PCNSE Core Concepts and Architecture Practice Question
A company has a Palo Alto Networks firewall with two virtual systems (vsys) configured. The administrator wants to ensure that traffic between vsys1 and vsys2 is inspected by the firewall. What must be configured to allow this inter-vsys traffic?
⚠ Common exam trap
The trap here is assuming that a Security policy rule alone is enough for inter-vsys traffic, but routing between the isolated vsys instances is also required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A shared Security policy rule in the shared policy or a rule in each vsys, plus routing between the vsys.
To allow inter-vsys traffic, the administrator must configure Security policy rules that permit the traffic, either as a shared rule or individual rules in each vsys, and ensure that routing is in place to direct traffic between the vsys. Each vsys has its own virtual router, so routes must exist to forward traffic from one vsys to the other, often through a shared interface or an inter-vsys link. Without both policy and routing, the traffic will be blocked or dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A NAT policy rule translating the source IP addresses between vsys.
Why it's wrong here
NAT policy is used for address translation and does not permit inter-vsys traffic. While NAT might be used in some inter-vsys scenarios, it is not a requirement to allow the traffic. The primary requirements are Security policy rules and routing. Without these, NAT alone will not enable communication between vsys, as the traffic will still be denied by the default interzone deny rule.
- ✗
A Security policy rule in each vsys allowing traffic to the other vsys.
Why it's wrong here
While Security policy rules are necessary, they are not sufficient by themselves for inter-vsys traffic. Traffic between vsys is treated as interzone traffic and requires both a Security policy rule and a route or virtual router configuration to direct the traffic between vsys. Simply having rules in each vsys without proper routing will not allow the traffic to flow, as the vsys instances are isolated and need explicit paths.
- ✓
A shared Security policy rule in the shared policy or a rule in each vsys, plus routing between the vsys.
Why this is correct
Inter-vsys traffic requires that each vsys have a Security policy rule permitting the traffic, and that routing is configured to send traffic from one vsys to the other. This can be achieved with a shared policy rule that applies to both vsys or with individual rules in each vsys. Additionally, the virtual routers in each vsys must have routes to the other vsys, often via a shared interface or inter-vsys link.
- ✗
A Policy-Based Forwarding (PBF) rule to redirect traffic between vsys.
Why it's wrong here
PBF can be used to override routing decisions, but it does not permit traffic. For inter-vsys traffic, PBF could be used to direct traffic to a specific egress interface, but it must be combined with Security policy rules. PBF alone will not allow traffic; the Security policy rulebase must permit the traffic. Additionally, PBF is not typically the primary method for inter-vsys routing.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.