Courseiva

PCNSE Manage, Monitor and Operate Practice Question

A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?

⚠ Common exam trap

Many candidates confuse the 'Test Policy Match' tool with traffic logs (Option C), thinking logs can predict future policy matches, but logs only show past events and cannot simulate a flow that hasn't occurred yet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy Optimizer > Test Policy Match

The 'Test Policy Match' tool under Policy Optimizer allows an administrator to simulate a specific traffic flow (source/destination IP, port, protocol) and see which security policy rule it matches. This directly addresses the need to verify whether a missing or misconfigured policy is blocking internet access for the 10.0.1.0/24 subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network > Virtual Routers

    Why it's wrong here

    Virtual Routers pages configure routing instances, interfaces and static routes; they do not evaluate policy match for a simulated flow. It is tempting because routing faults also break connectivity, but the requirement is identifying which security policy a flow hits, which needs the Test Policy Match tool under Policies.

  • ✓

    Policy Optimizer > Test Policy Match

    Why this is correct

    Policy Optimizer's Test Policy Match simulates a flow against the current ruleset, returning the exact security policy that would apply for specified source, destination, application and port. This directly satisfies the stem's requirement to identify which policy matches 10.0.1.0/24 traffic, exposing any missing or shadowed rule causing the outage.

  • ✗

    Monitor > Logs > Traffic

    Why it's wrong here

    Traffic logs record sessions already processed by the firewall, so they show which policy matched only after the fact, not which policy would match a hypothetical flow. It is tempting because logs reveal drops, but the stem asks for predictive policy-match testing, which the Test Policy Match tool provides.

  • ✗

    Device > Setup > Management

    Why it's wrong here

    Device > Setup > Management holds administrative settings such as hostname, DNS and management interface configuration; it performs no policy lookup. It is tempting because it is a central configuration area, but testing which security policy a flow matches requires the Test Policy Match tool under the Policies tab.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.