PCNSE Troubleshoot Practice Question
A network administrator notices that traffic from a specific user to the internet is being blocked by the firewall. The user's IP is 10.1.1.100, and the destination is a public website. The security policy has a rule that allows traffic from subnet 10.1.1.0/24 to any. What is the first thing the administrator should verify?
⚠ Common exam trap
The trap here is that candidates often jump to NAT or service configuration issues, but the PCNSE exam emphasizes that rule order and first-match logic are the most common root cause of unexpected blocks, especially when a seemingly correct allow rule exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the security policy rulebase order and matching
The first thing to verify is the security policy rulebase order and matching because Palo Alto Networks firewalls evaluate rules in a top-down order and apply the first matching rule. Even if a rule exists that allows traffic from subnet 10.1.1.0/24 to any, a preceding rule with a deny action or a more specific match could be blocking the traffic from 10.1.1.100. Checking rule order ensures that the intended allow rule is actually being hit before investigating other potential issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the security policy rulebase order and matching
Why this is correct
Security policies are evaluated top-down, so a deny rule above the permit rule for 10.1.1.0/24 would block this user despite the allow existing. Verifying rulebase order and matching confirms which rule actually handles the session, satisfying the need to identify why permitted subnet traffic is dropped.
- ✗
Verify the user-ID agent is mapping the IP correctly
Why it's wrong here
User-ID mapping only matters when the policy enforces user or group criteria; the rule here matches source subnet 10.1.1.0/24, so IP-to-user mapping cannot cause the block. Verifying the agent is tempting because User-ID failures commonly break user-based rules, but no such rule is described.
- ✗
Check the service configuration for the destination port
Why it's wrong here
The allow rule targets any destination, so the service object on the destination port cannot be the cause of the block. Checking services is tempting because port mismatches frequently block traffic when a policy names specific applications, but this rule's service scope is unrestricted.
- ✗
Check the NAT configuration for the user's subnet
Why it's wrong here
NAT affects source translation and routing, not security policy evaluation against the original 10.1.1.100 source, which already matches the allow rule. Checking NAT is tempting because misconfigured translation breaks outbound internet access, but the stem attributes the block to policy, not connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.