PCNSE Core Concepts and Architecture Practice Question
A network security administrator is deploying a new PA-3220 firewall in a data center. The security team requires that all traffic traversing the firewall be inspected for threats, but they want to minimize latency for trusted internal traffic that is already known to be benign. The administrator decides to create a security policy rule that allows traffic from the 'Trust' zone to the 'DMZ' zone without any security profiles attached. Which statement accurately describes the behavior of this rule?
⚠ Common exam trap
The trap here is assuming that the firewall always performs threat inspection on allowed traffic, but threat inspection requires explicit attachment of security profiles to the security policy rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic will be allowed, and because no security profiles are attached, the firewall will not perform any threat inspection on this traffic.
Security profiles are the components that enable threat inspection on allowed traffic. When a security policy rule permits traffic but has no security profiles attached, the firewall performs application identification and other basic functions but does not scan for threats such as viruses, spyware, or vulnerabilities. This behavior allows administrators to tailor inspection based on trust levels and performance requirements. In this scenario, the administrator intentionally omits profiles to reduce latency for trusted internal traffic, and the firewall will honor that configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic will be allowed, but the firewall will still perform application identification and threat inspection if a profile is later added to the rule.
Why it's wrong here
While the firewall always performs application identification regardless of profiles, threat inspection (such as antivirus or anti-spyware) only occurs if security profiles are attached to the rule. Without profiles, no threat inspection is performed, so this statement is misleading for the described scenario.
- ✓
The traffic will be allowed, and because no security profiles are attached, the firewall will not perform any threat inspection on this traffic.
Why this is correct
Security profiles are the mechanism that enables threat inspection. When a security policy rule allows traffic and no security profiles are attached, the firewall does not apply antivirus, anti-spyware, vulnerability protection, or other threat scanning for that session. This matches the administrator's intent to minimize latency for trusted internal traffic.
- ✗
The traffic will be blocked by default because security profiles are mandatory for all allow rules.
Why it's wrong here
Security profiles are not mandatory for allow rules. A security policy rule can be configured to allow traffic without any security profiles, and the traffic will be permitted. The firewall does not block traffic solely because profiles are missing; the action is determined by the rule's action setting.
- ✗
The traffic will be allowed, but the firewall will automatically apply the default security profiles from the 'default' security profile group.
Why it's wrong here
There is no automatic application of a default security profile group. Security profiles must be explicitly attached to a security policy rule. Without explicit attachment, no threat inspection occurs. The firewall does not have a built-in default profile group that is automatically applied.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.