Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

A firewall is configured with two ISPs for load balancing. Traffic from certain sources should always egress via ISP-1. What is the correct configuration?

⚠ Common exam trap

Many candidates confuse ECMP load balancing with source-based path selection, assuming that route metrics or multiple virtual routers can achieve deterministic egress control, when in fact only PBF provides the necessary policy override for specific source traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy-based forwarding (PBF) with source criteria

Policy-based forwarding (PBF) allows you to override the routing table for specific traffic based on criteria such as source IP, destination IP, or application. By configuring a PBF rule with source criteria, you can force traffic from certain sources to always egress via ISP-1, regardless of the load-balancing configuration. This is the correct method for source-based path selection in a multi-ISP setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple virtual routers

    Why it's wrong here

    Multiple virtual routers segment routing domains, not policy-based ISP selection within one domain. Source-based egress requires policy-based forwarding rules on a single virtual router. Virtual routers suit separating distinct routing tables, such as multi-tenant or lab isolation, where traffic must never share a routing instance.

  • ✗

    ECMP with route metrics

    Why it's wrong here

    ECMP with route metrics distributes flows across equal-cost paths by hashing, so source-based egress selection cannot be enforced; metrics only break ties between paths. It suits general bandwidth aggregation across two ISPs. Policy-Based Forwarding, matching source addresses to a specified egress interface, satisfies the requirement.

  • ✓

    Policy-based forwarding (PBF) with source criteria

    Why this is correct

    Policy-based forwarding evaluates source addresses before the routing table, so matching traffic is forced out ISP-1 regardless of load-balancing or route metrics. This directly satisfies the requirement that specific sources always egress via one ISP, which ECMP or failover alone cannot guarantee.

  • ✗

    Subinterfaces per ISP

    Why it's wrong here

    Subinterfaces create logical interfaces on one physical link, so they cannot steer traffic across two separate ISP connections. They suit VLAN trunking or multiple logical networks on a single circuit. The scenario requires policy-based forwarding, which matches source addresses to an egress interface and next hop.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.