PCNSE Core Concepts and Architecture Practice Question
A firewall has two virtual routers: VR1 (for internal networks) and VR2 (for DMZ). An internal server in VR1 needs to reach a DMZ server in VR2. Both virtual routers have routes to each other's subnets via a shared inter-connect. The firewall is receiving traffic but is dropping packets between the virtual routers. What configuration is missing?
⚠ Common exam trap
It's easy for candidates to confuse routing (Layer 3) with security policy (Layer 4-7), assuming that if routes exist, traffic will flow, but Palo Alto firewalls enforce zone-based policies independently of routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security policy allowing traffic between the zones associated with the virtual routers
In Palo Alto Networks firewalls, virtual routers handle routing decisions independently, but traffic between zones (e.g., internal and DMZ) must be explicitly allowed by a security policy. Even if routes exist between VR1 and VR2, the firewall will drop inter-zone traffic without a policy that permits the session. This is a fundamental security enforcement mechanism that separates routing from access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Redistribution of routes between the virtual routers
Why it's wrong here
Redistribution shares routes between routing protocols or instances; here each VR already reaches the other's subnets through the inter-connect, so no route is missing. Redistribution would be correct where a VR learns subnets only via a different protocol and must advertise them onward.
- ✗
Enabling packet forwarding on the virtual router interfaces
Why it's wrong here
Packet forwarding is enabled by default on firewall interfaces; the firewall is already receiving and processing the traffic, so it is not disabled. Toggling it would be relevant only where an interface has forwarding administratively suppressed, which the stem does not indicate.
- ✓
A security policy allowing traffic between the zones associated with the virtual routers
Why this is correct
Inter-VR routing alone does not permit transit; the firewall still evaluates zone-to-zone traffic against security policy. Because VR1 and VR2 interfaces sit in separate zones, the missing rule is a security policy permitting the internal zone to the DMZ zone, satisfying the stem's requirement that packets traverse virtual routers.
- ✗
A static route on both virtual routers pointing to each other's subnets
Why it's wrong here
Routes already exist via the shared inter-connect, so adding static routes duplicates existing entries and changes nothing. Static routes are the right choice when no dynamic protocol or inter-VR connectivity advertises subnets, not when forwarding is blocked by a missing security policy permitting inter-zone traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.