PCNSE Manage, Monitor and Operate Practice Question
A firewall administrator needs to troubleshoot a connectivity issue where users in the 10.0.1.0/24 subnet cannot reach the internet. The administrator suspects a missing policy. Which tool within the firewall's web interface can be used to test which security policy will be matched for a given traffic flow?
⚠ Common exam trap
Many candidates confuse the 'Test Policy Match' tool with traffic logs (Option C), thinking logs can predict future policy matches, but logs only show past events and cannot simulate a flow that hasn't occurred yet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy Optimizer > Test Policy Match
The 'Test Policy Match' tool under Policy Optimizer allows an administrator to simulate a specific traffic flow (source/destination IP, port, protocol) and see which security policy rule it matches. This directly addresses the need to verify whether a missing or misconfigured policy is blocking internet access for the 10.0.1.0/24 subnet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network > Virtual Routers
Why it's wrong here
Virtual Routers pages configure routing instances, interfaces and static routes; they do not evaluate policy match for a simulated flow. It is tempting because routing faults also break connectivity, but the requirement is identifying which security policy a flow hits, which needs the Test Policy Match tool under Policies.
- ✓
Policy Optimizer > Test Policy Match
Why this is correct
Policy Optimizer's Test Policy Match simulates a flow against the current ruleset, returning the exact security policy that would apply for specified source, destination, application and port. This directly satisfies the stem's requirement to identify which policy matches 10.0.1.0/24 traffic, exposing any missing or shadowed rule causing the outage.
- ✗
Monitor > Logs > Traffic
Why it's wrong here
Traffic logs record sessions already processed by the firewall, so they show which policy matched only after the fact, not which policy would match a hypothetical flow. It is tempting because logs reveal drops, but the stem asks for predictive policy-match testing, which the Test Policy Match tool provides.
- ✗
Device > Setup > Management
Why it's wrong here
Device > Setup > Management holds administrative settings such as hostname, DNS and management interface configuration; it performs no policy lookup. It is tempting because it is a central configuration area, but testing which security policy a flow matches requires the Test Policy Match tool under the Policies tab.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.