 using application 'ssl'. What action does the firewall take?

Exhibit

set security policies policy-name Allow-Sales-to-Finance
  from Sales
  to Finance
  source any
  destination 10.10.10.0/24
  application ms-office365
  action allow
  log-start yes
set security policies policy-name Deny-Other
  from Sales
  to Finance
  source any
  destination any
  application any
  action deny
  log-end yes
Question 20easymultiple choice
Read the full DNS explanation →

Refer to the exhibit. An internal DNS server in the trust zone communicates with an external DNS server in the untrust zone. Which rule will match the DNS traffic?

Exhibit

> show running security-policy

rule 1: name: allow-http, source: trust, dest: untrust, application: web-browsing, action: allow
rule 2: name: allow-dns, source: trust, dest: untrust, application: dns, action: allow
rule 3: name: deny-all, source: any, dest: any, application: any, action: deny

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Policy Evaluation and Management sessions

Start a Policy Evaluation and Management only practice session

Every question in these sessions is drawn from the Policy Evaluation and Management domain — nothing else.

Related practice questions

Related PCNSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSA exam test about Policy Evaluation and Management?
Be able to trace a session through PAN-OS policy evaluation: match zones, addresses, users, applications, and services in rule order, then confirm with the Traffic log. The most important thing is identifying the exact rule that matches or the implicit rule that denies.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Policy Evaluation and Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Policy Evaluation and Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSA topics?
Use the topic links above to move to related areas, or go back to the PCNSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSA exam covers. They are not copied from any real exam or dump site.