Courseiva

PCNSE Core Concepts and Architecture Practice Question

A network security administrator is configuring a new Palo Alto Networks firewall and wants to ensure that traffic between two internal subnets is inspected by the firewall. The subnets are on different interfaces. What must be configured to allow the firewall to inspect this traffic?

⚠ Common exam trap

It's easy for candidates to confuse NAT or PBF with security policy; NAT translates addresses and PBF changes forwarding, but neither permits traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Security policy rule allowing traffic from the source zone to the destination zone.

To allow and inspect traffic between two internal subnets on different interfaces, the administrator must create a Security policy rule that permits traffic from the source zone to the destination zone. This rule enables the firewall to perform security inspections such as application identification, threat prevention, and content filtering. Other policies like NAT, PBF, or decryption are not required for basic traffic flow and do not replace the need for a Security policy rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Policy-Based Forwarding (PBF) rule to redirect the traffic to the firewall.

    Why it's wrong here

    Policy-Based Forwarding is used to override the routing table and forward traffic out a specific interface or next-hop based on policy. It does not permit traffic; it only changes the forwarding path. The firewall already receives the traffic if it is the default gateway or if routes direct it to the firewall. PBF is not needed to allow inspection; a Security policy rule is required to permit the traffic.

  • ✗

    A NAT policy rule translating the source IP addresses.

    Why it's wrong here

    NAT policy is used to translate addresses, not to permit traffic. While NAT can be used in conjunction with Security policy, it is not required to allow traffic between internal subnets. The firewall will inspect traffic based on Security policy rules regardless of NAT. Configuring NAT without a corresponding Security policy rule would still result in the traffic being denied by the default interzone rule.

  • ✓

    A Security policy rule allowing traffic from the source zone to the destination zone.

    Why this is correct

    For the firewall to inspect and allow traffic between two interfaces, a Security policy rule must permit the traffic from the source zone to the destination zone. Without such a rule, the default interzone deny rule will block the traffic. The rule should also specify the correct applications and services to match the traffic, ensuring that the firewall performs the necessary inspection.

  • ✗

    A decryption policy rule to decrypt the traffic.

    Why it's wrong here

    Decryption policy is used to decrypt SSL/TLS or SSH traffic for inspection, but it does not permit traffic. If the traffic is already unencrypted or if decryption is not required, a decryption policy is unnecessary. The primary requirement to allow traffic between zones is a Security policy rule. Without it, the traffic will be denied regardless of decryption settings.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.